• LibertyLizard@slrpnk.net
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    3
    ·
    7 hours ago

    Bad look for Claude after their vigorous insistence their model can’t be used this way.

    Also bad look for the 50 people I get in my inbox telling me AI is completely useless every time I talk about it. These arguments were worthy of entertainment a few years ago but not in 2026.

    • richmondez@lemdro.id
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 hours ago

      AI (specifically LLM) isn’t unless unless you need it to be accurate. You don’t need to be accurate to find software vulnerabilities for example, you just need to be able to sift enough of the false positives to be able to identify the real bugs for example.

      LLMs are over hyped and being given away below the cost of training and running the models in the hope of getting entrenched then ramping up the costs though.

    • A_norny_mousse@piefed.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 hours ago

      Exploit scripts can be bought on the darknet. Or possibly just googled. Claude’s role in this is close to insignificant.

    • Carnelian@lemmy.world
      link
      fedilink
      English
      arrow-up
      16
      arrow-down
      2
      ·
      6 hours ago

      What’s the use here? A random Ethiopian kid doxxing himself while “breaching companies”?

      This article reads like yet another sensationalist advertisement for ai. How many people have supposedly now gained the ability to “breach dozens of companies” simply by typing “please” into a text box? Hundreds of millions? How is society still functioning if this is going on?

      • ben@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        4 hours ago

        The reason things haven’t fallen apart is because there’s a lot of devs working a lot more than they used to making sure they’re patching vulnerabilities. Last year if you asked me what portion of my time was spent updating dependencies and responding to reports of vulnerabilities I’d say like 5-10%, this year that’s easily more like 30%

        I’m sure not every company is doing this, but depending on the sensitivity of the data the company is holding I’d imagine you’d see similar patterns elsewhere