The AI slop security reporting is basically extinct.
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
@bagder as in all AI security reporting doesn't happen? Or just the low quality reporting?
-
@bagder as in all AI security reporting doesn't happen? Or just the low quality reporting?
@flpvsk they're close to 100% AI now. High quality
-
@flpvsk they're close to 100% AI now. High quality
-
@flpvsk they're close to 100% AI now. High quality
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
@bagder What do you think changed? Better tools? Stopping the bug bounty?
-
@bagder What do you think changed? Better tools? Stopping the bug bounty?
@annika the tooling for sure, nothing else
-
@annika the tooling for sure, nothing else
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.
The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".
-
@annika the tooling for sure, nothing else
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
@bagder I wish this was my experience
. But it's certainly getting better. -
I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.
The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".
@bagder Yeah, seems like around january things flipped around.
I was hoping the slop would continue to be slop, but alas. Wishful thinking on my part (to make it easier to disregard the fad).
-
I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.
The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".
@bagder The other problem with AI bug reports is the verbosity, otherwise I basically agree.
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
@bagder I love how you changed your opinion on this topic when you saw real evidence in form of good security reports written by AI.
If someone would write this 2 years ago I would say they are delusional but today its just reality.
I hope soon we get open models with such capabilities as for now only the gatekeeped models from big tech are capable of doing such good work.
-
@bagder The other problem with AI bug reports is the verbosity, otherwise I basically agree.
@evilpie true they are normally way too talkative
-
The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.
@bagder Didn't you share one just 2 days ago though? hackerone.com/reports/3669305
-
@bagder I love how you changed your opinion on this topic when you saw real evidence in form of good security reports written by AI.
If someone would write this 2 years ago I would say they are delusional but today its just reality.
I hope soon we get open models with such capabilities as for now only the gatekeeped models from big tech are capable of doing such good work.
@grayrattus it was never my opinion as much as my summary of the situation... and the situation has changed quite drastically
-
I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.
The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".
@bagder I get this with fwupd too. Everything that's AI found is reported as a CVSS 10.0 CRITICAL vulnerability, and then you find out it's assuming the attacker has write access on /etc or something dumb like that.
At that point it's just a regular old typo bugfix like all the other thousands of unimportant commits.
-
Here you can read more.
-
@grayrattus it was never my opinion as much as my summary of the situation... and the situation has changed quite drastically
@bagder yeah. Sorry. More like summary of the situation.