Impact de l’IA sur la recherche de failles de sécu­rité

Simon Willi­son a démarré un regrou­pe­ment de ses liens à propos d’IA et de recherche de sécu­rité.

Les cita­tions montrent qu’il se passe indé­nia­ble­ment quelque chose. La seconde cita­tion (au moment où j’écris ce billet) est majeure.

On the kernel secu­rity list we’ve seen a huge bump of reports. We were between 2 and 3 per week maybe two years ago, then reached proba­bly 10 a week over the last year with the only diffe­rence being only AI slop, and now since the begin­ning of the year we’re around 5–10 per day depen­ding on the days (fridays and tues­days seem the worst). Now most of these reports are correct, to the point that we had to bring in more main­tai­ners to help us.

And we’re now seeing on a daily basis some­thing that never happe­ned before: dupli­cate reports, or the same bug found by two different people using (possi­bly slightly) different tools.

Willy Tarreau, Lead Soft­ware Deve­lo­per. HAPROXY

Comments

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *