• Vincent@feddit.nl
    link
    fedilink
    arrow-up
    10
    arrow-down
    1
    ·
    2 days ago

    If these tools are indeed finding security issues, then ignoring them means someone else will find those issues - and abuse them.

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      8
      ·
      edit-2
      2 days ago

      Doesn’t matter if they find security issues (they won’t) if they’re buried in a veritable haystack of false reports.

      • Vincent@feddit.nl
        link
        fedilink
        arrow-up
        2
        arrow-down
        2
        ·
        2 days ago

        That’s true. If they’re not, though, or if they’re easy to generate yourself, then you are kinda forced to pay attention though, if you care about the security of your project.

        I don’t have the expertise or experience to say whether that is true. But GregKH seems to think so, and other prolific projects seem to be coming to the same conclusions.

        I get that it’s attractive to think that AI isn’t capable of it. But it’s important that what you believe to be true is, and stays, based on reality rather than on what I wish is true. And it’s especially important to be wary of when you really want something to be true.

        • artyom@piefed.social
          link
          fedilink
          English
          arrow-up
          3
          ·
          1 day ago

          I get that it’s attractive to think that AI isn’t capable of it

          LOL you think this is just what I want to believe? Quite the opposite, I assure you.

          But GregKH seems to think so, and other prolific projects seem to be coming to the same conclusions.

          Lots of people are deluded, and subject to mental manipulation, unable to understand what’s happening in front of them. Falling prey to powerful marketing with unlimited budgets. Ever heard of “AI psychosis”?