All the fun vanishes.
XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
21–30 of 128 posts
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#22Earlier quoted context omitted.
One would think if AI can generate the slop it could also triage the slop.
How does it know the difference?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#23> XBOW submitted nearly 1,060 vulnerabilities. Yikes, explains why my manually submitted single vulnerability is taking weeks to triage.
The XBOW people are not randos.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#24> To bridge that gap, we started dogfooding XBOW in public and private bug bounty programs hosted on HackerOne. We treated it like any external researcher would: no shortcuts, no internal knowledge—just XBOW, running on its own.
Is it dogfooding if you're not doing it to yourself? I'd considerit dogfooding only if they were flooding themselves in AI generated bug reports, not to other people. They're not the ones reviewing them.
Also, honest question: what does "best" means here? The one that has sent the most reports?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#25Receiving hundreds of AI generated bug reports would be so demoralizing and probably turn me off from maintaining an open source project forever. I think developers are going to eventually need tools to filter out slop. If you didn’t take the time to write it, why should I take the time to read it?
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#26Like any "AI" article, this is an ad.
If you are willing to tolerate a high false positive rate, you can as well use Rational Purify or various analyzers.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#27Earlier quoted context omitted.
The XBOW people are not randos.
That's not their point, I think. They're just saying that those nearly 1060 vulnerabilities are being processed so theirs is being ignored (hence "triage").
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#28Earlier quoted context omitted.
HackerOne was already useless years before LLMs. Vulnerability scanning was already automated. When we put our product on there, roughly 2019, the enterprising hackers ran their scanners, submitted everything they found as the highest possible severity to attempt to maximize their payout, and moved on. We wasted time triaging all the stuff they submitted that was nonsense, got nothing valuable out of the engagement,…
Moreover, I don't think XBOW is likely generating the kind of slop beg bounty people generate. There's some serious work behind this.
Re: XBOW, an autonomous penetration tester, has reached the top spot on HackerOne
#29Earlier quoted context omitted.
HackerOne was already useless years before LLMs. Vulnerability scanning was already automated. When we put our product on there, roughly 2019, the enterprising hackers ran their scanners, submitted everything they found as the highest possible severity to attempt to maximize their payout, and moved on. We wasted time triaging all the stuff they submitted that was nonsense, got nothing valuable out of the engagement,…
Moreover, I don't think XBOW is likely generating the kind of slop beg bounty people generate. There's some serious work behind this.