8 ms·
Vulnerability reports are not special anymore
- themanmaran 3mo agoI feel like it's also been overrun by a lot of spam. As someone running a company, I get 2-5 unsolicited "vulnerability reports" per week. Half of them are an LLM finding some bad CSS on our framer splash page. The other half I assume are an extortion attempt so we just mark as spam. Occasionally I see real security researchers on HN complaining that no one takes the disclosure seriously, or that people reply immediately with a cease and desist. But from the receiving end it's just because the spam is unmanageable.
- spoaceman7777 3mo agoHave you considered having an agent, or just a model, classify/triage them for you? Modern problems require modern solutions.
- cleverfoo 3mo agoSame experience here. I've run a successful vulnerability disclosure program for over a decade and paid out thousands of dollars in bounties for scanii.com (a malware identification API service), but recently (since the beginning of the year), we went from receiving maybe 5 per month to receiving 5 per day. These are clearly AI-generated and extremely low quality (albeit well-written). The rules of the program aren't read, and it's clearly a “point-and-click to a website" and file a report. I'm now considering just shutting down the program since, as the OP pointed out, if you found this vulnerability using an AI tool, they are inherently public. I haven't gone that far yet but have instituted some new rules aiming at filtering out most of the reports: 1- No AI-generated report and 2 - Reports must include a video of the exploit. You can see our program rules here: https://docs.scanii.com/article/131-does-scanii-have-a-security-vulnerability-disclosure-program https://docs.scanii.com/article/131-does-scanii-have-a-secur...
- lemagedurage 3mo agoHave you considered requiring a small payment for vulnerability disclosure? Refund it on payout. This should be very effective at deterring spammers. It also sucks for real reports, but beats shutting down the program entirely.
- inigyou 3mo agoWhy would anyone pay money to have a chance of being arrested?
- lemagedurage 3mo agoIf a vulnerability disclosure program has a good track record of paying out, and legitimate reports get refunded, why not? Again, the alternative might be shutting down the program entirely.
- cleverfoo 3mo agoIt's not a horrible idea... the challenge there would be making that payment/refund flow totally transparent in order to build trust and be fair to the researchers.
- ozim 3mo agoMaking, payment/refund setup is more complicated than „set and forget”. First question: Do you keep money for shit reports? Well no, you have to pay it back like credit card validation. There is no pain for posting shit report just inconvenience. There is no legal way where you can keep the money.
- inigyou 3mo agoWhy not?
- 3mo ago
- Gigachad 3mo agoI'm getting CVE fatigue with all of these super ultra critical 10/10 vulnerabilities that are some node package that compiles my frontend can get stuck if I give it a malicious regex. It's hard to spot the stuff that actually matters.
- dirkc 3mo ago[dead]
- teaearlgraycold 3mo agoNot sure what dumbass out there is marking those as 10/10. A 10 should be an auth bypass or RCE. Not a crashed build in my CI.
- themanmaran 3mo agoSeriously. We got 116 github dependabot alerts this week. Half of them for dev dependencies.
- jamesfinlayson 3mo agoI tried to raise that with my internal security team recently - don't clutter my vulnerability dashboard with issues in dev dependencies. They somewhat rightly pointed out that malware needs to be dealt even if it's a dev dependency. So my suggestion went nowhere because I guess we can't filter by type of vulnerability.
- zmgsabst 3mo agoDev dependencies is how they compromised SolarWinds and thereby most of the US federal government. > The attackers used a supply chain attack. The attackers accessed the build system belonging to the software company SolarWinds, possibly via SolarWinds's Microsoft Office 365 account, which had also been compromised at some point. SolarWinds was using build management and continuous integration server TeamCity provided by the Czech company JetBrains. In 2021 The New York Times stated that unknown parties apparently embedded malware in JetBrains' software and through this way compromised also SolarWinds. https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach https://en.wikipedia.org/wiki/2020_United_States_federal_gov... I don’t know what kind of software you write, how valuable your company’s infrastructure is, etc. But supply chain and insider threat in security/infrastructure is a big topic — that I’m sure they’re concerned about because that’s their area of responsibility. Even if I’m personally sympathetic to not wanting to deal with the churn of dev dependency updates.
- abrookewood 3mo agoI believe the term is Beg Bounties and they are constant and annoying.
- jacobgold 3mo agoI hated these low-effort reports, so I created a simple automation that checks my security inbox, mentions me in #security on Slack for things that look legitimate so I see them quickly, and marks things that seem entirely automated as spam. I still check the spam folder for legitimate emails, but so far there haven't been any false positives.
- wolfi1 3mo agobut why would you answer with a C&D if you are overwhelmed? provided, it's not always the same person?
- ActorNightly 3mo agoIts been like that for half a decade across all software. People act like finding a linux kernel bug is a big deal, completely ignoring the fact that in order to exploit that bug, the attacker has to be able to run code on your computer in the first place, which is extremely hard to do these days remotely. Also people ironically just DGAF that much. The last actual bad exploit was log4shell in java, which given how it was introduced (i.e someone purposefully at Apache made it so a log statement can execute code, and nobody questioned it before pushing it to prod), should have been the signal for everyone to completely remove all Apache libraries from their services, but yet all the software is still being used.
- Tepix 3mo agoThese bugs are indeed important, you need them once you‘ve found a bug in an application.
- ActorNightly 3mo agoIf someone manages to get remote code execution at user space on a machine, the amount of damage that they can do with just that versus having a kernel level exploit is about the same.
- pixl97 3mo agoAh yes, just move away from all apache libraries, should only take a day or two.
- ActorNightly 3mo agoNo I agree, its a pain, but its necessary if you care about security and don't want to audit every single release for potential vulnerabilities. People don't do this, so they really don't care that much.
- gucci-on-fleek 3mo agoYeah, I help review security reports for a small FOSS organization, and someone reported a "critical" vulnerability about a publicly-accessible SVN server. Like yes, that is indeed the purpose of hosting open source software. But at least that report was obviously bogus; much worse are the ones that look legitimate at first, so you have to read through dozens of AI-generated paragraphs to make sure that there's nothing valid hidden in there.
- saaspirant 3mo agoI use AI to read such emails!
- swiftcoder 3mo agoWe also get unsolicited vulnerability reports from companies trying to poach our annual pentest contract, which is... a tad grey ethically-speaking
- deleted 3mo ago[deleted]
- mooreds 3mo ago> As someone running a company, I get 2-5 unsolicited "vulnerability reports" per week. Half of them are an LLM finding some bad CSS on our framer splash page. The other half I assume are an extortion attempt so we just mark as spam. I don't think that is unique to the LLM era. The company I work for has been getting some form of spam vulnerability reports years before LLMs were a thing. Often similar to what you mention about 'bad CSS'. Maybe the volume has increased a bit, but we've added in a filtering solution and I'm more distant from the reports now, so hard to be sure.
- matthewdgreen 3mo agoVulnerability reports are a voluntary service to help a vendor or software project. It’s often an annoyance for the security researcher. I understand people are getting slammed and it sucks, but the main result of rejecting them is going to be an increase in full disclosure. As a note: if you have a bug (that isn’t devastating but you’d like to talk about) having an LLM write up the disclosure is a great way to check the “we disclosed responsibly and they didn’t care” box.
- FiloSottile 3mo ago> I understand people are getting slammed and it sucks, but the main result of rejecting them is going to be an increase in full disclosure. Right, what I'm saying is that letting those bugs go to full disclosure (aka being filed as public issues, like every other bug) would have been a significant damage to user safety a year ago, and it's not anymore.
- matthewdgreen 3mo agoI think that’s an assumption. Just because an LLM might be able to find some bugs does not mean every attacker has a packaged attack, or the right prompting. The easiest way to find a vuln is just to Google for it.
- woodruffw 3mo agoI agree with this. One of the consequences of the "vulnpocalpyse" is that it's become even harder to sift through the noise: I triage well over a dozen reports a week, many of which are "real" in the sense that they reflect a genuine defect but otherwise have an unclear impact on a typical user. This has always been true of the median vulnerability report, but the volume means that I now lean much more heavily away from coordinated disclosure. One flipside to this is that, because many of these bugs are "shallow" to LLMs, it's actually easier than ever to moderate the worst participants in your vulnerability program -- if someone sends you slop, you can just ban them and wait for the next, better orchestrated LLM to send you a better report for the same vulnerability.
- notnmeyer 3mo agothis is hilarious and i might try it.
- cadamsdotcom 3mo agoSecurity through obscurity was never a great strategy.. and now it’s not a strategy at all.. Hopefully at the end of this decade, a ton of software practices have been overhauled to eliminate classes of problems. Memory-safe language use is a great start - but it’d be great to see innovation in checking for TOCTOU problems, improper/missing authn & authz, and many others. This is an engineering problem. It won’t be solved by models that “only do dumb shit 1/10th as often, only 0.01% of the time now not 0.1%!” It won’t be solved by adding more models to do even more double-checking before and after the work. It won’t be solved by hoping humans catch it in review. It isn’t solvable by adding outer loops of any sort - though we may get close. To truly solve this will take serious CS research.
- user3939382 3mo agoVerifying correctness of an implementation is P NP, not serious CS research.
- bawolff 3mo agoVerifying behaviour of an arbitrary program is uncomputable. However that doesnt mean you can't have proofs of behaviour of specific programs you create. Personally i have some doubts, a lot of research has gone into the idea without much to show for it, but its a very reasonable research area.
- crote 3mo agoI fear it'll just move the problem one layer up. Sure, you've now proven that the code matches the specification - but how do you ensure the specification is watertight?
- jopsen 3mo agoThe specification doesn't have to be. But yeah, writing specs is usually harder than reviewing the code 4 times :)
- david_shaw 3mo agoAt risk of quoting too much of the article, it opens with this: > A requirement for staying sane while working in public as an open source maintainer is realizing that every issue, PR, and piece of feedback is a present, not an obligation. You can accept it, ignore it, and use it partially or not at all. > Except… > For years, as lead of the Go Security team at the time, I’ve told new team members that it doesn’t apply to vulnerability reports. No, vulnerability reports are special. Security researchers are doing us a favor by reporting things confidentially instead of doing full disclosure, so we owe them something, which is not true of regular issues opened on the issue tracker. [...] > It’s 2026 and none of the premises are true anymore. I respectfully disagree. The premise is absolutely still true: if someone discovers a critical, exploitable vulnerability in your software, the impact and tradeoffs are exactly the same as they were before LLMs started finding bugs. There are just more of them now, so they're easier to come by. But that won't last forever, either. As LLMs find increasingly difficult-to-find vulnerabilities, there will be fewer of them to report. This is just chugging through the backlog. All of that said, I don't think finding vulnerabilities has really been the difficult security problem for most companies (or open source projects). The difficult problem is dedicating resources to fixing those vulnerabilities instead of building software, products, and/or infrastructure that people want. That problem is absolutely still here today, but I'm optimistic that agentic security developers will be able to take the burden off of development teams in the near future. For tokens, of course.
- CJefferson 3mo agoThe problem is there used to be a fairly high correlation between ‘security report’ and ‘real vulnerability’. Not perfect but good enough. Now the two are almost entirely disconnected.
- appplication 3mo ago> But that won't last forever, either. As LLMs find increasingly difficult-to-find vulnerabilities, there will be fewer of them to report. This is just chugging through the backlog. I think your logic is partly correct but the fact that the same LLMs are allowing an exponential increase in insecure code generated is a counterbalancing point. I do not think this phenomena will slow down.
- zeveb 3mo ago> If a security vulnerability is reported by someone who is also violating the CoC, what do you do? Do you ignore it? Fix it silently? Is this even a question? You triage and fix the vulnerability just like any other one. Are truths spoken by folks one dislikes — even for perfectly valid reasons — any less true? The only way I can imagine this somehow applying is if someone has a habit of reporting vulnerabilities which do not exist, or of exaggerating their severity. Is crying wolf a CoC violation? If so, then I can imagine that particular sort of bad behaviour justifying some consideration before acting on a report.
- calvinmorrison 3mo agoWill xorg backport patches from Xlibre?
- inigyou 3mo agoNo, because xorg is a dead project that doesn't take any patches from anywhere and xlibre has shit code quality and is probably vibecoded now
- calvinmorrison 3mo agoreally? From what I have seen so far most of the contributions to xlibre have been cleaning up stuff thats been obviously wrong in xorg, and using tools - including AI and more bog standard tooling to find issues, add safety checks, and a whole lot more. They're merging in a namespace extension which solves many of the purported 'security' issues in X11 today.
- fragmede 3mo agoHow badly are they violating the code of conduct? It wouldn't be the first time a security researcher got thrown into prison or jail, in this line of work.
- bawolff 3mo agoThere are some problems with incentives in the vuln report space. People report trivial vulns and expect the same treatment as people reporting critical vulns. But this isn't new with AI. Look at all the ReDos vulns in npm ecosystem. Its questionable if its a vuln in general but half of them aren't even triggerable.
- skybrian 3mo agoI'm wondering whether this is a permanent change. After all the easy-to-find bugs have fixed and you can't find them just by asking an AI, perhaps security issues will deserve special treatment again.
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- agolio 3mo agoTangent point, I think more broadly this is a big piece of AI-cynicism in general- “x isn’t special anymore”. It’s tough staying motivated on a craft when an AI is nearly as good as you. Chess players manage to do it at least.
- Avicebron 3mo ago> Chess players manage to do it at least. The 5 on earth still getting paid to play chess?
- fragmede 3mo agoThere's only one Magnus Carlsen, who earned > $1 million in 2025 for playing chess, but the long tail, there were 26 people who made more than $100k, https://thechessworld.com/articles/general-information/the-15-highest-earning-chess-players-of-2025/ https://thechessworld.com/articles/general-information/the-1... but like, if you mean literally "someone gave them money and they played a game of chess", the number becomes much bigger. Chess coaches, streamers, club instructors, exhibition players, league players, camp counselors, and titled players receiving appearance fees, etc. All told, you're looking at ten's of thousands across the world.
- moi2388 3mo agoAnd if you mean “people who can live off of tournament winnings” it’s not more than 26. It’s like most of art, writing, and sports. The only way to make money is by becoming a teacher.
- z0ltan 3mo ago[dead]
- jerrythegerbil 3mo agoVulnerability reports were never special. The _demonstration_ of security impact through vulnerability reports was special. The automation of “demonstration of impact” with AI isn’t that at all. The last mile is human and always was. This isn’t to say it won’t change in the future, but that’s a fact of where we are now. Vulnerability reports aren’t special anymore. They never were. It was the impact, the demonstration, the communication that was special. When you realize that this is being written from the perspective of someone who does vulnerability reporting in a professional capacity, you’ll connect the dots. We took care to be kind and succinct because for many of us, we learned our skills from being on the development side of things first. Vulnerability reports aren’t special anymore. The only ones that felt special were the ones with human touch, the ones doing their job as an adversarial thinker, and taking the care to understand that net positive outcomes require coordination even if both parties don’t see eye to eye. Nothing has changed. It never was. You’re just inundated with AI slop; which as a practitioner who uses AI regularly I can say with absolute confidence. The end result is the same, the volume is increased, but the special thing was never the report itself. Finding a vulnerability was always the easy but high toil part. It was the care to communicate succinctly and be invested in the outcome that was special. Godspeed.
- kirici 3mo agoThis screams LLM to me and I couldn't bear to read past the second paragraph.
- ofjcihen 3mo agoThis x 1000 I’ve been screaming this from the rooftops. Impact is what was always important. No one is going to take down prod to do an emergency patch on an RCE that COULD NEVER ACTUALLY BE EXPLOITED. I feel like we’re witnessing the result of multiple roles suddenly becoming security aware but not having the background or understanding to make any sense of it.
- cpuguy83 3mo agoIn an ideal universe yes. But we live in a world where vulnerability scanners reign supreme.
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- fastball 3mo agoThey weren't special even before LLMs. Drive-by script-kiddies would run some basic scripts against your platform and send generally-not-actually-a-vulnerability reports, claiming that these were big problems, and requesting to be paid bug bounties.
- mbauman 3mo agoAnd then they submit them to a CNA and get a CVE assigned, and then _everyone_ needs to deal with the not-actually-a-vulnerability report, especially when the not-actually-triggerable-DOS gets assigned a "Critical" CVSS score from EUVD or NVD.
- deleted 3mo ago[deleted]
- socalgal2 3mo agoI feel like the current situation is temporary. LLMs are finding all the bugs. LLMs are also help fixing most of the bugs. Once most of the bugs are fixed, LLMs should be good at finding bugs before shipping them, the stream of bug reports will die down, and we'll be back to vulnerabiltiy reports being special. Further, the fact that bugs are so easy to find by LLMs means there is strong incentives to find ways to minimize creating bugs in the first place. That could be new or better languages, less 3rd party dependencies, more vetted code, better linters, better fuzzers, whatever. The point the new reality of bugs being easy to find will, actually must, lead to less bugs eventually because the world can't function with easy to find bugs.
- fajmccain 3mo agoLol you think LLMs are generating bug free code?
- socalgal2 3mo agoI never said that. I said they are good at helping fix them. Go read the bug reports on firefox, or Safari, or Chrome. Most of them have a fix. It might be wrong but it usually points in the right direction, which is a 1000x more than nearly all human bug reports. So, the LLM helps. which is all I stated.
- mackenney 3mo agoThat supposes that LLMs can write secure software. Also, if we assume that finding bugs is easier that not creating them (reasonable I would say), the supply of bugs will never be exhausted.
- enraged_camel 3mo ago>> A requirement for staying sane while working in public as an open source maintainer is realizing that every issue, PR, and piece of feedback is a present, not an obligation. I don't think the gift analogy works well. In most cultures, turning down or even ignoring a gift is considered anywhere from impolite to hugely offensive. But that's the opposite of open source: there's nothing wrong with requesting changes to a PR or even closing it.
- cpuguy83 3mo agoPlenty of people offended by closing a PR or issue unresolved.
- naturalmovement 3mo agoLinus Torvalds once went on record saying security vulnerabilities are no more important than regular bugs. This of course made vulnerability researchers seethe worse than aggrieved Redditors. It turns out he was right all along. The author also gets it wrong by assuming that regular bug reporters are not "providing a service". They are. When I wrote up a bug report, I made sure it's thorough with detailed steps to reproduce. It takes a lot of time and I've done it professionally for projects you've absolutely heard of. Having said that, getting them ignored repeatedly and — even worse — having my detailed PRs rejected, sometimes within minutes, as if I'm some ignorant luser is why I don't do it anymore. My time is more valuable than your hubris. A lot of open source developers have their heads so far up their own asses they forgot that it takes a community for projects to be successful.
- bcjdjsndon 3mo ago[flagged]
- thoangai 3mo ago[flagged]
- sans_souse 3mo agoI'm curious about people's experiences with Kalshi support in this context.
- deleted 3mo ago[deleted]
- jamesjhare 3mo ago"LLMs are as good as almost any security researcher" No they are not. Everything else can be safely ignored. The author is suffering from AI psychosis and needs to get some help.
- deleted 3mo ago[deleted]
- _el1s7 3mo agoEveryone here is apparently, that's why you getting downvoted.
- deleted 3mo ago[deleted]
- qbane 3mo ago> LLMs are as good as almost any security researcher, and anyone can run them. I wonder what the metrics are. Also, not "anyone", just the affordable.
- shipfastai 3mo ago[dead]
- jongjong 3mo agoI found a DoS vulnerability in Coinbase several months ago on Hacker One. It took me literally 30 minutes to find. First time I did this in my life. I could craft a message cheaply which, when sent as the HTTP payload to a specific endpoint, would cause the server to hang for a full 30 or so seconds before getting a response. I could have easily scaled up that attack, cheaply... I filed a report, they marked it as 'informative' and thanked me, recommended I keep looking for more vulnerabilities, but no payment at all; they said I had to be able to demonstrate major disruption of service... Which I presume is illegal. I literally showed them all the ingredients of the attack, the exact curl commands, payloads, the exact response delay could be easily be verified; you could see the server response slowing down proportional to the degree of nesting in the payload. I could execute it without authentication too; so it was essentially certain that the attack could be scaled but they made it impossible to get a reward. The hardest part was writing the report which took several hours. So yeah, 30 minutes of looking for a vulnerability, no prior experience in security research, first project I looked into on Hacker One, ever... A company in crypto sector which is a major target of hackers and takes security relatively seriously. Imagine how insecure most software is! Imagine how bad most vibe-coded software is especially! Companies might as well run their servers directly inside Kim Jong Un's data center in North Korea. North Korean hackers probably have a dashboard which shows more detailed and accurate platform analytics than what the founders of the company can see.
- rakel_rakel 3mo agoI read every piece like this one as: Money is moving in the vulnerability space now, when as before the LLM hype incentivized that, your best bet was that someone skilled enough would accept living with the financial insecurity of being a gig worker to hopefully stumble upon your projects bug bounty program. Is the bet here is that the hype lasts, and that people willingly will keeping on paying Dario to be able to contribute? > But give it 1-3 months and the open models will catch up. I wish that this would stopped being thrown around, what is this timeline based on? How good is your open model from between March and May? Also, having read "Gödel, Escher, Bach" I know that the hare never catches up with the turtle.
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- jsmudda 3mo ago[dead]
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- aetherspawn 3mo agoLLMs find more vulnerabilities than people because people time is heaps more expensive than LLM time, that’s it. We’ve always been able to find heaps, we’ve just never had the right structures to put in the effort and renumerate people for looking (even if they don’t find anything).
- bluGill 3mo agoLooking for bugs is boring. LLMs don't get bored the same way humans do. Thus even if you had infinite budget you should expect a LLM to be better.
- deleted 3mo ago[deleted]
- maxignol 3mo agoIn the end, sorting prs and vulnerabilities has been the same for open source maintainers. How about adding a credibility score to every github account ? Couldn’t that cut sorting times ?
- dirkc 3mo agoThese two bits stand out to me: > The security researchers are not special, the insight and confidentiality are vs > The bottleneck now is not finding potential issues but assessing which ones are real. Unless there’s already a trust relationship, external researchers can’t meaningfully contribute My take-away from this is that the researchers were special all along and you should probably be building a trust relationship with them. Despite what I want to believe about tech being a meritocracy, the reality is that trust plays an extremely important role and without it we risk a collapse of our open source software ecosystem. One of my biggest criticisms of AI is the trust vacuum within which it operates
- jupenur 3mo agoThis whole blog post makes me sad. I've been active on both sides of the vulnerability disclosure process for well over a decade and have reported a whole bunch [1] of security bugs to the Go security team. I was there back when Filippo was running the show and have continued since Roland took over. My experience with the people there has always been great. > Ultimately, it all stems from our responsibility to our users. The security researchers are not special, the insight and confidentiality are, and we need them to keep our users safe. Ignoring a security report communicates you don’t care about users’ security, and it’s rightly a reason for shame. 100%. This was always true and I still think it is. LLMs don't change anything. At most they shift the balance and force a temporary compromise. > LLMs are as good as almost any security researcher This statement is extremely dependent on the definition of a security researcher. It might hold if you consider anyone with a HackerOne account, but if you restrict the definition to people who actually put in some effort, it's just not true. LLMs can find some real vulnerabilities, yes, but they also spew unprecedented volumes of garbage that an expert can immediately recognize as such. > The insight is not scarce and precious anymore. The bottleneck now is not finding potential issues but assessing which ones are real. Assessing which ones are real should be part of the insight. Real researchers will not submit 150 pages of spam, and three real bugs hidden in 150 pages of spam are not insight. In most cases a researcher will spend significant effort on triage before submitting anything, and an LLM still cannot do that reliably. > Confidentiality, embargoes, and coordination also don’t matter nearly as much as they used to. I'd argue these now matter more: the one thing LLMs do seem to do fairly well is figure out specific things based on sufficient information and a scope that's limited enough. So a plain commit containing a security fix is now much easier and cheaper to turn into an exploit than it was before. > The years of vulnerability reports being special might be over, as weird and uncomfortable as that feels. I'd hope not. Bug bounties might be over unless someone can figure out the spam problem, but disclosure programs that don't offer monetary incentives are probably just going through a tough period that will eventually calm down as the operators of LLMs realize the costs and do the math. Unreliable reports have always been an issue and will remain one, LLMs or no. When it gets worse, like in the current influx of LLM-generated reports, the focus should be on identifying reliable researchers, building relationships, and providing guidance on how they can make the reports easier to triage. Researchers are not special, but the insight they can provide totally is. LLMs might force everyone to make better use of that insight, instead of just consuming bug reports and drowning in triage. [1] https://groups.google.com/g/golang-announce/search?q=juho https://groups.google.com/g/golang-announce/search?q=juho
- jybuilds 3mo agoI agree. Accoding to a security engineer I know, the impact of mythos is enormous.
- mawadev 3mo agoI read a casual teams message from one consultant type of guy who said "the low level linux hackers who don't care about best practices, code quality and security get what they deserve". I don't know how to feel about this other than disgust. The entire space has been overrun by LLMs making stuff up or finding things that aren't critical while some roles capitalize on the fear. There is just so much wrong with saying such things in such a way, I couldn't describe. This entire demeanor of the way people and ai people talk about software and technical people is getting absurd and simply unprofessional. It is as if we stopped being adults.
- _el1s7 3mo ago> LLMs are as good as almost any security researcher, and anyone4 can run them. What is this, rage bait? It's bullshit, and insulting to actual security researchers. That might be true for low-effort vulnerabilities and fake security researchers, but the real security researchers are far from being replaced by LLMs.
- sheerazali 3mo ago[flagged]
- iepathos 3mo ago"LLMs are as good as almost any security researcher" Oh really? If LLMs were as good as almost any security researcher then you wouldn't be getting flooded by bullshit reports from them. You'd be receiving legitimate reports instead.
- ivlad 3mo agoReally. Back in the days, the majority of “researchers” sent scan results. The term “beg bounty” didn’t come about for nothing.
- zadg 3mo agoI think the main impact of this is that a successful career in vulnerability research is going to require a high level of proficiency in exploit development, as that's where the demonstrable real-world impact lies.
- wobbat 3mo agoHonestly, even that is something LLMs are becoming scarily good at. Not all of it, but they have surprised me, including in terms of exploit development, more than I am comfortable with.
- muldvarp 3mo agoTech careers no longer exist. Tech jobs will still exist for a few years, but careers they will no longer be.
- gib444 3mo agoI guess we now need AI tools to filter security report spam. I'll go out on a limb and say such products already exist.
- vlindos 3mo agoStella Ops has call paths, vulnerabilities classifications, VEX to mitigate most of these: https://stella-ops.org/features/ https://stella-ops.org/features/
- vlindos 3mo ago[flagged]
- torginus 3mo agoI wonder if LLM's 'jagged intelligence' will come to bite here again. AI might be better at finding certain kind of bugs, to the degree outperfoming the best humans, but that doesn't mean a skilled human can't find an issue which is hard for LLMs incredibly easily.
- alper 3mo agoWere they ever "special"? The inbound stuff we get through the vulnerability e-mail is pretty much exclusively spam. Then they start e-mailing random people of the company they can find to get through, and in the end it's still spam.
- 0x1622 3mo agosoo true
- AmbroseBierce 3mo ago>I honestly have no idea how the profession will look after that, so this whole post is more of a current observation than a long-term prediction. My sweet summer child, the "profession" will become an agent managers talk directly to, like many other professions.
- parasense 3mo agoCan anybody say what is going to happen? It's not a rhetorical question, and the implied or entailed context might involve a Nash equilibrium of some sort. Right now the rate of signal is high, and the ratio of noise is proportionally high. But it seems like everyone expects the signal to eventually plateau or sharply decline. Almost as if there is a finite supply of "low hanging fruit" for shallow scanning machines to easily discover, and then there will be some kind of new world that follows where only truly difficult problems emerge. But eventually the question then becomes why even bother with Rust or any other silly borrow checking ideas if we can use more enjoyable programming languages with LLM side-kicks to catch security vulnerabilities on the front side of the development workflow? IT seems to me if we exhaust all the extant security vulnerabilities to a calculus that asymptotically goes to infinitesimal zeroness, then... the only trick remaining is to scan code before it becomes vulnerable.
- Goofy_Coyote 3mo agoSecurity Eng here. The whole thing is an absolute mess. I’ve been (and still am) on both sides of the fence. I currently have two reports (one RCE on a famous OSS ML platform, one cluster take over on a k8s related projects), both are more than 2 months old without as much as an “F you, get lost”. Just got ignored and ghosted, which hurts a lot, because I spent a lot of time finding, and verifying these (all reports with poc and patch). BUT I understand why it’s happening, because I’m also on the receiving end. security@ and VDPs have always received BS reports and beg-bounties, but boy oh boy, these days we have two people spending 3-4 days a week sifting through this constant flood of garbage compared to 2-3 tears ago where 1 person could triage the inbox and VDP in a day’s work max, which would’ve been considered very busy. Unfortunately we can’t just shutdown the programs or the mailbox because 1. We do occasionally get important and great stuff that actually matters, and 2. We’re a critical infra company and can’t ignore anything really. The signal to noise ratio is almost zero, but the “what if” is keeping us swimming through this unending river of garbage and burning us out. Overall, chaotic mess on both sides. Ending on a doom-and-gloom note: there will be a reckoning. (Don’t take the note too seriously though, I’m a SecEng, so I have a built-in doom multiplier lol)
- PaulStatezny 3mo ago> Ending on a doom-and-gloom note: there will be a reckoning. Can you elaborate on what you mean by this?
- philipwhiuk 3mo agoI imagine: AI vulnerability analysis is going to find something, it will be reported by a researcher and ignored as chaff, and then separately, later, someone will build it into an exploit and compromise a piece of critical national infrastructure
- -mlv 3mo agoHave you considered using LLMs to perform some automated more-or-less reliable classification of incoming reports by severity, affected product, etc., then have agents try to replicate the reported findings? Ideally the reports would also be coming in in the same structured format.
- deleted 3mo ago[deleted]
- ksajadi 3mo agoCannot agree more. As part of our SOC2 we have to log and respond to all inbound vulnerability reports. Before it was easy to tell if a report was just a bounty hunter looking for a low hanging fruit. Now well crafted emails with seemingly legitimate disclosures take a lot of time to validate and triage. Our solution was to build a tool that uses LLMs to assess the report before it gets to us. Honestly I wish we didn’t have to do this but it works and has really allowed us to spend our time on the actual good reports. (Feel free to check it out at fortworx.com if you want)
- JohnMakin 3mo agoThese kinds of posts act like there wasn't already a rich suite of automated security scanning tools available. The fact you can put them in a LLM's hand or point it at a codebase to do the exact same thing isn't really a big leap, the spam is. It's a bunch of amateurs thinking they can do work outside of the realm of their expertise now, and this trend isn't unique to security, you see it spreading across the various realms of expertise out there in the world. The world's slowly filling with slop, and CVE spam is a byproduct of that.
- MoAz06 3mo ago[flagged]
- casey2 3mo agoYet again it's <person who is not an X> saying that AI can replace the job of an X. Take a hint people, if AI can't replace your job it can't replace anyone elses'.