logoalt Hacker News

nonfamoustoday at 8:47 AM2 repliesview on HN

From the Twitter advisory on the issue being referenced here [1]:

>>> To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike.

Kinda turns the “many eyes” principle of OSS on its head, eh?

[1] https://x.com/nvk/status/2083216713693151552?s=61


Replies

abecedariustoday at 1:24 PM

If your source is not open that's barely a speedbump, given a binary. At least that's my impression of the current state.

dist-epochtoday at 10:07 AM

If the industry most seasoned experts are not using LLMs right now to front-run the discovery of vulnerabilities in the code they are responsible for, they are not experts, but clowns.