Elektrine lite

← Feed

@ligasser@social.epfl.ch

Post #2935514

2026-05-12 11:33 UTC

@gedankenstuecke@scholar.social @Gusted@social.linux.pizza just to throw a cat amongst pigeons: what do you think about Mozilla closing 400 security bugs with LLMs? I'm working on an app and really got frustrated by the lack of a useful rust to wasm library, so an LLM wrote that part. It allows me to go on with the rest of the app. And I started to move to codeberg, setting up my own runners. Yes, an LLM helped me find some of the bugs. Do I need to move away now? Use radicle? Or DeGit?

Replies (2)

  • @ligasser@social.epfl.ch 2026-05-12 11:38

    @gedankenstuecke@scholar.social @Gusted@social.linux.pizza honestly, a year ago I was not sure if LLMs are actually worth it. They still didn't cross the break even point, thinking about the 200$ Claude which can create charges for anthropic up to 2000$. But these models start to do some actual new stuff, like uncovering two long hidden Linux kernel bugs. The cost is still very high, and I would love the environmental impact to be much lower. But just ignoring them will not make them disappear.

    Open ##2935515

  • @scheme@freiburg.social 2026-05-12 21:57

    @ligasser@social.epfl.ch @gedankenstuecke@scholar.social @Gusted@social.linux.pizza They (Mozilla) didn't. https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/ The relevant tldr is that if a bug could be reached by multiple code paths, they counted those as separate bugs. Also, bugs are found all the time. But normally companies aren't throwing infinite money at them in a desperate bid to stay relevant and to exploit the tiniest bits for marketing.

    Open ##2935519