Post #3858507
2026-07-16 12:27 UTC
Replies (4)
-
@tychotithonus@infosec.exchange 2026-07-16 12:32
@WPalant@infosec.exchange So sorry to hear this. Selfishly, I hope you find a way to balance these and still find useful and interesting ways to contribute. And if not here, then wherever you end up!
-
@Xavier@infosec.exchange 2026-07-16 12:32
@WPalant@infosec.exchange I think for as many folks stepping away from security research, there folks like me that is having a blast with LLM assisted hacking. I used to run a research team about 10-15 years ago, but now I'm doing hands on work again. And when I do workshops at hacker meetups, there are lots of people hungry to compare notes. It's sad to see some folks like you decide that AI is not for them. I think the industry will be fine.
-
@WPalant@infosec.exchange 2026-07-17 19:43
Not quite unsurprisingly there are people in my comments who feel that automating vulnerability research is increasing their productivity and that they are in control, being the “human in the loop,” that they are in fact learning a lot. Well, Christine Lemmer-Webber just published a great article on that. One passage is particularly worth repeating: “The vehicle is the LLM, you are the passenger. And I think the amount of agency people have over their journey is greatly reduced from what they feel like it is.” This is about coding but if you look closely you will notice the same dynamics applying to vulnerability research. It’s all about speed, and understanding/validating LLM-generated results is inherently slow. So the human in the loop will always tend to give up more and more control, relying more and more on the LLM to just do the right thing. And we get the same deskilling that we see everywhere else, all while LLMs keep regurgitating old stuff. Either way, I’m not interested in arguing about this. I won’t convince LLM fans just as they won’t convince me. We’ll see soon enough how this goes.
-
@apreiml@fosstodon.org 2026-07-16 12:53
@WPalant@infosec.exchange Thanks for your efforts so far. I appreciate your work. I've learned a lot about practical security by reading your password manager tear down posts.