Elektrine lite

← Feed

@hsivonen@mastodon.social

Post #1671880

2026-04-21 09:21 UTC

I keep seeing bad takes that express hostility towards security bug finding whether by Project Zero or by LLMs. It’s as if folks with these takes are ignoring two basic things: 1) Google and Anthropic didn’t put the bugs in your code. The known risks of memory-unsafe programming languages are hitting the fan. 2) Attacks that exploit memory-unsafety hurt _users_. (Take an ffmpeg vulnerability: Chances are that YouTube’s back end is already isolated but VLC users could have a very bad time.)

Replies (1)

  • @hsivonen lots of people are being / were hit by LLM-slop bugs first and foremost, which pretty much set a bad stage. Most who haven't been directly involved are just epxecting AI bugs to be slop. I wish this was true :)

    Open ##2097435