@zzt Humans are about as good when it comes to introducing vulns. However LLMs for 0day discovery works so well that it leaves you with really no choice, there's no LLM-free tool or process that can compete, in the mean time, you are just left with vulnerable software, that's a fact. The very nature of it being fast means vulnerability hunting becomes much easier and you can't compete as humans on the fixing side without using LLMs, there just isnt even enough qualified labor available in the world to manually handle the influx while keeping users safe. Android uses Linux and GrapheneOS didnt exactly chose that and for compatibility reasons it's quite difficult to change. A more durable choice for enforcing better theoretical security boundaries would be rewriting Linux in a safe programming language, however that is also an effort that requires enormous amount of labor that is not really practical. That would however be a viable human's response to it. You unfortunately just can't keep users safe on existing systems that arent designed from ground up to extremely minimize possible attack surface. Android is in a sense but also has many complex attackable systems made only to increase usability and versatility, you could have a human-made secure system that can resist LLM automated vulnerability hunting but it would certainly not have many features and be very crude to use. Unusable secure software isnt really that helpful either.
laura_ge@eldritch.cafe
@laura_ge@eldritch.cafe