Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. The AI slop security reporting is basically extinct.

The AI slop security reporting is basically extinct.

Scheduled Pinned Locked Moved Uncategorized
40 Posts 27 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.socialB This user is from outside of this forum
    bagder@mastodon.social
    wrote last edited by
    #1

    The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

    flpvsk@mastodon.socialF annika@xoxo.zoneA bagder@mastodon.socialB raboof@merveilles.townR grayrattus@mastodon.socialG 10 Replies Last reply
    0
    • bagder@mastodon.socialB bagder@mastodon.social

      The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

      flpvsk@mastodon.socialF This user is from outside of this forum
      flpvsk@mastodon.socialF This user is from outside of this forum
      flpvsk@mastodon.social
      wrote last edited by
      #2

      @bagder as in all AI security reporting doesn't happen? Or just the low quality reporting?

      bagder@mastodon.socialB 1 Reply Last reply
      0
      • flpvsk@mastodon.socialF flpvsk@mastodon.social

        @bagder as in all AI security reporting doesn't happen? Or just the low quality reporting?

        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.socialB This user is from outside of this forum
        bagder@mastodon.social
        wrote last edited by
        #3

        @flpvsk they're close to 100% AI now. High quality

        brian@social.brian.jpB kboyd@phpc.socialK 2 Replies Last reply
        0
        • bagder@mastodon.socialB bagder@mastodon.social

          @flpvsk they're close to 100% AI now. High quality

          brian@social.brian.jpB This user is from outside of this forum
          brian@social.brian.jpB This user is from outside of this forum
          brian@social.brian.jp
          wrote last edited by
          #4

          @bagder @flpvsk Mythos?

          1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            @flpvsk they're close to 100% AI now. High quality

            kboyd@phpc.socialK This user is from outside of this forum
            kboyd@phpc.socialK This user is from outside of this forum
            kboyd@phpc.social
            wrote last edited by
            #5

            @bagder @flpvsk do you know which specific tools/models they come from?

            1 Reply Last reply
            0
            • bagder@mastodon.socialB bagder@mastodon.social

              The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

              annika@xoxo.zoneA This user is from outside of this forum
              annika@xoxo.zoneA This user is from outside of this forum
              annika@xoxo.zone
              wrote last edited by
              #6

              @bagder What do you think changed? Better tools? Stopping the bug bounty?

              bagder@mastodon.socialB 1 Reply Last reply
              1
              0
              • annika@xoxo.zoneA annika@xoxo.zone

                @bagder What do you think changed? Better tools? Stopping the bug bounty?

                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.socialB This user is from outside of this forum
                bagder@mastodon.social
                wrote last edited by
                #7

                @annika the tooling for sure, nothing else

                j_s_j@mastodon.socialJ aedius@lavraievie.socialA 2 Replies Last reply
                0
                • bagder@mastodon.socialB bagder@mastodon.social

                  @annika the tooling for sure, nothing else

                  j_s_j@mastodon.socialJ This user is from outside of this forum
                  j_s_j@mastodon.socialJ This user is from outside of this forum
                  j_s_j@mastodon.social
                  wrote last edited by
                  #8

                  @bagder @annika What was the total time between “this slop is a problem” and “this stuff is pretty good”?

                  grayrattus@mastodon.socialG 1 Reply Last reply
                  0
                  • bagder@mastodon.socialB bagder@mastodon.social

                    The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.socialB This user is from outside of this forum
                    bagder@mastodon.social
                    wrote last edited by
                    #9

                    I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.

                    The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".

                    kboyd@phpc.socialK evilpie@hachyderm.ioE hughsie@mastodon.socialH utopiah@mastodon.pirateparty.beU langerjan@chaos.socialL 9 Replies Last reply
                    0
                    • bagder@mastodon.socialB bagder@mastodon.social

                      @annika the tooling for sure, nothing else

                      aedius@lavraievie.socialA This user is from outside of this forum
                      aedius@lavraievie.socialA This user is from outside of this forum
                      aedius@lavraievie.social
                      wrote last edited by
                      #10

                      @bagder @annika

                      I assume that they also used your free work to create the prompt that refuse a lot of bad report internaly.

                      1 Reply Last reply
                      0
                      • bagder@mastodon.socialB bagder@mastodon.social

                        The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

                        raboof@merveilles.townR This user is from outside of this forum
                        raboof@merveilles.townR This user is from outside of this forum
                        raboof@merveilles.town
                        wrote last edited by
                        #11

                        @bagder I wish this was my experience 😆. But it's certainly getting better.

                        1 Reply Last reply
                        0
                        • bagder@mastodon.socialB bagder@mastodon.social

                          I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.

                          The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".

                          kboyd@phpc.socialK This user is from outside of this forum
                          kboyd@phpc.socialK This user is from outside of this forum
                          kboyd@phpc.social
                          wrote last edited by
                          #12

                          @bagder Yeah, seems like around january things flipped around.

                          I was hoping the slop would continue to be slop, but alas. Wishful thinking on my part (to make it easier to disregard the fad).

                          1 Reply Last reply
                          0
                          • bagder@mastodon.socialB bagder@mastodon.social

                            I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.

                            The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".

                            evilpie@hachyderm.ioE This user is from outside of this forum
                            evilpie@hachyderm.ioE This user is from outside of this forum
                            evilpie@hachyderm.io
                            wrote last edited by
                            #13

                            @bagder The other problem with AI bug reports is the verbosity, otherwise I basically agree.

                            bagder@mastodon.socialB 1 Reply Last reply
                            0
                            • bagder@mastodon.socialB bagder@mastodon.social

                              The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

                              grayrattus@mastodon.socialG This user is from outside of this forum
                              grayrattus@mastodon.socialG This user is from outside of this forum
                              grayrattus@mastodon.social
                              wrote last edited by
                              #14

                              @bagder I love how you changed your opinion on this topic when you saw real evidence in form of good security reports written by AI.

                              If someone would write this 2 years ago I would say they are delusional but today its just reality.

                              I hope soon we get open models with such capabilities as for now only the gatekeeped models from big tech are capable of doing such good work.

                              #LLMs #genai #anthropic

                              bagder@mastodon.socialB 1 Reply Last reply
                              0
                              • evilpie@hachyderm.ioE evilpie@hachyderm.io

                                @bagder The other problem with AI bug reports is the verbosity, otherwise I basically agree.

                                bagder@mastodon.socialB This user is from outside of this forum
                                bagder@mastodon.socialB This user is from outside of this forum
                                bagder@mastodon.social
                                wrote last edited by
                                #15

                                @evilpie true they are normally way too talkative

                                1 Reply Last reply
                                0
                                • bagder@mastodon.socialB bagder@mastodon.social

                                  The AI slop security reporting is basically extinct. It almost does not happen anymore. At all.

                                  varpie@peculiar.floristV This user is from outside of this forum
                                  varpie@peculiar.floristV This user is from outside of this forum
                                  varpie@peculiar.florist
                                  wrote last edited by
                                  #16

                                  @bagder Didn't you share one just 2 days ago though? hackerone.com/reports/3669305

                                  edmcbane@hachyderm.ioE 1 Reply Last reply
                                  0
                                  • grayrattus@mastodon.socialG grayrattus@mastodon.social

                                    @bagder I love how you changed your opinion on this topic when you saw real evidence in form of good security reports written by AI.

                                    If someone would write this 2 years ago I would say they are delusional but today its just reality.

                                    I hope soon we get open models with such capabilities as for now only the gatekeeped models from big tech are capable of doing such good work.

                                    #LLMs #genai #anthropic

                                    bagder@mastodon.socialB This user is from outside of this forum
                                    bagder@mastodon.socialB This user is from outside of this forum
                                    bagder@mastodon.social
                                    wrote last edited by
                                    #17

                                    @grayrattus it was never my opinion as much as my summary of the situation... and the situation has changed quite drastically

                                    grayrattus@mastodon.socialG 1 Reply Last reply
                                    0
                                    • bagder@mastodon.socialB bagder@mastodon.social

                                      I want to emphasize this because when I talk about AI security reports now, half my readers seem to believe those are AI slop. They're not. They are found with AI tools and normally high quality bug reports.

                                      The weakest part is that they tend to overstress the vulnerability angle. Lots of them are well phrased bug reports that are still "just bugs".

                                      hughsie@mastodon.socialH This user is from outside of this forum
                                      hughsie@mastodon.socialH This user is from outside of this forum
                                      hughsie@mastodon.social
                                      wrote last edited by
                                      #18

                                      @bagder I get this with fwupd too. Everything that's AI found is reported as a CVSS 10.0 CRITICAL vulnerability, and then you find out it's assuming the attacker has write access on /etc or something dumb like that.

                                      At that point it's just a regular old typo bugfix like all the other thousands of unimportant commits.

                                      1 Reply Last reply
                                      0
                                      • j_s_j@mastodon.socialJ j_s_j@mastodon.social

                                        @bagder @annika What was the total time between “this slop is a problem” and “this stuff is pretty good”?

                                        grayrattus@mastodon.socialG This user is from outside of this forum
                                        grayrattus@mastodon.socialG This user is from outside of this forum
                                        grayrattus@mastodon.social
                                        wrote last edited by
                                        #19

                                        @j_s_j @bagder @annika month.

                                        Link Preview Image
                                        Claude Mythos Preview \ red.anthropic.com

                                        favicon

                                        (red.anthropic.com)

                                        Here you can read more.

                                        1 Reply Last reply
                                        0
                                        • bagder@mastodon.socialB bagder@mastodon.social

                                          @grayrattus it was never my opinion as much as my summary of the situation... and the situation has changed quite drastically

                                          grayrattus@mastodon.socialG This user is from outside of this forum
                                          grayrattus@mastodon.socialG This user is from outside of this forum
                                          grayrattus@mastodon.social
                                          wrote last edited by
                                          #20

                                          @bagder yeah. Sorry. More like summary of the situation.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups