| ▲ | pianopatrick 7 hours ago | |||||||
I dunno man, if there's a deluge of new AI generated code at all layers of the stack I think there will still be vulnerabilities. Like if we were willing to stop adding new code and just have a small secure code base, AI could maybe help us find all the vulnerabilities in that code base. But people have consistently been unwilling to do that. Like if we were willing to stop adding code we could have stopped decades ago and done SQLite level testing everywhere and probably have found almost all the bugs already. | ||||||||
| ▲ | fragmede 7 hours ago | parent [-] | |||||||
When we've got people who don't know the difference between ssh and bash creating SaaS companies that generate revenue, yeah there's gonna be a lot of insecure code going out, but that same person can also tell the AI "red team my app to find vulnerabilities and then fix them", and the AI can competently actually do that, I don't know that there will be. I'm not saying that's never going to happen, but the bar is getting raised on both sides. | ||||||||
| ||||||||