this post was submitted on 23 Apr 2026
130 points (95.1% liked)
Technology
84828 readers
6547 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
"Finding" bugs by throwing shit at the walls and assuming people will sort it out provides negative value. You technically are finding bugs, but you could do the same just assuming every line of your code contains five bugs. The question is in "and then what", and the answer is "someone needs to sort them out and deal with it", and if you have people who can fix the bug, they're perfectly capable of finding it themselves. The bugs still exist because there is not enough people to fix that. And slop gen doesn't help with that either.
It's only a negative value if the AI+review process takes longer than a human just finding the bugs.
One of the biggest hurdles in infosec right now is just the sheer volume of data. Sifting through hoards of data and finding anomalies is something AI actually excels at.
One of the biggest hurdles in any app, security related or not, is making the app actually do what you need. We were able to use transformers to sift through logs for ages, we also have people to do that. The bottleneck was always in not having enough developers and time to fix all the bugs. Now that precious time needs to be also spent on sifting through all the llm output, all the hallucinations, all the bullshit that it outputs, to find whatever of that is real, and then check that it actually a problem that needs fixing.