Post #4164815
2026-07-28 13:14 UTC
@drwhax@infosec.exchange I think LLMs get the low hanging fruit of vulnerabilities, so you shouldn't trust an LLM's security audit as a definitive audit. As models get better, they'll catch higher up fruit, but still.
Replies (1)
-
@drwhax@infosec.exchange 2026-07-28 13:29
@edward@activitypub.ro I do think that's the case at the moment, cross-file vulnerabilities are sometimes not found. What I feel they're mostly good at is, pattern recognition, e.g, there's a specific bug class fixed from past git history that it found repeated or as a variant. After all, LLM's is just a stochastic parrot and it shows