Elektrine lite

← Feed

@jerry@infosec.exchange

Post #4140211

2026-07-27 15:24 UTC

interestingly, at least some of the vulenrabilities fixed in today's Mastodon update were discovered by claude.

Replies (4)

  • @paul_ipv6@infosec.exchange 2026-07-27 15:31

    @jerry@infosec.exchange i have much more confidence in AI finding bugs, less so in the patches (if not human reviewed). when fuzzing first got affordable, a slew of bugs in old code was found. then folks started being proactive and fuzzing *before* releasing new code. i sure hope we get to a point soon where AI "testing" is done before release too.

    Open ##4140386

  • @energisch_@troet.cafe 2026-07-27 19:48

    @jerry@infosec.exchange of course LLMs can find out vulnerabilities with massive data processing at their back. Vulnerabilities show a pattern, and those LLMs just look at all the pattern in code. That's not rocket science. This is just a super big pattern checker machine. Not intelligence. Not logic. Not creativity. It is an automation for pattern comparison.

    Open ##4238210

  • @jerry@infosec.exchange I'm not surprised, machine learning is really good when the search space is large (all the possible interactions with the Mastodon software), but the expected outcome is small and easy to measure (unexpected privilege escalation). This doesn't tell anything about Claude or any other LLM, this fuzzing is really expensive and currently only affordable because it is subsidized by investor's money (including a portion of everyone's government-backed retirement fund in the US).

    Open ##4238213

  • @jerry@infosec.exchange Honestly if fuzzing and security posture is getting improved by LLM/AI, Im all for it. Good use case IMO

    Open ##4238214