Hacker News new | ask | show | jobs
by BoredPositron 65 days ago
"Bug fixes and general improvements."

Supply chain attacks are easier because changelogs for most software are useless now if they are provided at all.

1 comments

"Fix for a critical issue when querying the CPU that could lead to data corruption in other processes executing at the same time"

Or, "hey ChatGPT generate me a changelog for updates and fixes I could make to the software CPU-Z"

Expecting a more detailed changelog doesn't help at all

(I'm not even sure you'd need to prompt an LLM around guardrails like I did here, it would probably happily spit out a fake changelog even if you were explicit about it not being real as long as you don't tell the LLM you're planning to trick people with malware)