Live data from Hacker News

Google announces Sec-Gemini v1 a new experimental cybersecurity model

security.googleblog.com

51–53 of 53 posts

Re: Google announces Sec-Gemini v1 a new experimental cybersecurity model

#51

Earlier quoted context omitted.

Thanks for looking in-depth in our post. The Hitachi RTU500 mention is not an hallucination, we did check for those. It is mentioned in the Mandiant threat intelligence data.

Have you considered that Mandiant is wrong? I cannot find any evidence that it would be vulnerable. Hitachi doesn't even appear to be a technology partner of Palo Alto ( https://technologypartners.paloaltonetworks.com/English/dire... ). As far as I can tell, the only connection between those is, that CISA released this alert which mentions multiple unrelated advisories in one post. Which happens to be the Siemens Pal…

Isn't the tool doing its job in that case? I wouldn't generally expect it to independently determine that an otherwise reliable source made a mistake. In fact I feel like that would be a really bad idea.

Imagine if a relatively clueless intern left something out of a report because the textbook "seemed wrong".

Re: Google announces Sec-Gemini v1 a new experimental cybersecurity model

#52
post #16

Earlier quoted context omitted.

2.5 has been amazing for programming. I just send it entire repo as context when I am lazy and then ask it for entire modified files back with the (medium sized) change. It almost always works! I wish to either start using cursor or some vscode extension to do this from ide itself.

How do you send an entire repo to it ? file by file ?

I have a few ways but usually https://github.com/yamadashy/repomix works

Re: Google announces Sec-Gemini v1 a new experimental cybersecurity model

#53

Earlier quoted context omitted.

Have you considered that Mandiant is wrong? I cannot find any evidence that it would be vulnerable. Hitachi doesn't even appear to be a technology partner of Palo Alto ( https://technologypartners.paloaltonetworks.com/English/dire... ). As far as I can tell, the only connection between those is, that CISA released this alert which mentions multiple unrelated advisories in one post. Which happens to be the Siemens Pal…

Isn't the tool doing its job in that case? I wouldn't generally expect it to independently determine that an otherwise reliable source made a mistake. In fact I feel like that would be a really bad idea. Imagine if a relatively clueless intern left something out of a report because the textbook "seemed wrong".

I don't really know what its job is to be honest.

Saying that the input data is wrong and the AI didn't hallucinate that data is also kind of a "trust me bro" statement. The Mandiant feed is not public, so I cannot check what was fed to it.

I don't really care why its wrong. It is wrong. And using that as the example prompt in your announcement is an interesting choice.

Post reply on HN