Elektrine lite

← Feed

@hsivonen@mastodon.social

Post #1671860

2026-04-13 17:24 UTC

Then there’s the dismissal that, yes, LLMs now find security bugs, but the bugs could have been found by other methods. But evidently defenders hadn’t actually found them by other methods. (Unknown what attackers had already found.) Or folks find it objectionable that the new capability has been made available to attackers and the proposed cure is to pay for access to the same LLM. But that does make the existence of the capability untrue.

Replies (2)

  • @hsivonen@mastodon.social 2026-04-13 17:25

    Or folks go LOL at security incidents or code quality at an LLM company. Irrelevant to whether their model can find security bugs. The way this works is that you have a non-LLM oracle like ASAN. If the model found a way to trigger the oracle, then it’s not really productive to argue that it didn’t. Why even post this considering the predictable hate? Because denial about the situation does not make users safer from attacks.

    Open ##1671861

  • @gabrielesvelto@mas.to 2026-04-13 19:26

    @hsivonen isn't fuzzing a number game though? LLMs are fuzzers backed by billions, they'll absolutely find something, but so would everything else given the same resources and no restrain on how to spend them, no matter how wasteful.

    Open ##1671862