logoalt Hacker News

OtherShrezzing • today at 6:54 PM • 1 reply • view on HN

We’ve seen this in a few open source repos we voluntarily manage security on. They’re not massive repos, but big enough they get attention from security researchers.

Most of the real low hanging fruit was picked up by humans years ago. When doing automated scanning, the majority of stuff is overly-verbose nonsense which takes hours of expert human labour to understand, test, and discard.

Reading through a Claude generated false positive is absolutely excruciating, because it is absolutely determined that what it’s found is justified. Often you’ll receive very long accompanying “proof of concept” code which demonstrates absolutely wild scenarios. It’s especially frustrating when you’re volunteering your time for a project, and a well-meaning contributor submits the report without the technical nous to understand why you’re rejecting it.


Replies

b112 • today at 8:09 PM

Right now, all top tier LLMs are as eager, bright 20ish year old interns.

Very gung ho, full of energy, loads of book learning, no real world experience or understanding of why things are as they are.

Leave them to their own devices at your peril. Trust nothing they do.

Yet directly guide them, monitor everything they do, some value emerges.

➕ show 1 reply