logoalt Hacker News

ozgrakkurtyesterday at 9:44 PM3 repliesview on HN

> K3 is the only frontier model I can have a serious conversation with about my product's security.

This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)


Replies

satyrneinyesterday at 10:06 PM

This has been the prevailing advice all along, and yet we have security vulnerabilities everywhere that LLMs are good at spotting and exploiting. I think we need more options on the menu.

show 1 reply
novaleafyesterday at 10:27 PM

I think security is an integral part of any production software, and if you get value from LLM's in software development, it seems likely they can be useful in security too.

My point and frustration is that gatekeeping in the name of Security makes the Chinese models actually better at security than USA models.

jazzyjacksonyesterday at 9:49 PM

I think I like this perspective because it points to where regulation might be more usefully applied than “the oracle must be prevented from answering certain question” and more like, “if you handle PII or provide services as a defense contractor, you may not take security advice from an oracle”