4 ms·
Exactly, the entire AI industry has been trying to create an AI powered security arm race. I am not necessarily blaming them. Hard to know how much has been th
by sunshine-o 3mo ago
Exactly, the entire AI industry has been trying to create an AI powered security arm race. I am not necessarily blaming them.
Hard to know how much has been thrown into this but I would bet a lot.
So far I have been very surprised we haven't been flooded by those type of announcements. If you look you will always find something and OpenBSD is the top price.
- cratermoon 3mo agoThey are throwing tokens at codebases and finding mostly vulnerabilities in cases that have not been worth the limited time and effort of the chronically underfunded and understaffed professional groups. There’d be a lot more value in the companies giving the money they spend on their synthetic text extruders to the organizations doing quality security research work.
- anuramat 3mo ago> they are ... finding ... vulnerabilities ... that have not been worth the time and effort ... that's kinda the entire point
- dTal 3mo agoThe point of the comment you are replying to is that it's also not worth the time and effort to use LLMs to find vulnerabilities, if "time and effort" can be measured with "money". If you factor in all the money spent on training, GPU data centers etc, it's not actually a financially efficient way to find bugs unless you profit from creating demand for LLMs. LLMs aren't cheaper than humans per unit work, yet. They're just massively deficit funded because capital thinks "AI" is going to reshape the world order, and wants in.
- anuramat 3mo ago> it's not actually a financially efficient way ... unless you profit from creating demand for LLMs well, they do? it's a win-win, you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers > If you factor in all the money spent on training why would I? it's not a cybersec-specific model
- dTal 3mo ago>you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers Sure I can, if they - or you - pretend "the entire point" is about useful security work rather than expensive loss-leading marketing and demand creation. We shouldn't look at this and think "wow AI is super useful for security". We should look and this and think "wow, there's a LOT of capital going into persuading us that AI is super useful for security". THAT is "the entire point".
- anuramat 3mo agosecurity researchers are using the free tokens that they get to do useful security work, AI labs are giving away free tokens to maximize their profits; is it really that hard to imagine that different parties might have different goals? > We shouldn't look at this and think you're gonna tell me what to think now?