Elektrine lite

← Feed

@hsivonen@mastodon.social

Post #1131118

2026-04-13 17:24 UTC

I’m seeing a lot of denial and logical fallacies on Mastodon about LLM capability to find security bugs. I get it that when folks have concluded that LLMs are harmful, they want to believe that LLMs fail at everything. But a list of correctly-identified bad things about LLMs does not logically imply that LLMs can’t find security bugs.

Replies (4)

  • @Turre@mementomori.social 2026-04-13 17:44

    @hsivonen@mastodon.social Well. When those companies have touted and pushed their AI thingies at a thousand things they're unsuited for, that kinda sets the expectations. Most of us are just so bloody fucken tired of hearing AI AI AI AI everywhere. You tone it out or go crazy. And so even the one thing it might be actually good at goes missed because folks are no longer listening. It's all so fantastically stupid.

    Open ##1131117

  • @hsivonen@mastodon.social 2026-04-13 17:24

    And, yes, the Anthropic Mythos post fits a previously-seen pattern of “AI” companies marketing by danger, but saying that it’s marketing does not refute what the models that are already generally offered can do. And people act like their own conjecture is more informative than what people from multiple projects that deal with security bug reports say. See e.g. https://mastodon.social/@bagder/116363034479757682 .

    Open ##1671859

  • @sayrer@mastodon.social 2026-04-13 17:51

    @hsivonen if you haven't run it on your own code, you're missing out. once you do that, it's hard to argue about it.

    Open ##1671867

  • @marshray@infosec.exchange 2026-04-14 01:51

    @hsivonen ”Quick, get the torches and pitchforks! Someone suggested that LLMs could in some way be useful.”

    Open ##1671868