cwebber@social.coop ("Christine Lemmer-Webber") wrote:
I really don't think that you can fight LLM agent exposed and exploited security issues with *more vibes*. You absolutely cannot. These machines are good at finding exploits, but they are also good at *inserting* them, accidentally all over the place, and also in terms of them being the perfect machines to insert subtle, hard-to-find intentional vulnerabilities.
In terms of using them as vulnerability scanners, I think they're important tools. In terms of code generation, there is simply no way to fight vibes with more vibes.
Instead, we need to get systemic about things.
So how do we fix security issues SYSTEMICALLY?