BEAM There, Done That with Ingela Andin on the OTP TLS Stack, the AI Vulnerability Wave and the Security Fix Pipeline

New BEAM There, Done That with Ingela Andin - over 20 years on the OTP team at Ericsson, maintaining the TLS stack and handling first triage of security reports.

The Erlang-relevant points:

THE 2026 SHIFT. At the start of the year, AI-generated reports were mostly hallucinations. Within weeks they became real and the volume increased sharply. The OTP inbox is now part of the same wave that hit the Linux kernel - Linus Torvalds called the kernel security list almost entirely unmanageable by May. The BEAM did not escape.

WHAT A HALLUCINATION LOOKS LIKE. A client/server TLS asymmetry flagged as a serious vulnerability - which was actually correct-by-specification behavior. The AI saw something anomalous, couldn’t check the RFC, and escalated it. Domain knowledge resolved it quickly.

THE FIX PIPELINE AT OTP SCALE. Patches coordinate across three maintained releases on the same day. Best case is a clean cherry-pick. Harder cases require per-release adapted solutions. The goal is to never ship a bug fix with a bug - a partial fix that improves the situation is more acceptable than a buggy one. Everything passes nightly runs across multiple platforms.

CONTRIBUTING TO OTP. Small bug fixes with test cases in the OTP testing framework are the easiest path to a merged contribution. Large feature additions without prior discussion with the team rarely make it. If you’ve patched OTP locally, the team’s ask is to contribute it as a general feature - local patches create forward-merge burden and make it harder to take security updates.

SBOM GENERATION. OTP now generates a Software Bill of Materials for all releases, announced on the Erlang Forum.

2 Likes