Comment by CharlesW

13 days ago

It's good these bugs are being found and closed. The problems have nothing to do with AI, unless I'm missing something.

If people can use AI to find bugs to close them, people can use AI to find bugs to exploit them. The scale has changed.

  • And the project maintainers or their allies can use AI to find bugs and fix them.

    • The people developing exploits have an obvious way to recoup their token investment. How do the open source maintainers recoup their costs? There's a huge disparity here.

Picture the traumatized Mr. Incredible meme with the text "lowering the barrier means more exploits are found"