| ▲ | pizlonator 3 hours ago | ||||||||||||||||
Not symmetric at all. There are countless bugs to fund. If the offender runs these tools, then any bug they find becomes a cyberweapon. If the defender runs these tools, they will not thwart the offender unless they find and fix all of the bugs. Any vs all is not symmetric | |||||||||||||||||
| ▲ | energy123 an hour ago | parent | next [-] | ||||||||||||||||
LLMs effectively move us from A to B: A) 1 cyber security employee, 1 determined attacker B) 100 cyber security employees, 100 determined attackers Which is better for defender? | |||||||||||||||||
| ▲ | 0xDEAFBEAD 2 hours ago | parent | prev [-] | ||||||||||||||||
How do bug bounties change the calculus? Assuming rational white hats who will report every bug which costs fewer LLM tokens than the bounty, on expectation. | |||||||||||||||||
| |||||||||||||||||