Daniel Stenberg
"I am also sure AIs can be trained and ultimately get used even for finding and reporting security problems in productive ways, but so far we have yet to find good examples of this.
"Right now, users seem keen at using the current set of LLMs, throwing some curl code at them and then passing on the output as a security vulnerability report. What makes it a little harder to detect is of course that users copy and paste and include their own language as well.
"The entire thing is not exactly what the AI said, but the report is nonetheless crap."
Comments
Post a Comment
Empathy recommended