← Back to context

Comment by viccis

3 days ago

God bless you, the beautiful thing about computer security is that this attitude has kept us happily in business for many years.

Say more? It's really hard to navigate the antecedents of this argument.

  • People who don't do intense security work for a living underestimate the complexity of it. This might find some vulnerabilities, but it's not really capable of producing new methods and attacks. What it replaces isn't a high quality human researcher; it replaces current static code review systems.

    If AI models never had stack smashing writeups in their corpus, they'd never be able to invent stack smashing.

    • So, by any reasonable measure, I've spent a career doing "intense security work", with a particular focus in vulnerability research, and I do not agree with this at all.

      1 reply →