Live data from Hacker News

Anthropic's open-source framework for AI-powered vulnerability discovery

github.com

111–120 of 177 posts

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#111
post #95
post #18

The thing about things like this is that they're shop jigs. You can buy a crosscut sled if you really want to, but most woodworkers just make their own. It was a different situation 2 years ago, when there was significant cost to building your own harness (but then: you probably weren't doing AI vuln research 2 years ago). Today, I think your best bet is to look at something like this for ideas, and then just ask for…

I’ve been looking for a way to articulate this shift, and your analogy nails it. The value of libraries and infrastructure components in software engineering is eroding fast. I am sure that in many organizations, teams responsible for this sort of work have less and less users coming to them.

Maybe for developer tooling, but on the consumer app side I think it's the opposite: MusicKit is much more valuable than Music.app now, because Claude can one-shot most reasonable things you could ask it to do. I think there's actually more value in ambitious libraries than there was 5 years ago, when any serious use of a library entailed a minimum 5-figure investment of time.

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#112
post #86

Earlier quoted context omitted.

Sort of? The definition of "bad" from a security PoV is rapidly expanding, in light of relatively new capabilities and increasingly cheap access to exploitable vulnerabilities.

I don't think the definition of "bad" is expanding. Rather the ability to detect and exploit "bad" is.

fair point. another way of putting it might be to say that, for all extant software, much more of it is "bad" than we realized even a month or two ago -- and the cost to create and maintain "good" software is increasing (even as the naive / surface-level / apparent cost is plummeting)

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#116
post #18

The thing about things like this is that they're shop jigs. You can buy a crosscut sled if you really want to, but most woodworkers just make their own. It was a different situation 2 years ago, when there was significant cost to building your own harness (but then: you probably weren't doing AI vuln research 2 years ago). Today, I think your best bet is to look at something like this for ideas, and then just ask for…

Sure it’s possible for anyone to build a harness if they had the inclination, but most people don’t have the inclination to do that.

And even if you did… I spent months refining AI workflows that were just obsoleted by ultracode.

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#117
post #86

Earlier quoted context omitted.

I don't think the definition of "bad" is expanding. Rather the ability to detect and exploit "bad" is.

fair point. another way of putting it might be to say that, for all extant software, much more of it is "bad" than we realized even a month or two ago -- and the cost to create and maintain "good" software is increasing (even as the naive / surface-level / apparent cost is plummeting)

Same thing happened with the growth of the internet. There was a time when there was basically no consideration of buffer overflow.

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#118
post #14

To be sure, security is an amazing AI/LLM use case. A huge swath of the work is pattern matching known security issues against stuff that's very precise to analyze -- programming language text. Something that stands out is that for the strongest use cases, AI companies will prefer to sell the technique as a service rather than its raw output. For use cases where the output is less valuable, tokens are sold. If AI tok…

> The same way as someone selling an expensive course in the stock market is signaling that they have more to gain by selling the course rather than Or they want to diversify > If AI tokens were so magical in creating new value in developing software applications generally, they wouldn't be selling tokens directly. That requires to build and sell a whole product they have little experience with, competing with their…

What market is hotter than AI models? Do you think their energy would be better making games or image editing software?

Re: Anthropic's open-source framework for AI-powered vulnerability discovery

#119
post #83

Earlier quoted context omitted.

Unless it is very specific to a proprietary product, craftspeople take their jigs with them from job to job, building up a personal library over a career. As a software developer I've always had a well-tuned IDE and shell config in a safe place. Something I think about a lot is what is the equivalent for the software builders of today using AI tools? how do make these harnesses exportable and portable? You might thin…

Using something like pi helps. I've made my own dotfiles for skills/extensions I like and can install them just like my normal dotfiles https://github.com/anishthite/agent-dotfiles

"Humor When you finish a job — completing a task, answering a question, fixing a bug, shipping a feature — end your final message with one short funny line. A quip, a dad joke, a wry observation, a playful self-roast. One line. No emoji spam. Make it land, then shut up."

whats the purpose of this? just fun or does it cause some desired behaviour?

Post reply on HN