logoalt Hacker News

lelanthrantoday at 6:06 PM6 repliesview on HN

> Closed source software won't receive any reports, but it will be exploited with AI.

What makes you so sure that closed-source companies won't run those same AI scanners on their own code?

It's closed to the public, it's not closed to them!


Replies

440bxtoday at 6:21 PM

As someone who works on closed source software and has done for a couple of decades, most companies won't even know about that and of those who do only a fraction give enough of a shit about it to do anything until they are caught with their pants down.

show 2 replies
baileypumfleettoday at 6:32 PM

As I mentioned above, we actually do run these AI scanners on our code, but the problem is it's simply not enough. These AI scanners, including STRIX, don't find everything. Each scanning tool actually finds different results from the other, and so it's impossible to determine a benchmark of what's secure and what's not.

ihaveajobtoday at 6:19 PM

More eyes, more chances that someone will actually use the tools. Also, the tools and how you use them are not all the same.

show 1 reply
cyanydeeztoday at 8:28 PM

Because they're a company. Even if the bar to entry can fit a normal sized american, doesn't mean they will do it, or do it in a systematic way; We know very well that nothing about AI is naturally systematic, so why would you assume it'll happen in a systematic way.

LunicLynxtoday at 6:15 PM

Came here to say the same. Same tools + private. In security two different defense-mechanisms are always better than one.

show 1 reply
suhputttoday at 7:40 PM

[dead]