Elektrine lite

← Feed

@mattbrowndev@mastodon.social

Post #2429654

2026-03-23 01:49 UTC

@sarah@phpc.social @pollita@phpc.social Here's Daniel's initial blog post on the matter: https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/ In the hands of experts, proprietary LLM-assisted security analysis caught 50 bugs/vulnerabilities in Curl: https://daniel.haxx.se/blog/2025/10/10/a-new-breed-of-analyzers/ But commercially-available LLMs make it easy for clueless grifters to submit HackerOne reports, so they had to shut down the whole thing.

Replies (1)

  • @sarah@phpc.social 2026-03-23 16:26

    @mattbrowndev@mastodon.social @pollita@phpc.social thanks! I am really sad to hear that slop has been such a problem. When I use AI I know its limits and use my own expertise to verify its outcomes. But I can see where slop is a real issue.

    Open ##2429655