Live data from Hacker News

SQLite Critical CVEs or LLM Slop?

research.jfrog.com

221–230 of 406 posts

Re: SQLite Critical CVEs or LLM Slop?

#221
post #198

Earlier quoted context omitted.

Every day I wake up and open HN. “LLM has made legitimate mathematical discoveries” —> Wow the rate of progress is amazing. Highly upvoted. “LLM does something not good” -> Does everyone else not realize LLMs are just dumb next token predictors? Highly upvoted. So tired of this discourse and this site.

The rate of progress can be high and they can also be dumb next token predictors. Not sure why that is hard to understand. These models can do a lot of things but they also can't do a lot of things. In order to use these models effectively you have to understand that they are next token predictors and how that allows it to do what they do.

Are they useful or not? Will they continue changing the world or not? People who choose one way or the other for describing them typically fall on one side or the other in these questions imo. What do you think? Will these next token predictors change the world or not?

Re: SQLite Critical CVEs or LLM Slop?

#222
post #221

Earlier quoted context omitted.

The rate of progress can be high and they can also be dumb next token predictors. Not sure why that is hard to understand. These models can do a lot of things but they also can't do a lot of things. In order to use these models effectively you have to understand that they are next token predictors and how that allows it to do what they do.

Are they useful or not? Will they continue changing the world or not? People who choose one way or the other for describing them typically fall on one side or the other in these questions imo. What do you think? Will these next token predictors change the world or not?

They are useful. They will continue to change the world. They are still next token predictors with all the problems that comes with that.

For them to change the world you have to work with them as next token predictors. Ensure that the next token predictor has enough prediction paths to solve the problems you want and so on. Since when they don't they fail spectacularly. These big companies will continue to add new skills to them, so they will continue to get more useful.

Re: SQLite Critical CVEs or LLM Slop?

#223

Earlier quoted context omitted.

I'm sending all my condolences out to everyone who is in a corporate environment using tools like Veracode or Snyk to automatically assess for CVEs and block merges or deployments based on "findings". My experience in such environments leads me to believe this is going to be a rough ride for those heavily locked-down enterprises, because depending on the environment, an exception of "this CVE was hallucinated by AI"…

They’re not bad if you give up on being able to reproduce arcane bugs. Don’t pin versions, pull everything from latest, CVEs are just a rebuild. Certainly not an amazing idea, but it solves the problem of the day. The funnier, Kafakaesque problem of the day is interactions with mandatory cooldown periods on new versions because of supply chain risks. I’ve had a couple tickets get stuck because the CVE scanner says I…

> Don't pin versions, pull everything from latest

Rebuild broke half your tests. People are exploiting the CVE against your system right now. Good luck!

Re: SQLite Critical CVEs or LLM Slop?

#224
post #198
post #52

We can chalk this up as another example of over-exhuberance by what folks believe LLMs can accomplish vs. what they actually are. LLM-based “AI” is able to use its vast corpus of inputs and calculate the most statistically likely output in a given situation. It is probabilistic, and when you are dealing with probabilities in a situation where certainties, not probabilities, matter, you’re going to get dinged on credi…

Every day I wake up and open HN. “LLM has made legitimate mathematical discoveries” —> Wow the rate of progress is amazing. Highly upvoted. “LLM does something not good” -> Does everyone else not realize LLMs are just dumb next token predictors? Highly upvoted. So tired of this discourse and this site.

Not sure what your point is? Those things can both be true.

Or should the discourse in a diverse community like HN only reflect the positions you personally hold?

Re: SQLite Critical CVEs or LLM Slop?

#225

Earlier quoted context omitted.

OK. A more pointed question. What do you know about intelligence that allows you to exclude LLMs with CoT from the category of intelligent systems with certainty?

How do you know there's not a teapot orbiting the sun?

There is no reason to think that teapots were sent into orbit or spontaneously formed there.

Likewise, there is no reason to think the brain employs super-Turing or quantum computations that cannot be approximated by LLMs.

Re: SQLite Critical CVEs or LLM Slop?

#226

The federal government ought to be funding NIST sufficiently to actually do sufficient analysis. Do we care about funding civil "cyber" defense or not? (Obviously the answer is not, we only care about funding offensive capabiltiies).

The federal government defunded the CVE program last year, I think, because it was woke.

Re: SQLite Critical CVEs or LLM Slop?

#227

Earlier quoted context omitted.

How do you know there's not a teapot orbiting the sun?

There is no reason to think that teapots were sent into orbit or spontaneously formed there. Likewise, there is no reason to think the brain employs super-Turing or quantum computations that cannot be approximated by LLMs.

The point is that you're asking someone to prove a negative.

Re: SQLite Critical CVEs or LLM Slop?

#228
This isn't great but a negative side effect of an otherwise positive change. I know a lot of comments will try to make this into a gotcha but its really not. Decreased friction leads to misuse. Just like before we'll figure out ways (reputation, light filter pass) to deal with it.

Re: SQLite Critical CVEs or LLM Slop?

#229
post #198

Earlier quoted context omitted.

Every day I wake up and open HN. “LLM has made legitimate mathematical discoveries” —> Wow the rate of progress is amazing. Highly upvoted. “LLM does something not good” -> Does everyone else not realize LLMs are just dumb next token predictors? Highly upvoted. So tired of this discourse and this site.

The rate of progress can be high and they can also be dumb next token predictors. Not sure why that is hard to understand. These models can do a lot of things but they also can't do a lot of things. In order to use these models effectively you have to understand that they are next token predictors and how that allows it to do what they do.

[dead]

Re: SQLite Critical CVEs or LLM Slop?

#230
post #205

So a so-called vulnerability has: - cited code not exist, and - PoC not work. How would any serious system allow it become a big deal?

Exactly. CVEs shouldn't be allowed to be anywhere near critical without a working PoC or other proof.. Trust+verify.
Post reply on HN