← Back to context

Comment by inigyou

3 days ago

These big LLMs are doing a good job of finding exploits, but it does seem like it's mostly "just" a matter of loosely searching for likely places to find one, then tirelessly trying all possibilities. They are mostly finding things that a human would find it a human looked at that section of code, but humans don't have time to review the whole code 24/7. I wonder if there are more intelligent ways to scan that would find even more.