| ▲ | rvz 4 hours ago | ||||||||||||||||
You need to understand that they have no choice. Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them. So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release. As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports. > so using AI like ASAN etc. is welcome. AddressSanitizer is not "AI", nor does it use AI. [0] [0] https://static.googleusercontent.com/media/research.google.c... | |||||||||||||||||
| ▲ | dpoloncsak 4 hours ago | parent | next [-] | ||||||||||||||||
Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds. | |||||||||||||||||
| |||||||||||||||||
| ▲ | as12qh 3 hours ago | parent | prev [-] | ||||||||||||||||
I'm not a native speaker, but in other languages the cited text clearly means "using AI in the manner of ASAN or similar tools". | |||||||||||||||||