• Jo Miran@lemmy.ml
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    6 days ago

    Infosec professional for almost 30 years here. I can confirm that the latest iterations of AI models are finding high quality bugs and vulnerabilities in the code we work with. If Daniel has access to Mythos, I suspect his experience would be even more shocking.

    The problem I have is that the AI tools can find bugs faster than they can be patched, which is eventually going to prompt companies to use AI to patch bugs found by AI. Before long, no living being will be able to make heads or tails out of the code we run. Just my 2¢.

    • utopiah@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      5 days ago

      AI tools can find bugs faster than they can be patched

      Not a security expert but wasn’t that the case already? It feels like before AI there were already a lot more bugs, security related or not, on backlogs. That’s precisely why there are metrics like severity.

    • kibiz0r@midwest.social
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 days ago

      Perpetual loop of “bounty encourages bad reports”, “canceled bounty”, “bug reports improve”, “bounty comes back”, “bounty encourages bad reports”…

      • thingsiplay@lemmy.ml
        link
        fedilink
        arrow-up
        4
        ·
        6 days ago

        bounty also encourages good reports. So your argumentation is that the bounty program is the reason why reports were bad lately? I don’t think that is the reason and bringing it back will not make it that worse again.

    • ffhein@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      6 days ago

      If they are getting valid findings with high quality reports from AI tools already, why would they do that?