GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    bluca (bluca@fosstodon.org)'s status on Saturday, 28-Mar-2026 02:48:55 JST bluca bluca
    in reply to
    • daniel:// stenberg://
    • hanno
    • Greg K-H

    @bagder @gregkh @hanno same in systemd, quality of these reports has skyrocketed late last year. The current problem is that these LLMs cannot of course understand non-trivial security models, so they often report issues that are not really security issues, even though they are real bugs

    In conversation about 7 months ago from fosstodon.org permalink
    • James Morris likes this.
    • Embed this notice
      daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:56 JST daniel:// stenberg:// daniel:// stenberg://
      in reply to
      • hanno
      • Greg K-H

      @gregkh @hanno I concur. We see lots of accurate finds reported with AI tools in curl as well.

      In conversation about 7 months ago permalink
    • Embed this notice
      Greg K-H (gregkh@social.kernel.org)'s status on Saturday, 28-Mar-2026 02:48:57 JST Greg K-H Greg K-H
      in reply to
      • hanno
      @hanno It is real, see my interview in the Register today about this very problem: https://www.theregister.com/2026/03/26/greg_kroahhartman_ai_kernel/
      In conversation about 7 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: regmedia.co.uk
        Linux kernel czar says AI bug reports aren't slop anymore
        Interview: Greg Kroah-Hartman can't explain the inflection point, but it's not slowing down or going away
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:58 JST hanno hanno
      in reply to

      But that wasn't an isolated development either. It's clearly showing up everywhere. I'm running out of reasons not to think that AI tools got really good at finding security vulnerabilities.

      Obvious caveat: None of that changes that there are plenty of good reasons to be very worried about the whole AI thing.

      In conversation about 7 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:58 JST hanno hanno
      in reply to

      FWIW: I don't have a big conclusion here, I'm just sharing random thoughts and observations. /end thread

      In conversation about 7 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:59 JST hanno hanno
      in reply to
      • daniel:// stenberg://

      The most visible thing how AI impacted security vulnerabilities early on were slop reports. Famously, @bagder shared plenty of experiences with AI written garbage reports.
      But there's another more recent development. Real, and valuable security reports show up. I heard those starting early this year. Those were single instances, but they were clearly showing that there are companies out there developing tools that spit out real vulnerabilities, with proof of concepts, and sometimes even patches.

      In conversation about 7 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:48:59 JST hanno hanno
      in reply to

      Something else happened, and that was *very* recently. Those reports grew in numbers.
      if I see 1-2 valid reports in a major open source lib from an AI tool, I'm not impressed. If I had enough funding, I could find valid vulns in a variety of ways.
      When the Mozilla/Antropic thing came out, that was what I was thinking. "Yeah, these are real bugs, but you know, if I had infinite funding like Antropic, and a team of top security people, you know how many bugs I could find in Firefox?"

      In conversation about 7 months ago permalink
    • Embed this notice
      hanno (hanno@mastodon.social)'s status on Saturday, 28-Mar-2026 02:49:00 JST hanno hanno

      AI, a few thoughts, observations about AI & security vulns.
      My standard line about AI is "there's a lot I'm uncertain about". But let's be clear, there's a lot I don't like & I'm probably biased towards the "here's how spectacularly AI failed once again" news (of which there are plenty) or at least the "it's not as impressive as it may look".
      Yet, I don't want to close my eyes if I see things that clearly don't fit my biases. And I know a thing or two about security vulnerabilities.🧵

      In conversation about 7 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.