RE: https://infosec.exchange/@drwhax/116997238394916522
Maybe confirmation bias, but an interesting read nevertheless https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities
RE: https://infosec.exchange/@drwhax/116997238394916522
Maybe confirmation bias, but an interesting read nevertheless https://www.propublica.org/article/anthropic-mythos-microsoft-software-vulnerabilities
@t_var_s
it's not like that yet
@Netzblockierer tell me you dont understand it, wihtout saying you dont understand it
@castedo yes, some of these got an CVE assigned here: https://github.com/tuxera/ntfs-3g/security
As these are reported privately, there's no open issue. I could however make these findings open-source in a git repo if that's useful?
@Netzblockierer if your data leaks on a next LLM powered leak you can't cry!
@SpaceLifeForm also this 
@pip ok doei
@SteveClough it's only downhill from here
@LordCaramac we both hate capitalism dont get me wrong
@t_var_s these new models are pretty good at a self adversarial review and writing PoC's. They do tend to cheat and there need to be options to flag false positives using some kind of harness, but that can be done.
@em_and_future_cats @zimzat unfortunately less cute than Mr Snufflepagus: https://en.wikipedia.org/wiki/Mr._Snuffleupagus
@kaleb I think it's a decent first step beyond, ideally we remove a ton of bug classes ala snufflepagus.
@monnier Anything else is also fine, it's a good first step 
@em_and_future_cats It might've been immersion cooling
https://en.wikipedia.org/wiki/Immersion_cooling (although I don't know what the difference would be when it would come to electricity..)
@em_and_future_cats that is to say, were abusing huge plots of land for... what exactly??
@em_and_future_cats we both agree on this! I don't see them making a profit on these gigantic datacenters either!
@elle ok doei
@zimzat No one wants to fund it is what I think.
Suhosin did something like this for PHP, now it's just jvoisin maintaining snufflepagus: https://github.com/jvoisin/snuffleupagus
I don't remember if there was something similar for other languages. Grsecurity for the Linux Kernel, that's the three I know 
@alice_pea_3526 the parrots are pretty good at pattern recognition which is where I think they shine. Some smaller projects as well, but architecture wise, you'll have to handhold them a lot. Its almost like having a junior that's good in some incredibly niche things, but you'll be iterating a lot over code.
I think curl maintainer said something similar, the reports used to be bad from LLM's and they suddenly got a lot better. It still requires a pair of human eyes to understand if its not hallucinating.
I wish it was better at eliminating whole bug classes tho, that'd be the ideal situation?
@MossyQuartz I still think thats a good idea to this day 