Remix.run Logo
mbroshi 7 hours ago

> In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.

This doesn't resonate with me. I see companies adding more sloppily written features with AI. I see more bugs in the software I use, not less. While it's plausible that software is getting both buggier and more secure, I suspect those two move in the same direction not opposite.

My guess is that we're getting better at finding _existing_ security issues with AI (and thus fixing those issues), but simultaneously adding more insecure surface areas _at a faster rate_.

tptacek 6 hours ago | parent | next [-]

One way to resolve the tension here is to note that CNE and lawful-intercept access to phones depends generally on platform vulnerabilities, not application code vulnerabilities. Low-level platform code churns less, absorbs more fixes under AI workloads than it does new features, and works in a constrained space where guardrails are easier to provide (and where those guardrails already have institutional support at Apple and Google).

Over the long term this state of play could change, and IC/LEO organizations could start leaning more on application vulnerabilities than on platform RCEs. But the action would probably still coalesce around a couple of app-layer targets that could themselves be hardened.

schoen 42 minutes ago | parent [-]

I was hoping that the basebands and firmwares would get formally verified. Maybe they will ... with AI-written proofs!

thinkthatover 6 hours ago | parent | prev | next [-]

Disagree, and in a way it feels like we are dealing with inverse issues: the security "skill" is well defined and will be also engaged with by an agent. Communication companies are further incentivized as any failure is at best reputational harm. Meanwhile SaaS companies are not strictly required to have good UX for their human end users, largely because those users will likely work around the issue. also network effect vs low costs of switching for for comms

aleksandrm 7 hours ago | parent | prev | next [-]

I don't know, my colleague refuses to use AI and I've been seeing more bugs from their side, while reducing bugs on my side with the help of AI.

That said if companies want to "ship ship ship fast", then yes even AI can produce bugs or regressions if not carefully reviewed by the human.

Ancapistani 7 hours ago | parent | next [-]

I don't have any colleagues like that anymore, but even as far back as the last half of 2025 I was seeing that automated AI review was becoming effective enough that I considered it essential to any project where security was a serious concern.

These days we're generating multiple times more code than we were writing before. That means a similar multiple of opportunities for bugs to be introduced - so the ability to automate security review is more impactful in proportion to that.

kelnos an hour ago | parent | prev | next [-]

> while reducing bugs on my side with the help of AI.

How do you know? You might be adding (latent) bugs every time your LLM fixes one for you.

bossyTeacher 7 hours ago | parent | prev | next [-]

> I've been seeing more bugs from their side, while reducing bugs on my side with the help of AI.

You should question your ability to see any bugs on YOUR side.

Forgeties79 6 hours ago | parent | prev [-]

Have you asked your colleagues what it’s like to deal with your code?

boc 5 hours ago | parent [-]

It's not 2025 anymore my friend.

Forgeties79 4 hours ago | parent [-]

Yet apparently people still dump unvetted LLM outputs onto their colleagues and expect them to thank them for the privilege. So it’s worth asking them what the consensus is of their work to find out if it’s the case.

leptons 6 minutes ago | parent [-]

[dead]

Forgeties79 6 hours ago | parent | prev [-]

They’re not “bugs” they’re “quirks”! Our software is so quirky. It’s a feature!

hollerith 6 hours ago | parent [-]

Quirky and adorable!