| ▲ | usef- 5 hours ago | ||||||||||||||||||||||
Are you claiming that LLMs aren't finding new issues compared to previous methods? There's a huge number of security issues coming out in recent months, especially via Anthropic (glasswing etc). We don't have to take their word for it: look at the code. Some open source maintainers are talking about burnout due to spending so much time patching. | |||||||||||||||||||||||
| ▲ | overgard an hour ago | parent | next [-] | ||||||||||||||||||||||
They're probably creating way more vulnerabilities than they're solving. Go look at OpenCode and tell me that any of that is sane. Or fuck, the OG of vibe coding, Claude basically is a terrifying attack vector. It's poorly reviewed and open to prompt injection and yet it basically has access to whatever the user has access to on most corporate machines. They can't even fix flickering bugs but somehow we're supposed to trust that they aren't opening our machines up to terrifying vulnerabilities? It's amazing to me that people will just let it run arbitrarily bash commands in their home directory without thinking, but all the sudden act gravely concerned about security in the age of overhyped LLMs. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | bee_rider 3 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
The suggestion was to have some AI system “fix” the code. They are reporting that they’ve found lots of bugs. Are they even claiming to have exhaustively found all the bugs? I don’t think even the most optimistic pitches would claim that. I’d expect patching existing codebases to be an eternal treadmill as better models come about. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | K0balt 5 hours ago | parent | prev | next [-] | ||||||||||||||||||||||
Yeah, there’s a lot of people that are in the “AI doesn’t work” camp. IDK what to tell them except that they are holding it wrong. My Anthropic subscription (in the hands of an experienced developer) is worth 4 mid tier or 2 top tier devs. And makes better code than the mids. If you “hold it right”. | |||||||||||||||||||||||
| |||||||||||||||||||||||
| ▲ | computably 5 hours ago | parent | prev [-] | ||||||||||||||||||||||
Spending their time patching, or reviewing slop "patches"? | |||||||||||||||||||||||
| |||||||||||||||||||||||