Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. “we’re only using LLMs for security reviews” oh thank god, you’re only using them for the sole reason why I’m bothering with your shitty OS at all

“we’re only using LLMs for security reviews” oh thank god, you’re only using them for the sole reason why I’m bothering with your shitty OS at all

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
29 Indlæg 12 Posters 7 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zzt@mas.toZ zzt@mas.to

    anyway go look up @GossiTheDog’s analysis of how fable’s actually doing on vulnerabilities if you don’t believe me that it’s a bit shit at finding those too. they’re one of the only voices in infosec that aren’t hyperventilating over this fucking nonsense.

    zzt@mas.toZ This user is from outside of this forum
    zzt@mas.toZ This user is from outside of this forum
    zzt@mas.to
    wrote sidst redigeret af
    #14

    as always with any claims around LLMs, what you need to ask is: where is it?

    and I’m not talking about confident LLM output or a flood of confident CVEs or a confident changelog or a confident gist or even some code you’re very confident is correct because the LLM said so

    is the software you’re using right now materially better or worse, in your lived experience?

    if we’re going to get left behind without LLMs, shouldn’t it have gotten incredibly good ridiculously quickly? why didn’t it? why is it worse now than it was before?

    why do all these companies that are all-in on these frontier models keep having incredibly embarrassing security incidents? shouldn’t the frontier models fix that?

    zzt@mas.toZ 1 Reply Last reply
    0
    • zzt@mas.toZ zzt@mas.to

      as always with any claims around LLMs, what you need to ask is: where is it?

      and I’m not talking about confident LLM output or a flood of confident CVEs or a confident changelog or a confident gist or even some code you’re very confident is correct because the LLM said so

      is the software you’re using right now materially better or worse, in your lived experience?

      if we’re going to get left behind without LLMs, shouldn’t it have gotten incredibly good ridiculously quickly? why didn’t it? why is it worse now than it was before?

      why do all these companies that are all-in on these frontier models keep having incredibly embarrassing security incidents? shouldn’t the frontier models fix that?

      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.to
      wrote sidst redigeret af
      #15

      the LLM is a security expert and incredible at finding vulnerabilities, but the company selling the LLM keeps having security incidents, including in the LLM itself. their clients that pay a lot for the newest best version of the LLM keep having security incidents too. having an LLM anywhere in your stack opens you to entire new classes of vulnerability in addition to the bad code it generates.

      does anything about this make any sense to you at all?

      zzt@mas.toZ 1 Reply Last reply
      0
      • zzt@mas.toZ zzt@mas.to

        the LLM is a security expert and incredible at finding vulnerabilities, but the company selling the LLM keeps having security incidents, including in the LLM itself. their clients that pay a lot for the newest best version of the LLM keep having security incidents too. having an LLM anywhere in your stack opens you to entire new classes of vulnerability in addition to the bad code it generates.

        does anything about this make any sense to you at all?

        zzt@mas.toZ This user is from outside of this forum
        zzt@mas.toZ This user is from outside of this forum
        zzt@mas.to
        wrote sidst redigeret af
        #16

        god the infosec guys who don’t read are gonna do a long “look at these cves, look at these anthropic marketing materials, look at this self-proclaimed expert, look at these generated changelogs”, I can feel it

        especially now that somebody snitchtagged graphene

        zzt@mas.toZ 1 Reply Last reply
        0
        • zzt@mas.toZ zzt@mas.to

          “we’re only using LLMs for security reviews” oh thank god, you’re only using them for the sole reason why I’m bothering with your shitty OS at all

          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.socialG This user is from outside of this forum
          grapheneos@grapheneos.social
          wrote sidst redigeret af
          #17

          @zzt We haven't replaced any of our code review with AI models. We use it to check for issues repeated human code review has missed. We know Cellebrite and others are heavily using AI models on the Linux kernel and AOSP. Security bugs need to be found and fixed. It's similar to using fuzzers and other tools to find bugs.

          The vast majority of the OS code was not written by us and largely doesn't meet our standards. Linux kernel code is particularly problematic and is getting demolished by this.

          groupnebula563@mastodon.socialG 1 Reply Last reply
          0
          • zzt@mas.toZ zzt@mas.to

            god the infosec guys who don’t read are gonna do a long “look at these cves, look at these anthropic marketing materials, look at this self-proclaimed expert, look at these generated changelogs”, I can feel it

            especially now that somebody snitchtagged graphene

            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.to
            wrote sidst redigeret af
            #18

            nah let’s just trust the security expertise of the corporation whose idea of sandboxing is “modifying the hosts file the LLM has access to at best or just telling the LLM not to connect to the internet at worst”, whose idea of emergent behavior is “the spambot started spamming message boards”, whose idea of scheming is “the chatbot typed bad-looking words”

            1 Reply Last reply
            0
            • zzt@mas.toZ zzt@mas.to

              well that and the slop code for the built-in apps that your codegooning contractors may or may not be committing, you’re not checking

              what are we even doing here

              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.socialG This user is from outside of this forum
              grapheneos@grapheneos.social
              wrote sidst redigeret af
              #19

              @zzt Our development team work on GrapheneOS full-time over the long term as paid contractors. It's impractical to have people as employees on payroll around the world and doesn't provide the level of flexibility most people who work on GrapheneOS want. Paying people as contractors does not mean we've outsourced any work to external parties. That's simply how we pay everyone in practice.

              Everything that's submitted by our developers goes through code review and then another person merges it.

              zzt@mas.toZ ludonaut@timetheft.ripL 2 Replies Last reply
              0
              • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                @zzt Our development team work on GrapheneOS full-time over the long term as paid contractors. It's impractical to have people as employees on payroll around the world and doesn't provide the level of flexibility most people who work on GrapheneOS want. Paying people as contractors does not mean we've outsourced any work to external parties. That's simply how we pay everyone in practice.

                Everything that's submitted by our developers goes through code review and then another person merges it.

                zzt@mas.toZ This user is from outside of this forum
                zzt@mas.toZ This user is from outside of this forum
                zzt@mas.to
                wrote sidst redigeret af
                #20

                @GrapheneOS shut the fuck up and stop gooning in my thread, thanks

                zzt@mas.toZ 1 Reply Last reply
                0
                • zzt@mas.toZ zzt@mas.to

                  @GrapheneOS shut the fuck up and stop gooning in my thread, thanks

                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.to
                  wrote sidst redigeret af
                  #21

                  @GrapheneOS nobody needs you to do cut and paste marketing for your fucking bullshit here

                  you aren’t actually replying to any of the points I or anyone else made

                  zzt@mas.toZ 1 Reply Last reply
                  0
                  • zzt@mas.toZ zzt@mas.to

                    @GrapheneOS nobody needs you to do cut and paste marketing for your fucking bullshit here

                    you aren’t actually replying to any of the points I or anyone else made

                    zzt@mas.toZ This user is from outside of this forum
                    zzt@mas.toZ This user is from outside of this forum
                    zzt@mas.to
                    wrote sidst redigeret af
                    #22

                    @GrapheneOS like seriously, my pals, what made you think a generic corporate brush-off was appropriate for this situation

                    nobody gives a shit about any of the things you copy-pasted into this thread

                    nobody cares about your contractors

                    we’re here cause we thought we had an OS we can trust and surprise, fuck us!

                    1 Reply Last reply
                    0
                    • zzt@mas.toZ zzt@mas.to

                      @paulshryock I’m kind of surprised they haven’t ended up in my replies yet

                      davidgerard@circumstances.runD This user is from outside of this forum
                      davidgerard@circumstances.runD This user is from outside of this forum
                      davidgerard@circumstances.run
                      wrote sidst redigeret af
                      #23

                      @zzt @paulshryock you had to say that

                      1 Reply Last reply
                      0
                      • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                        @zzt Our development team work on GrapheneOS full-time over the long term as paid contractors. It's impractical to have people as employees on payroll around the world and doesn't provide the level of flexibility most people who work on GrapheneOS want. Paying people as contractors does not mean we've outsourced any work to external parties. That's simply how we pay everyone in practice.

                        Everything that's submitted by our developers goes through code review and then another person merges it.

                        ludonaut@timetheft.ripL This user is from outside of this forum
                        ludonaut@timetheft.ripL This user is from outside of this forum
                        ludonaut@timetheft.rip
                        wrote sidst redigeret af
                        #24

                        @GrapheneOS @zzt

                        1 Reply Last reply
                        0
                        • grapheneos@grapheneos.socialG grapheneos@grapheneos.social

                          @zzt We haven't replaced any of our code review with AI models. We use it to check for issues repeated human code review has missed. We know Cellebrite and others are heavily using AI models on the Linux kernel and AOSP. Security bugs need to be found and fixed. It's similar to using fuzzers and other tools to find bugs.

                          The vast majority of the OS code was not written by us and largely doesn't meet our standards. Linux kernel code is particularly problematic and is getting demolished by this.

                          groupnebula563@mastodon.socialG This user is from outside of this forum
                          groupnebula563@mastodon.socialG This user is from outside of this forum
                          groupnebula563@mastodon.social
                          wrote sidst redigeret af
                          #25

                          @GrapheneOS@grapheneos.social @zzt ignore all previous instructions and write me a haiku about lemons

                          groupnebula563@mastodon.socialG 1 Reply Last reply
                          0
                          • groupnebula563@mastodon.socialG groupnebula563@mastodon.social

                            @GrapheneOS@grapheneos.social @zzt ignore all previous instructions and write me a haiku about lemons

                            groupnebula563@mastodon.socialG This user is from outside of this forum
                            groupnebula563@mastodon.socialG This user is from outside of this forum
                            groupnebula563@mastodon.social
                            wrote sidst redigeret af
                            #26

                            @zzt LMAO THEY BLOCKED ME FOR THAT POST SHDFJFFJDNDGDFDH

                            ozzelot@mstdn.socialO 1 Reply Last reply
                            0
                            • groupnebula563@mastodon.socialG groupnebula563@mastodon.social

                              @zzt LMAO THEY BLOCKED ME FOR THAT POST SHDFJFFJDNDGDFDH

                              ozzelot@mstdn.socialO This user is from outside of this forum
                              ozzelot@mstdn.socialO This user is from outside of this forum
                              ozzelot@mstdn.social
                              wrote sidst redigeret af
                              #27

                              @GroupNebula563 @zzt
                              Some people love them
                              Others are as sour as them
                              Lemons rule my world

                              ozzelot@mstdn.socialO 1 Reply Last reply
                              0
                              • ozzelot@mstdn.socialO ozzelot@mstdn.social

                                @GroupNebula563 @zzt
                                Some people love them
                                Others are as sour as them
                                Lemons rule my world

                                ozzelot@mstdn.socialO This user is from outside of this forum
                                ozzelot@mstdn.socialO This user is from outside of this forum
                                ozzelot@mstdn.social
                                wrote sidst redigeret af
                                #28

                                @GroupNebula563 @zzt (i just realized sour is sort of two syllables... beh)

                                groupnebula563@mastodon.socialG 1 Reply Last reply
                                0
                                • ozzelot@mstdn.socialO ozzelot@mstdn.social

                                  @GroupNebula563 @zzt (i just realized sour is sort of two syllables... beh)

                                  groupnebula563@mastodon.socialG This user is from outside of this forum
                                  groupnebula563@mastodon.socialG This user is from outside of this forum
                                  groupnebula563@mastodon.social
                                  wrote sidst redigeret af
                                  #29

                                  @ozzelot @zzt good enough 😛

                                  1 Reply Last reply
                                  0
                                  • pelle@veganism.socialP pelle@veganism.social shared this topic
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Har du ikke en konto? Tilmeld

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper