Earlier quoted context omitted.
It's weird because why can't they train the AI to simply output secure code? The basic security flaws with regards to input validation and overflows should never ever be output by an AI. For "security flaws due to bad design" I'll cut them slack until AGI is achieved.
What's destabilizing the industry right now isn't vulnerabilities AI introduces into new code; it's a flood of sev:hi vulnerabilities in existing code, not introduced by AI but discovered by it.
Anthropic's open-source framework for AI-powered vulnerability discovery
171–177 of 177 posts
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#172Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#173Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#174Earlier quoted context omitted.
I never seen any other kind of contract, on my 50ys.
I'm curious how does it work, you handover the tools you wrote, .bashrc/.zshrc, etc? When I'm hired in a company (not contract), they wipe the harddrive when I leave (well, I also do it before I hand it over sometimes). So they don't get the tools (I take them with myself, it would be a waste to loose them)
As per NDAs and work contracts, nothing is supposed to leave either employer nor customer systems into unauthorised third parties.
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#175Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#176Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#177Earlier quoted context omitted.
I never seen any other kind of contract, on my 50ys.
I'm curious how does it work, you handover the tools you wrote, .bashrc/.zshrc, etc? When I'm hired in a company (not contract), they wipe the harddrive when I leave (well, I also do it before I hand it over sometimes). So they don't get the tools (I take them with myself, it would be a waste to loose them)