VulnHunter: Capital One's agentic AI code security tool
21–30 of 45 posts
Re: VulnHunter: Capital One's agentic AI code security tool
#22All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat
Re: VulnHunter: Capital One's agentic AI code security tool
#23Re: VulnHunter: Capital One's agentic AI code security tool
#24https://github.com/visa/visa-vulnerability-agentic-harness
https://github.com/cloudflare/security-audit-skill
I'm on the fence here, for one as from recent Linux mailing discussions those tools can really find good bugs (51% of them?), but on other side - I'm afraid of false sense of security.
Re: VulnHunter: Capital One's agentic AI code security tool
#25All these security/vulnerability scanning harnesses look more or less the same. Not sure what’s the point of bragging or publishing about them anymore, there’s no moat
They're desperate for the hype.
fwiw I have seen good whitepapers from them. A while back I used one about their IVR to get exec buy in for re-doing my company's IVR into something a lot better.
Re: VulnHunter: Capital One's agentic AI code security tool
#26https://github.com/capitalone/VulnHunter/blob/main/vulnhunt/...
Re: VulnHunter: Capital One's agentic AI code security tool
#27Why does this feel like an exec trying to justify token spend?
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
Forget AI—you even have to justify using a MacBook.
Re: VulnHunter: Capital One's agentic AI code security tool
#28Why does this feel like an exec trying to justify token spend?
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
Re: VulnHunter: Capital One's agentic AI code security tool
#29Earlier quoted context omitted.
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
Don’t underestimate how banks operate. Things move very slowly in banking, so they absolutely need to justify it. Many banks still use GPT Mini, and even that requires approval from two levels of management. Even upgrading from Java 8 to Java 17 requires extensive justification. Forget AI—you even have to justify using a MacBook.
Re: VulnHunter: Capital One's agentic AI code security tool
#30Earlier quoted context omitted.
They dont need to justify it. Sorry to say, tokens aren’t going anywhere, people aren’t going to suddenly stop using AI, and this whole paradigm shift of how people are changing how they work - is a full blown reality. There is no reversal, no “eh we don’t think the tokens/AI are worth it”. Accept the new reality.
We also have to stop treating any criticism of some practices surrounding AI adoption like a rejection of the technology.
It doesn’t take a genius or system architect to figure out AI use in banking both internally and for consumers is a huge benefit especially for capital one.
Maybe we should critique the actual agentic products they are creating rather than critique the entire AI spend.