5 ms·
What is happening? I see multiple outages and CVEs is being reported on HN's front page. I've never seen these many security/incident related posts on HN's fron
by rishabhaiover 5mo ago
What is happening? I see multiple outages and CVEs is being reported on HN's front page. I've never seen these many security/incident related posts on HN's front page.
- majorchord 5mo agoAI is happening.
- cachius 5mo agoIn each recent case?
- gordonhart 5mo agoAI assistance was explicitly disclosed on yesterday's. Today's has Claude as one of two contributors on this GitHub Pages site at least so it's also very likely. Agents are capable of finding this kind of stuff now and people are having a field day using them to find high-profile CVEs for fun or profit.
- halJordan 5mo agoI was promised that ai was just a stochastic parrot
- spindump8930 5mo agoSome combination of reporting bias given concerns about LLM security capabilities and actual new vulnerabilities found with LLM assistance. Even if exploits and outages are unrelated to LLMs, I'm certainly thinking about whether claude could build these things (or if actors already have).
- gilrain 5mo agoAutomated vulnerability discovery via LLM.
- pixl97 5mo agoEveryone was talking about how Mythos was overblown marketing, and while it may be, they missed the forest for the trees. Capabilities have been escalating for a year now and we're at the point of widespread impact. I don't suspect we'll see a slowdown for a long time.
- pjmlp 5mo agoSame applies to them being good enough to program, but many are so focused on source code generation that they don't get the whole picture. Thanks to agents and tool calling, there are now business cases that can be fully described by AI tooling, the next step in microservices, serverless and what not. Naturally with a much smaller team than what was required previously.
- microtonal 5mo agoI agree. It is not like Mythos or other LLMs are insanely smart/superhuman. Many of these vulnerabilities could be discovered fairly easily by trained human experts as well. The problem is more that it requires an insane amount of attention and time of highly-paid experts to shake out these issues vs. an LLM that never gets tired and can analyze a large amount of code at low cost. Linus' law was wrong because there were never enough (qualified) eyeballs to check the code. LLMs provide an ample supply of eyeballs (though it's not a benefit to open source, since proprietary developers can use the same LLMs).
- ryandrake 5mo agoAnyone care to share which models and which prompts actually lead to finding these kinds of vulnerabilities? Or the narrowing-down workflow that can get an LLM to discover them? Surely just telling claude "Find all vulnerabilities in this project LOL" isn't enough? I hope?
- huflungdung 5mo ago[dead]
- 5mo ago
- john_strinlai 5mo agoi believe a good portion of the cves hitting the front page are moreso because they are ai-related (found partially/in whole by ai) and make for quick upvotes.
- NitpickLawyer 5mo ago> What is happening? Slowly at first, and then suddenly. AI assisted anything follows this trend. As capabilities improve, new avenues become "good enough" to automate. Today is security.
- themafia 5mo agoPerhaps it was the prior quiescent period that was the anomaly.
- sva_ 5mo agoA mix of AI and hybrid warfare.
- elija 5mo agoIn some sense, I wonder if non-open-source is "safer" since LLMs can't mass scan the code for exploits.
- overboard2 5mo agoMaybe for a while, but there's nothing stopping LLMs from examining disassembler output.
- LtdJorge 5mo agoSecurity through obscurity
- nly 5mo agoThat's significantly more challenging for an LLM (and a human)
- lsaferite 5mo agoI would caution against thinking it's difficult for an LLM. I've used them in raw data file analysis and they are frequently shockingly good at pulling structures and meaning out of seemingly random data. Disassembled binaries already are structured, so pulling code flow out of that is easier. Mixing that with existing disassembly and inspection tooling and an LLM has what is needed to fast track this kind of vulnerability research. Point being, an LLM with the proper tools can potentially follow code flow from disassembled binaries way easier than a human.
- panzi 5mo agoI forgot who it was, but someone on YouTube said LLMs already work hooked up to gidra. If true it's only a matter of time once they find similar things in e.g. Windows. I'll wait half a year to a year (think of embargo) and if there still isn't such work for Windows I'll conclude that LLMs have a problem disassembling binaries.
- 5mo ago
- calebhwin 5mo agoIt's actually the perfect evergreen content to discuss on HN in an age where so much else is AI generated.
- jdub 5mo ago... there's also a bit of a frequency illusion factor.
- raverbashing 5mo agoI wonder where are the Rust naysayers hiding now C code is broken - period
- dgellow 5mo agoI'm not sure it is too unusual to be honest. I feel that we have that type of content from time to time