← Back to context

Comment by minraws

2 days ago

I mean if you gave me direct access to all your source code and fuzzers I could find vulnerabilities as well, these models also are allowed to use fuzzing and static analysis tools to help guide them.

The problem is the sheer scale of it, I could find 1 in a day or two.

They find dozens well depending on how much you are willing to spend ofc. I don't think it's massive in terms of how intelligent these are but how much they can understand intent and execute with relatively fuzzing or incorrectly built tools.

In big companies even most employees don't have access to all the code to be able to figure out the attacks quickly enough.

Somehow they are now willing the red tape since these systems could theoretically with much greater effort(read spend) reverse engineer APIs and break through even without access to the source code.