Elektrine lite

← Feed

@tehfishman@ioc.exchange

Post #4385864

2026-08-04 23:25 UTC

@mttaggart@infosec.exchange cory doctorow recently wrote about the hazards of using LLMs as a teaching aid that I think has some overlap here. The short version being that LLMs when used for learning are hazardous because an expert knows when an LLM is producing bullshit, but a novice doesn't and is more susceptible to accepting bullshit as fact. You have probably done enough malware analysis to know when an LLM based tool is way off the mark. But a novice security analyst might throw a malware sample at an LLM, get a terribly misleading result, and be completely lacking in the skills to refute it. To some degree, that's true of many tools in the security space. That same novice analyst let loose on the full contents of an enterprise Splunk environment will easily get lost in the endless sea of scary looking log events. But many tools don't lie so... convincingly. I guess those limits, and where they translate into added danger, are up to every individual defender to gauge for themselves though. So many thorns.

Replies (0)

No replies.