logoalt Hacker News

sigmartoday at 2:52 AM2 repliesview on HN

I'd love to see Anthropic (or someone with mythos access) create a cybersecurity version of this. So that I could create a pool that says "find security concerns in this github repo." Then the report from mythos gets sent to the code/project maintainer and revealed to the public (that paid for it) at the 90 day mark.


Replies

sublineartoday at 3:16 AM

The target codebase cannot improve beyond the point that the reports are incorrect and a waste of money.

There is also the question of whether humans can waste so much time reviewing AI code that the vulnerability is not patched before it is exploited. Another one is whether when the human is removed from the loop that the codebase becomes more vulnerable in some other ways.

stevefan1999today at 3:03 AM

sounds like FableBugBounty