this post was submitted on 26 May 2026
51 points (94.7% liked)
Fuck AI
7162 readers
1635 users here now
"We did it, Patrick! We made a technological breakthrough!"
A place for all those who loathe AI to discuss things, post articles, and ridicule the AI hype. Proud supporter of working people. And proud booer of SXSW 2024.
AI, in this case, refers to LLMs, GPT technology, and anything listed as "AI" meant to increase market valuations.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The problem is that I do not believe a word that anthropic says. They say this is only 1%, but do they have any proof to back it up? I am also sceptical of the claim that it can "look at the entire repo and how it all works together". It can produce an approximation which could give it an advantage over more traditional fuzzers, but most reported bugs are still very local(and/or non-existant) and easily ruled out if it could actually model the naur theory behind the code.
They already explained how they have placed hashes inside all their bug reports for Project Glasswing and will reveal their report once there has been time for patches to be applied.
Mozilla, developer of one of the most active and heavily scrutinized open source repositories in existence today, blogged about it with their product known as Firefox. They agree with you that it doesn't do anything better that what a human researcher could find, but its perk is that it can relentlessly play that role and keep looking, while human researchers have to sleep, eat, and enjoy other activities:
https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
I'll see when these hashes materialise, until then I have to assume LLM companies are lying always about everything.
See, the problem is that I am not talking about human researchers, I am talking about other methods of automated fuzzing. I believe mozilla is overstating how useful the LLM has actually been. This has many reasons, one of them being that their main source of income is trying to become an LLM company. If that project fails said company might have to make some unfortunate cuts.
Im sure FreeBSD probably appreciates the bug reports as well, and I don't believe they are tied to LLMs. They have totally revamped their processes recently to accommodate for the influx of reports coming in.