logoalt Hacker News

a_victorpyesterday at 8:27 PM2 repliesview on HN

Legit question: when working on finding security issues, are there any guidelines on what you can send to LLMs/AI?


Replies

fallinditchyesterday at 10:04 PM

I got downvoted, so maybe that means someone thinks un-minifying code is not advised for dealing with security issues? But on reflection surely you can just use the 'format code' command in the ide? I am no expert but surely it's ok to use AI to help track down and identify security issues with the usual caveats of 'don't believe it blindly, do your double checking and risk assessing.'

CER10TYyesterday at 10:11 PM

Personally, I'd just use common sense and good judgment. At the end of the day, would you want someone to hand your address, and other private data to OpenAI just like that? Probably not. So don't paste customer data into it if you can avoid it.

On the other hand, minified code is literally published by the company. Everyone can see it and do with it as they please. So handing that over to an AI to un-minify is not really your problem, since you're not the developer working on the tool internally.