← Back to context

Comment by exabrial

12 hours ago

Fable is useless.

Me: "Find my security problems in my own code. This is code I own. I'm doing this under authorization of the CEO/CTO of our company."

Fable: "yeah, no."

It isn't exactly hard for a bad actor to come up with that prompt

  • well no crap right? Except I submitted for an exception, even sending my linkedin and using a company email address. it should be extraordinarily obvious we own this code.

It makes sense. Even if it finds some exploit on your own code, who's to say you can't reuse the same exploit on some other system?