Live data from Hacker News

SQLite Critical CVEs or LLM Slop?

research.jfrog.com

1–10 of 407 posts

Re: SQLite Critical CVEs or LLM Slop?

#4
The problem with this kind of thing, is that it reduces the S/N (Signal-to-Noise) ratio, so weeding out the legit CVEs becomes a lot more difficult.

But, on the other hand, I do know that LLMs have been discovering a lot of legit CVEs, and I will lay odds that the blackhats are leveraging them to the max.

Re: SQLite Critical CVEs or LLM Slop?

#7
post #3

This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?

This was my first thought, this could be terrible if used offensively.

The best defense I can imagine is to have an agent reproduce the issues before a human sees it, but even that will cost money.

Re: SQLite Critical CVEs or LLM Slop?

#9
post #3

This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?

I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).

Re: SQLite Critical CVEs or LLM Slop?

#10
post #9
post #3

This is going to be fun for organizations that are mandated to patch all CVEs, isn't it?

I'm very curious what organisations would have such a policy. I can't imagine it being viable for any size of org without significant self-deception (or banning the use of all open source at which point CVEs are moot anyway).

ITAR
Post reply on HN