Quote from: franco on April 22, 2026, 12:57:52 PMNot on your radar at the moment.
Cheers,
Franco
Hello Franco,
Has something changed after these past few months?
I'd like to voice an opinion on this subject as a (home) user of OPNsense.
Major vendors of commercial network security products have all joined the party. Of course, from the outside, it may seem like a marketing/PR stunt ("let's join to show everyone how serious we're about security", "X joined so we also have to, otherwise X's sales will say to the customers that we aren't serious enough about security", etc.). I can't know what were the incentives at the start of it, but it's certainly not the case today.
During the past few months, the number of security-related software updates in some relevant commercial software products increased significantly. I know it is taken very seriously inside those companies.
Leaving aside the political, economic, and social aspects of AI as a phenomenon, in my opinion, ignoring its direct impact on the security/tech landscape is not pragmatic.
I don't know what requirements a FOSS project like OPNsense would have to meet to get involved in Glasswing (and I appreciate the amount of work this can potentially generate for maintainers), but my suggestion would be to at least have a look and try to get access.
After all, if getting access itself is not a lot of work, the worst that could happen is that all you get is useless false positives and/or minor things not worth fixing (immediately). In return you will learn the current baseline for frontier AI security capabilities in the context of OPNsense codebase and get a confirmation that (at least at the moment) OPNsense is safe in this brave new world. And us, users, will also get a peace of mind.
Of course, I don't have your full perspective, so it'd be valuable to at least understand why not.
"