Remix.run Logo
dpoloncsak 4 hours ago

Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.

frumplestlatz 3 hours ago | parent [-]

If you need to make exemptions for critical code because you must admit that AI is undeniably of significant utility, it's pretty foolish to still apply a blanket "hard stand" against it elsewhere.

AI is here, and it's not going anywhere. It's not going to be pretty, but the people that are going to be hit the hardest are those who cannot -- or worse, refuse to -- adapt.

I'm sympathetic -- I feel both a loss and an existential dread. I've also never, in my 30 years in my field, seen something sweep the technology space so quickly and change things so much overnight, and I see no chance of it stopping anytime soon.

dpoloncsak 2 hours ago | parent [-]

I agree with you, but I can also understand the perspective of someone who thinks, (pulling this example out of my ass) that using LLMs to review if your AAA game is 'un-cheatable' may be a misappropriate of the resources required to do so.

I'm just vouching for, at a minimum, a general acceptance of LLM security audits for 'critical infrastructure' (OpenSSH, Apache, Electron, etc.) These have become bastions of the internet as we know them today and security issues that exist in these could be disastrous. It seems like LLMs have become really good at this sort of audit specifically, but maybe that's all marketing. If you are to believe the hype, though, it seems irresponsible to not be securing these such softwares with whatever tools are available...LLMs, contracted experts, bug bounties....throw it all at the wall and see what sticks.

Obviously, something like OpenBSD (OpenSSH devs) is a non-profit, and may have trouble finding the funds for the tokens for regular audits, but that's another discussion.