3 ms·
Where all of this is going? Will there be a dedicated servers running coding agents that iterate throught codebases for each company to find vulnerabilities 24/
by fl1pper 4mo ago
Where all of this is going? Will there be a dedicated servers running coding agents that iterate throught codebases for each company to find vulnerabilities 24/7?
- vessenes 4mo agoYes
- Aurornis 4mo agoMore like: There will be a budget for tokens to be spent on security audits. 1000 different companies will be pitching your CTO their proprietary vulnerability scanning harness as the most cost effective.
- colejohnson66 4mo agoSo what already happens, but worse?
- flomo 4mo agoIt's just another tool in the belt. Someone will say that's cheaper than rewriting in safe rust or whatever. (Apple must have a bunch of 1980s code written to 1980s standards. But that is their moneymaker.)
- jeffbee 4mo agoWhy shouldn't there be such things? We already have fuzzing, and responsible software publishers dedicate 24/7 resources to fuzzing.
- 0123456789ABCDE 4mo agothis has been the reality for while now google has been running ClusterFuzz since ~2012, and naptime was announced in 2024 (https://projectzero.google/2024/06/project-naptime.html https://projectzero.google/2024/06/project-naptime.html). they call it big sleep and codemender now. openai announced aardvark last year, no they call it codex security.
- pjmlp 4mo agoYes, this is quite similar to proper configured CI/CD pipelines, which unfortunely are still a minority across the industry.