• DeadDigger@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    2
    ·
    5 hours ago

    Well the problem is that for example curl got flooded with generated security reports where only 5% had some true security potential. So your llm will basically flood you with false positives

    • ByteJunk@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      If 5% of the reports are genuine security vulnerabilities that they wouldn’t have found otherwise, that’s looking like a big win to me, not sure how you see it differently.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        3 hours ago

        The problem is identifying which 5%. Nobody wants to filter that much AI slop.

        • AwesomeLowlander@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          3 hours ago

          If you’re working for a company’s cybersec, that’s your job. And a much preferable one to waiting for an attacker to do it for you.