logoalt Hacker News

baqyesterday at 11:25 PM4 repliesview on HN

at some point having LLMs spit out libraries for you might be safer than actually downloading them.


Replies

morshu9001yesterday at 11:54 PM

This does help. Even before, I was pretty careful about what I used, not just for security but also simplicity. Nowadays it's even easier to LLM-generate utils that one might've installed a dep for in the past.

Eduardyesterday at 11:50 PM

LLMs will happily copy-paste malware or add them as dependencies

Muromectoday at 12:14 AM

this kicks the can down the road until we get supply chain attacks through LLM poisoning, like we already do with propaganda

show 1 reply
throw-12-16today at 6:01 AM

or just vendor your deps like we have been doing for decades.

show 1 reply