▲ 957 ▼ Gentoo Linux Begins Codeberg Migration In Moving Away From GitHub, Avoiding Copilot (www.phoronix.com) submitted 6 months ago by throws_lemy@lemmy.nz to c/technology@lemmy.world 77 comments fedilink hide all child comments
[+] Ladislawgrowlo@lemy.lol -18 points 6 months ago (6 children) reporting security issues Is this not an advantage? If AI can find new security vulnerabilities reliably? permalink fedilink source parent hideshow 12 child comments replies: [–] gwl@lemmy.blahaj.zone 24 points 6 months ago It cannot permalink fedilink source parent [–] jjagaimo@sh.itjust.works 19 points 6 months ago It often makes up non existent vulnerabilities. I think it was curl getting flooded with fake vulnerability reports which drowns out real reports, esp because it can take time to parse through the code or run the poc permalink fedilink source parent [–] WhyJiffie@sh.itjust.works 16 points 6 months ago https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/ permalink fedilink source parent [+] JordanZ@lemmy.world 9 points 6 months ago* (last edited 6 months ago) [deleted] permalink fedilink source parent [–] bananabread@lemmy.zip 8 points 6 months ago (1 child) Or it could introduce new ones :) permalink fedilink source parent hideshow 2 child comments replies: [–] eronth@lemmy.world -2 points 6 months ago Yeah, but you can have it scan without implementing. permalink fedilink source parent [–] sp3ctr4l@lemmy.dbzer0.com 4 points 6 months ago* Basically anywhere that LLMs are implemented... they are a security vulnerability, for any situation in which they are not sandboxed. Anything they can interface with? You can probably trick it or exploit it into doing something unintended or unexpected to anything else it is connected to. Either that or take advantage of the system that serves as the framework that connects it to other systems. Theoretically you could use an LLM to do something like come up with more accurate heuristics for identifying malware.... But... they're nowhere near 'intelligent' enough to like, give it a whole code base for some kind of software, and thoroughly make that software 100% secure. permalink fedilink source parent
[–] jjagaimo@sh.itjust.works 19 points 6 months ago It often makes up non existent vulnerabilities. I think it was curl getting flooded with fake vulnerability reports which drowns out real reports, esp because it can take time to parse through the code or run the poc permalink fedilink source parent
[–] WhyJiffie@sh.itjust.works 16 points 6 months ago https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/ permalink fedilink source parent
[+] JordanZ@lemmy.world 9 points 6 months ago* (last edited 6 months ago) [deleted] permalink fedilink source parent
[–] bananabread@lemmy.zip 8 points 6 months ago (1 child) Or it could introduce new ones :) permalink fedilink source parent hideshow 2 child comments replies: [–] eronth@lemmy.world -2 points 6 months ago Yeah, but you can have it scan without implementing. permalink fedilink source parent
[–] eronth@lemmy.world -2 points 6 months ago Yeah, but you can have it scan without implementing. permalink fedilink source parent
[–] sp3ctr4l@lemmy.dbzer0.com 4 points 6 months ago* Basically anywhere that LLMs are implemented... they are a security vulnerability, for any situation in which they are not sandboxed. Anything they can interface with? You can probably trick it or exploit it into doing something unintended or unexpected to anything else it is connected to. Either that or take advantage of the system that serves as the framework that connects it to other systems. Theoretically you could use an LLM to do something like come up with more accurate heuristics for identifying malware.... But... they're nowhere near 'intelligent' enough to like, give it a whole code base for some kind of software, and thoroughly make that software 100% secure. permalink fedilink source parent