3 ms·
The ability to audit the code. If not that, the ability to trust the reputation of the author which creates an incentive not to willingly insert a backdoor. Y
by za_creature 6d ago
The ability to audit the code.
If not that, the ability to trust the reputation of the author which creates an incentive not to willingly insert a backdoor.
Yes, `npm install` was always bullshit because most people didn't bother to check, which is exactly why it was exploited multiple times, which created a conversation about "supply chain security".
If you want to argue that "npm changed the world" then you are correct. It did not change the world for the better though.
- williamcotton 6d agoWhy is LLM code always harder to audit? So LLMs might decide to add backdoors without prompting?
- za_creature 6d agoI'm less worried about what LLMs decide and more about what their system prompts tell them to do.