3 ms·
From the Twitter advisory [1]: >>> To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find la
by nonfamous 2mo ago
From the Twitter advisory [1]:
>>> To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.
Kinda turns the “many eyes” principle of OSS on its head, eh?
[1] https://x.com/nvk/status/2083216713693151552?s=61 https://x.com/nvk/status/2083216713693151552?s=61
- markjenkinswpg 2mo agoFrom my perspective, the bug became shallow because the machine world extended the number of effective eyes. The aphorism applied, but just not fast enough as it took too long to get the right number of eyes. More people would have been harmed had the bug been in production longer. One unfortunate aspect is that responsible disclosure would have only saved some people, a responsible disclosure would have lead to a notice to migrate seeds and bad actors would have immediately realized seed generation was the root cause and would have swept many folks before they could even see the notice for themselves and get around to migrating.
- lxgr 2mo ago> If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike. You better assume the same for closed-source software too. Turns out modern models are pretty good with decompilers...