logoalt Hacker News

outside1234today at 2:34 PM2 repliesview on HN

Source?

The rumor is the opposite, that Microsoft has actually used AI to discover and fix common security issues at scale.


Replies

ang_ciretoday at 3:14 PM

Those are 2 different questions. They wouldn't even be the same people involved.

Your appsec engineers will be the ones bug hunting with Mythos or whatever. Your regular engineers will be the ones implementing features. If the feature is a bad design and functions badly as a result, that is entirely orthogonal to whether it contains coding errors or bugs.

Also, there are bugs on the integration side that won't be caught running Mythos against source code, because it's not a source code issue. Even using Mythos for DAST is going to be very limited compared to how actual users will move through something as complex as a 'mature' OS like Windows.

mistrial9today at 2:42 PM

> common security issues

the entire industry is experiencing this as model capacity increases. How does "all projects get critical security fixes now" relate to "crap apps and loopy services by literally millions of lines of slop code" ?