Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
Kernel code removals driven by LLM-created security reports
21–30 of 130 posts
Re: Kernel code removals driven by LLM-created security reports
#22Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
We are there. This is pretty much the reason why Mythos isn't being released publically.
Re: Kernel code removals driven by LLM-created security reports
#23Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
Re: Kernel code removals driven by LLM-created security reports
#24Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
My experience with these tools is that they generate absolutely enormous amounts of insidiously wrong false positives, and it actually takes a decent amount of skill to work through the 99% which is garbage with any velocity. Of course some people don't do that, and send all the reports anyway... and then scream from the hilltops about how incredible LLMs are when by sheer luck one happens to be right. Not only is th…
Re: Kernel code removals driven by LLM-created security reports
#25Earlier quoted context omitted.
We are there. This is pretty much the reason why Mythos isn't being released publically.
The reason Mythos isn't being released publicly is to drive up Anthropic's valuation by making big promises.
> As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation.
Re: Kernel code removals driven by LLM-created security reports
#26Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
My experience with these tools is that they generate absolutely enormous amounts of insidiously wrong false positives, and it actually takes a decent amount of skill to work through the 99% which is garbage with any velocity. Of course some people don't do that, and send all the reports anyway... and then scream from the hilltops about how incredible LLMs are when by sheer luck one happens to be right. Not only is th…
Re: Kernel code removals driven by LLM-created security reports
#27They can't maintain the code so they are no longer going to maintain the code.
[0] not trivially if you want to validate if it works
Re: Kernel code removals driven by LLM-created security reports
#28Re: Kernel code removals driven by LLM-created security reports
#29Are we already in the time, or close to the time, that well-trained LLMs are more efficient in finding security holes than all but the best developers out there, even for OS kernel code? Can someone educate me on this?
My experience with these tools is that they generate absolutely enormous amounts of insidiously wrong false positives, and it actually takes a decent amount of skill to work through the 99% which is garbage with any velocity. Of course some people don't do that, and send all the reports anyway... and then scream from the hilltops about how incredible LLMs are when by sheer luck one happens to be right. Not only is th…
Re: Kernel code removals driven by LLM-created security reports
#30Unmaintained code is a security issue in of itself, so this is of course a net benefit.