Post #4383225
2026-08-04 21:08 UTC
@mttaggart@infosec.exchange I've been thinking on this for a while too and it's tough. My take for now is that if I can do the work properly without GenAI at the expense of some time, then that time cost offsets the general "cost" of using GenAI.
If for whatever reason the task requires GenAI, then it absolutely falls into the duty of care category.
I do think that there is also a place for teams to have a reasonable range of approaches among the team members. For example, I have teammates that use AI tools but they all know I don't so we approach the same tasks differently. So far I have never "lost" when we would see who could do a task quicker or better, me without AI and them with it. Because of that I have no incentive to change my position, but I also know that may not always be the case.
Replies (1)
-
@mttaggart@infosec.exchange 2026-08-04 21:14
@cR0w@infosec.exchange Real talk, I'm getting some bananas obfuscated samples that are most certainly more obfuscated because of LLM usage. It's just so much easier to do stuff like control flow flattening and other techniques. I can probably get there, but not in a reasonable timescale. Whereas the models can get me indicators fairly reliably. I really don't know what to do with that.