Hacker News new | ask | show | jobs
by ozgrakkurt 4 days ago
> K3 is the only frontier model I can have a serious conversation with about my product's security.

This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)

5 comments

This has been the prevailing advice all along, and yet we have security vulnerabilities everywhere that LLMs are good at spotting and exploiting. I think we need more options on the menu.
You hire someone that knows security and that guy uses an LLM. Ignorant business guy or the research engineer genius guy won’t be able to do much with just an LLM.

You can easily see this if you are using LLMs in a field you are an expert in

You are right, but you can't convince anyone, because the product owner bear all the responsibilities for his/her decisions.
I think security is an integral part of any production software, and if you get value from LLM's in software development, it seems likely they can be useful in security too.

My point and frustration is that gatekeeping in the name of Security makes the Chinese models actually better at security than USA models.

> This is wrong IMO. You should have a serious conversation about your products security with someone who is actually trained on that subject. LLMs are useless if you don't already know more about the thing than the LLM, or if you don't care too much about the outcome (internal tools etc.)

How did you read: "K3 is the only FRONTIER MODEL I can have a serious conversation with about my product's security" and infer that there isn't anyone with training also in the loop?

Did you seriously think: "they use an LLM so it's impossible they use a human with cyber experience; it's not like they could be using both (as would be expected when securing code). I'll help them out by using an oversimplified explanation suitable for a small child yet completely missing the OPs meaning. "?

I think I like this perspective because it points to where regulation might be more usefully applied than “the oracle must be prevented from answering certain question” and more like, “if you handle PII or provide services as a defense contractor, you may not take security advice from an oracle”
Excellent, that’s what people have been doing for 40 years. Surely that means the models have 0 hope of finding successful attack vectors