Elektrine lite

← Feed

@edward@activitypub.ro

Post #4164815

2026-07-28 13:14 UTC

@drwhax@infosec.exchange I think LLMs get the low hanging fruit of vulnerabilities, so you shouldn't trust an LLM's security audit as a definitive audit. As models get better, they'll catch higher up fruit, but still.

Replies (1)

  • @drwhax@infosec.exchange 2026-07-28 13:29

    @edward@activitypub.ro I do think that's the case at the moment, cross-file vulnerabilities are sometimes not found. What I feel they're mostly good at is, pattern recognition, e.g, there's a specific bug class fixed from past git history that it found repeated or as a variant. After all, LLM's is just a stochastic parrot and it shows

    Open ##4164814