Hacker News new | ask | show | jobs
by sunshine-o 20 days ago
Exactly, the entire AI industry has been trying to create an AI powered security arm race. I am not necessarily blaming them.

Hard to know how much has been thrown into this but I would bet a lot.

So far I have been very surprised we haven't been flooded by those type of announcements. If you look you will always find something and OpenBSD is the top price.

1 comments

They are throwing tokens at codebases and finding mostly vulnerabilities in cases that have not been worth the limited time and effort of the chronically underfunded and understaffed professional groups. There’d be a lot more value in the companies giving the money they spend on their synthetic text extruders to the organizations doing quality security research work.
> they are ... finding ... vulnerabilities ... that have not been worth the time and effort ...

that's kinda the entire point

The point of the comment you are replying to is that it's also not worth the time and effort to use LLMs to find vulnerabilities, if "time and effort" can be measured with "money". If you factor in all the money spent on training, GPU data centers etc, it's not actually a financially efficient way to find bugs unless you profit from creating demand for LLMs. LLMs aren't cheaper than humans per unit work, yet. They're just massively deficit funded because capital thinks "AI" is going to reshape the world order, and wants in.
> it's not actually a financially efficient way ... unless you profit from creating demand for LLMs

well, they do? it's a win-win, you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers

> If you factor in all the money spent on training

why would I? it's not a cybersec-specific model

>you can't really criticise an AI lab for doing AI instead of straight up giving money to security researchers

Sure I can, if they - or you - pretend "the entire point" is about useful security work rather than expensive loss-leading marketing and demand creation.

We shouldn't look at this and think "wow AI is super useful for security". We should look and this and think "wow, there's a LOT of capital going into persuading us that AI is super useful for security".

THAT is "the entire point".

security researchers are using the free tokens that they get to do useful security work, AI labs are giving away free tokens to maximize their profits; is it really that hard to imagine that different parties might have different goals?

> We shouldn't look at this and think

you're gonna tell me what to think now?