Post #4167713
2026-07-28 13:09 UTC
@glyph@mastodon.social If I'm following, the counterfactual we're exploring is: if all of these companies could have inflated their FTE pool with software testing experts, would we have the same outcome?
Maybe? To be honest, I really don't think enough software testing experts exist to even do that. This is one of the most rarefied skills in the entire industry. And exploit development even moreso. Or, maybe they do all exist, but they're all working in basements in CIS states developing 0-days to sell. Or they were.
I guess I'm trying to say I think there were real structural barriers to this being a feasible approach at scale.
That said, the capacity of these models to perform these specific tasks does not absolve the industry of its many sins. But now a duty of care question faces dev shops of all sizes: do we use these models to find vulns and attempt patches first, or do we abstain and let unscrupulous actors find them for us?
Replies (1)
-
@glyph@mastodon.social 2026-07-28 15:40
@mttaggart@infosec.exchange I don't disagree about the infeasibility of alternate paths to massively increasing the resource budget for infosec, but I guess we don't need to keep putting increasingly finer points on the aforementioned waste. I think it's bad to build an infosec dependency on LLMs for the same reasons I think it's bad to build an app development dependency on LLMs, but admittedly vuln discovery is one area where there is a big enough asymmetry to make this a real question.