4 ms·
I disagree -- we're clearly getting better safeguards by way of AI agents to spot potential vulnerabilities!
by x3n0ph3n3 5mo ago
I disagree -- we're clearly getting better safeguards by way of AI agents to spot potential vulnerabilities!
- nullsanity 5mo ago[dead]
- jabl 5mo agoThe question is whether the current situation is a short burst of action, and once those most critical bugs get fixed the hype around AI vulnerability scanning will die down, or whether the current crop of system/infra software written in vulnerable languages like C are beyond redemption and they will provide an endless source of critical bugs for AI to find until we fix them by rewriting them in Rust/Go/whatever.
- yardstick 5mo agoAn eternal summer of CVEs is upon us
- KronisLV 5mo agoSeems like those “rewrite in Rust” folks had a point after all (the viability of it for any number of projects being another thing entirely).
- LtWorf 5mo agohttps://www.securityweek.com/tanstack-mistral-ai-uipath-hit-in-fresh-supply-chain-attack/ https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-...
- Terr_ 5mo agoA better use of LLMs: To help translate the vast majority of C/C++ developers' output into memory-safe languages. :p
- lionkor 5mo agoYou're likely joking, but in case someone else misunderstands; this is not going to work. Rust with unsafe{} is the only thing you can translate directly to, even with LLMs. Rust with extensive unsafe{} is not something anyone wants to debug or maintain, and is near impossible to improve quickly.
- sieabahlpark 5mo ago[dead]