| ▲ | NitpickLawyer 11 hours ago | |
Google's entire modus operandi has been "automate everything" for decades. They've been doing this with fuzzers, with project zero and so on. Adding LLMs on top is a very obvious next step. And LLMs improving and finding more bugs also follows. Then improve the harness and the dev tools, to better use the LLMs. And then everything together end-to-end to find-triage-fix-confirm. Your LLMs are as good as the loop they run in, and the loop is as good as the verifier. Seems a reasonable enough dynamic without (or despite, depends how cynical you wanna be) the need for managers to show number goes up on some chart. | ||
| ▲ | jayd16 4 hours ago | parent | next [-] | |
So thinking about this, do you think these bugs are all unique or are there a small set of new bug categories that were found and once automated resulted in many separate bug fixes? For many of the new bugs, do we think they would all have been prioritized in the past? Are these all critical bugs that would have all been addressed in a timely fashion or are they getting done because its easier to do. Another way to ask it would be, do we think we're discovering that Chrome had more big holes than we thought or are we raising the security bar by fixing smaller holes? | ||
| ▲ | 3 hours ago | parent | prev [-] | |
| [deleted] | ||