Post #3893645
2026-07-17 19:43 UTC
Not quite unsurprisingly there are people in my comments who feel that automating vulnerability research is increasing their productivity and that they are in control, being the “human in the loop,” that they are in fact learning a lot. Well, Christine Lemmer-Webber just published a great article on that. One passage is particularly worth repeating:
“The vehicle is the LLM, you are the passenger. And I think the amount of agency people have over their journey is greatly reduced from what they feel like it is.”
This is about coding but if you look closely you will notice the same dynamics applying to vulnerability research. It’s all about speed, and understanding/validating LLM-generated results is inherently slow. So the human in the loop will always tend to give up more and more control, relying more and more on the LLM to just do the right thing. And we get the same deskilling that we see everywhere else, all while LLMs keep regurgitating old stuff.
Either way, I’m not interested in arguing about this. I won’t convince LLM fans just as they won’t convince me. We’ll see soon enough how this goes.
Replies (2)
-
@cR0w@infosec.exchange 2026-07-17 19:45
@WPalant@infosec.exchange
-
@erik@mastodon.infrageeks.social 2026-07-18 10:55
@WPalant@infosec.exchange Somewhat related to the people in school that immediately “turn to page 265 for the answer”. You have an answer, which looks obvious in retrospect, but your brain never took the path of looking at the problem space in order to learn *how* to get to that answer