Post #1671880
2026-04-21 09:21 UTC
I keep seeing bad takes that express hostility towards security bug finding whether by Project Zero or by LLMs.
It’s as if folks with these takes are ignoring two basic things:
1) Google and Anthropic didn’t put the bugs in your code. The known risks of memory-unsafe programming languages are hitting the fan.
2) Attacks that exploit memory-unsafety hurt _users_.
(Take an ffmpeg vulnerability: Chances are that YouTube’s back end is already isolated but VLC users could have a very bad time.)
Replies (1)
-
@freddy@social.security.plumbing 2026-04-21 11:25
@hsivonen lots of people are being / were hit by LLM-slop bugs first and foremost, which pretty much set a bad stage. Most who haven't been directly involved are just epxecting AI bugs to be slop. I wish this was true :)