The thing about things like this is that they're shop jigs. You can buy a crosscut sled if you really want to, but most woodworkers just make their own. It was a different situation 2 years ago, when there was significant cost to building your own harness (but then: you probably weren't doing AI vuln research 2 years ago). Today, I think your best bet is to look at something like this for ideas, and then just ask for…
I’ve been looking for a way to articulate this shift, and your analogy nails it. The value of libraries and infrastructure components in software engineering is eroding fast. I am sure that in many organizations, teams responsible for this sort of work have less and less users coming to them.
Anthropic's open-source framework for AI-powered vulnerability discovery
111–120 of 177 posts
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#112Earlier quoted context omitted.
Sort of? The definition of "bad" from a security PoV is rapidly expanding, in light of relatively new capabilities and increasingly cheap access to exploitable vulnerabilities.
I don't think the definition of "bad" is expanding. Rather the ability to detect and exploit "bad" is.
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#113Is Anthropic still majority French-owned? It would explain a lot about their entire approach to the wider ecosystem.
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#114Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#115Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#116The thing about things like this is that they're shop jigs. You can buy a crosscut sled if you really want to, but most woodworkers just make their own. It was a different situation 2 years ago, when there was significant cost to building your own harness (but then: you probably weren't doing AI vuln research 2 years ago). Today, I think your best bet is to look at something like this for ideas, and then just ask for…
And even if you did… I spent months refining AI workflows that were just obsoleted by ultracode.
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#117Earlier quoted context omitted.
I don't think the definition of "bad" is expanding. Rather the ability to detect and exploit "bad" is.
fair point. another way of putting it might be to say that, for all extant software, much more of it is "bad" than we realized even a month or two ago -- and the cost to create and maintain "good" software is increasing (even as the naive / surface-level / apparent cost is plummeting)
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#118To be sure, security is an amazing AI/LLM use case. A huge swath of the work is pattern matching known security issues against stuff that's very precise to analyze -- programming language text. Something that stands out is that for the strongest use cases, AI companies will prefer to sell the technique as a service rather than its raw output. For use cases where the output is less valuable, tokens are sold. If AI tok…
> The same way as someone selling an expensive course in the stock market is signaling that they have more to gain by selling the course rather than Or they want to diversify > If AI tokens were so magical in creating new value in developing software applications generally, they wouldn't be selling tokens directly. That requires to build and sell a whole product they have little experience with, competing with their…
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#119Earlier quoted context omitted.
Unless it is very specific to a proprietary product, craftspeople take their jigs with them from job to job, building up a personal library over a career. As a software developer I've always had a well-tuned IDE and shell config in a safe place. Something I think about a lot is what is the equivalent for the software builders of today using AI tools? how do make these harnesses exportable and portable? You might thin…
Using something like pi helps. I've made my own dotfiles for skills/extensions I like and can install them just like my normal dotfiles https://github.com/anishthite/agent-dotfiles
whats the purpose of this? just fun or does it cause some desired behaviour?
Re: Anthropic's open-source framework for AI-powered vulnerability discovery
#120Nice