Post #4167711
2026-07-28 15:44 UTC
@mttaggart@infosec.exchange Ironically, the best argument for bypassing this question of "should we use them" rather than an up or down yes/no decision, comes from an anthropic employee: https://alexgaynor.net/2026/jul/15/you-cant-bugfix-your-way-out-of-the-vulnpocalypse/
Right now, the LLM vulnpocalypse is overwhelming the entire open source community with big piles of vulnerabilities, increasing maintainer burnout, etc. But the path out of this is going to need to be less reactive: eliminating vuln classes, rather than fixing vulns.
Replies (1)
-
@mttaggart@infosec.exchange 2026-07-28 15:48
@glyph@mastodon.social This I wholeheartedly endorse. I'm the guy who actually believes we'd be a lot better off if multiple codebases were taken down and rebuilt (well) in memory-safe languages. This dropped today, which is worth a read as well. For all the new vuln findings, the actual exploitation of same is comin' up short. https://www.vulncheck.com/blog/state-of-exploitation-1h-2026