| ▲ | SchemaLoad 2 hours ago | ||||||||||||||||
Long term we will end up with software with no low hanging fruit exploits left. But right now we are in a period where low hanging fruit is everywhere and it's easier to exploit systems than ever before. | |||||||||||||||||
| ▲ | somenameforme an hour ago | parent | next [-] | ||||||||||||||||
That relies on a major assumption that current systems are finding the vast majority of all possible exploits out there. This assumption itself would assume that either current LLMs are near perfect, or that the peak difficulty for exploits was just above human capability (which is where LLMs currently are). I think both of those assumptions are very likely false. If so then we'll see indefinitely ongoing exploit discovery LLMs improve their capabilities. Long term I suspect that the purpose of the digital domain is going to end up being rethought. For instance connecting critical infrastructure to the internet has always been a terrible idea, and LLMs will just make that even more clear. | |||||||||||||||||
| |||||||||||||||||
| ▲ | catlifeonmars an hour ago | parent | prev [-] | ||||||||||||||||
That’s assuming we’re not adding software defects at the same pace, but I imagine we are generating a lot more defects than are being discovered at the moment. | |||||||||||||||||
| |||||||||||||||||