Earlier quoted context omitted.
I'm intimately familiar with SOC2 and I'm telling you it has practically nothing to do with software security and to the extent it does, the story is improved starkly and mechanically by agents. That's an outcome of how superficial SOC2 is, not a statement about how good agent code is. Of course, the reality is that competent orgs generally exclude virtually all their software from their audit scope, and it would be…
Your word for “competent” seems to be my word for “irresponsible”. A failure in that “line-of-business backoffice code” is exactly the sort of thing that'd cause irreparable damage in terms of regulatory compliance (and, you know, the tangible harms those regulations are meant to prevent). An LLM hallucination introducing bugs that make ERP transactions spontaneously disappear or allow users to bypass permissions che…
Re: Let's talk about LLMs
#201I believe that if you read what I wrote about that you'll see it's consistent with what I'm saying here.