Post #1919863
2026-04-08 14:08 UTC
@whitequark @tef also be extremely suspicious of anyone who references any article that's like "here are hundreds of REAL VULNERABILITIES identified by an LLM!" because not a single one of those I've looked at has had anything close to 10% of them be real actual security bugs, and most of the rest are low/info stuff you could've found with a linter.
Replies (2)
-
@whitequark@social.treehouse.systems 2026-04-08 14:10
@gsuberland @tef yeah i don't care about that, my assessment is based on personal examination of bug reports and talking to some people who i expect are not full of shit
-
@dominykas@fosstodon.org 2026-04-08 17:21
@gsuberland @whitequark @tef it might be that 90% of those reports are invalid, and slop sucks, but as someone on the side where I have tools alerting me about CVEs in my code I have my workload increased significantly over the past three months, so there's definitely signal somewhere in there too.