Elektrine lite

← Feed

@WPalant@infosec.exchange

Post #3858507

2026-07-16 12:27 UTC

I have been rethinking my life’s choices lately. I’ve spent years building a knowledge base for Firefox extension developers. Despite all its flaws, and development complexity definitely was one of them, the Firefox extension ecosystem was meant to provide functionality that browser developers didn’t think about. Then Chrome came along and forced Mozilla to abandon its extensibility approach for one which was neatly limited to functionality that browser developers decided to allow. They had good technical reasons for that of course, but it replaced an ecosystem that embraced creativity by one which encourages endless repetitions of the same thing. Now it’s educating people about security, another task I’ve spent years on. Currently this field is being killed by the so-called “AI.” Don’t get me wrong, I recognize the immense progress made on automated vulnerability finding. I see the short-term benefits. Yet the long-term outlook is grim. In a field that was already severely understaffed, this will result in even fewer people seriously learning about security. Yet the LLMs are by no means intelligent, nor will they ever be. They recombine existing human knowledge, and they are highly reliant on it. Without an influx of new knowledge their results will degrade. Either way, I’m not complaining. It was fun while it lasted. But you probably shouldn’t expect new security research from me any time soon, I have little incentive to do it in this changed landscape.

Replies (4)

  • @WPalant@infosec.exchange So sorry to hear this. Selfishly, I hope you find a way to balance these and still find useful and interesting ways to contribute. And if not here, then wherever you end up!

    Open ##3858565

  • @Xavier@infosec.exchange 2026-07-16 12:32

    @WPalant@infosec.exchange I think for as many folks stepping away from security research, there folks like me that is having a blast with LLM assisted hacking. I used to run a research team about 10-15 years ago, but now I'm doing hands on work again. And when I do workshops at hacker meetups, there are lots of people hungry to compare notes. It's sad to see some folks like you decide that AI is not for them. I think the industry will be fine.

    Open ##3858572

  • @WPalant@infosec.exchange 2026-07-17 19:43

    Not quite unsurprisingly there are people in my comments who feel that automating vulnerability research is increasing their productivity and that they are in control, being the “human in the loop,” that they are in fact learning a lot. Well, Christine Lemmer-Webber just published a great article on that. One passage is particularly worth repeating: “The vehicle is the LLM, you are the passenger. And I think the amount of agency people have over their journey is greatly reduced from what they feel like it is.” This is about coding but if you look closely you will notice the same dynamics applying to vulnerability research. It’s all about speed, and understanding/validating LLM-generated results is inherently slow. So the human in the loop will always tend to give up more and more control, relying more and more on the LLM to just do the right thing. And we get the same deskilling that we see everywhere else, all while LLMs keep regurgitating old stuff. Either way, I’m not interested in arguing about this. I won’t convince LLM fans just as they won’t convince me. We’ll see soon enough how this goes.

    Open ##3893645

  • @apreiml@fosstodon.org 2026-07-16 12:53

    @WPalant@infosec.exchange Thanks for your efforts so far. I appreciate your work. I've learned a lot about practical security by reading your password manager tear down posts.

    Open ##4215022