The US government cut off access to Mythos because Anthropic marketing claims it's so powerful that it could be misused. If China has a better system, doesn't that obligate companies that believe the marketing to use the Chinese system to find vulnerabilities in their software before somebody else does?
I know what you are talking about, I'm just confused why did you say it. Purely out of context and not respectful.
While I was showing a screenshot of the inner-reasoning behind a censor, you start talking about me being some type of politically stressed when I don't give a heck about your "colors". Just chill and stop randomly attack people you don't even know who are and what thinks.
If you knew what I was talking about then there would be nothing to be confused about. If you don't know what a color revolution is or the history of the US trying to overthrow the government in China, then spend the time to educate yourself instead of clowning around on here. Here's some reading you can start with in fact:
Make a one-time donationYour contribution is appreciated.Donate “As far as can be determined from the available evidence, NO ONE DIED that night in Tiananmen Square.” What?! Who would make such a b…
Please stop. Go touch grass. I don't care about your doctrine and what's inside your brain. What I shared has nothing to do about your provocatory comment. I will no further answer to your disrespectful provocations.
Ultimately, your opinion doesn't matter. China is winning and there's nothing you can do about it.
@yogthos@lemmy.ml is doing you a favor by trying to prepare you for the new world that China is creating. We just want you to understand what is happening; this is hospice care for the US empire. The empire is dying no matter how hard you try to deny the changes to our material reality. If you don't want to listen, that's fine! You'll live in the new world whether you accept it or not.
Guys, are you all hallucinating or something? Who the hell bring up China or USA and its winning or not something? The US empire? The new world? Are you ok?
I'm talking about their implementetion of censoring. Isn't this a tech community?
You guys really seems out of touch. Seems everything about USA vs China or your vision of it. Get out, do stuff with your friends, meet new people and do fun stuff. Don't get mad at people online about something you entirely made up. I didn't talk about anything you pointed.
Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Would you class the western oppression of dissent to be on the same level as that famous student protest in China?
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
📺 The Tiananmen Square "Massacre" Never Happened: , part 2, — [Sources]
Edit to add: YouTube took down for “violating YouTube’s terms of
... Show more...
Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Would you class the western oppression of dissent to be on the same level as that famous student protest in China?
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
📺 The Tiananmen Square "Massacre" Never Happened: , part 2, — [Sources]
Edit to add: YouTube took down for “violating YouTube’s terms of service,” but I found a reploaded a copy, splitting it up into three pieces. This is why you don’t know what really happened, because Western corporate media don’t want you to know. They were reuploaded just today; who knows how long they’ll stay up.
Washington Post, 1989: Rebel Without a Magazine >[Chinese Intellectual’s founder] Liang [Heng] had come from his New York office, where he serves as the magazine's foreign editor, to Washington Thursday and Friday to address the board of directors at the National Endowment for Democracy -- a substantial financial backer of the magazine -- to tell it what he knows, what he thinks and what will possibly happen. >After his arrival in the United States, he earned his master's degree in literature from Columbia University and secured an initial $200,000 grant from the NED, a private corporation created in 1983 to "strengthen democratic efforts worldwide," to start his magazine.
The Seattle Times, 2011: Quiet scholar who inspired uprisings >That is not to say [Gene] Sharp has not seen any action. In 1989, he jetted off to China to witness the uprising in Tiananmen Square. In the early 1990s, he sneaked into a Myanmar rebel camp at the invitation of Robert Helvey, a retired Army colonel who advised the opposition there. They met when Helvey was on a fellowship at Harvard; the military man thought the professor had ideas that could avoid war.
A note of reflection on the June 4th Tiananmen protests written by three members of Qiao Collective whose families were closely involved in the June 4th Tiananmen protests.
It’s an old post. I know the Reddit link is broken because Reddit banned & censored r/TheDeprogram. Reddit censoring socialists is why Lemmy was created in the first place: en.prolewiki.org/wiki/Lemmy#Fo…
Lemmy is a self-hosted, federated, free and open source social link aggregation and discussion platform. It was named after the lead singer from Motörhead, the old...
Chill out man, you don't even know me and you are talking shit about me. I'm no "orientalist dog" and I don't know who you are referring to with "your people".
I'm simply showing an interesting inner-analysis the LLM do when talking about censored stuff. It is always fun to try LLMs limits an see what have been censored and here there is also an inner reasoning which is cut-off.
Learn respect and how to talk to people before making stupid assumptions.
Are you also going to claim that DeepSeek isn’t censored?
You can download DeepSeek and run it yourself to get uncensored answers.
Large Language Models (LLMs) are not truth machines. They are garbage in, garbage out. The input to English-language models are largely English-language texts from Five Eyes countries, with all the disinformation and bias that that entails. So the DeepSeek company is in a “damned if you do, damned if you don’t” situation. They can either refuse to answer certain questions, in which case Western media will accuse them of censorship; or they can answer them, in which case (a) their model will perpetuate Cold War I & Cold War II falsehoods and (b) Western media will parade those false answers around in a victory lap. They chose the former for the cloud version of their app, and the latter for the local version.
I'm aware of open weights and yes, it is clearly a server-side block (since the text generation is cut-off). If I'm not wrong it was DeepSeek I tried (long time ago) locally offline and it was willing to talk even about this type of topics.
I disagree. Finding them has been the easy part. We’ve been using static analysers that could find common vulnerabilities for decades now, and LLMs are pretty good at text tokenisation, searching and matching.
Exploiting them is the hard part. Most researchers would tell you that once they suspect there’s something that can be exploited, there’s a laborious process that comes afterwards, consisting mostly of a lot of trial and error, and progressive discovery.
You're entitled to your opinion, but finding vulnerabilities goes far beyond simply doing static analysis. LLMs are able to find vulnerabilities that emerge from subtle interactions between different features, where things like keys and security credentials aren't handled properly, and finding these by hand in a large codebase is nearly impossible.
The very process of finding these vulnerabilities gives you a path towards making an exploit. And the LLM can actually do this laborious process largely autonomously as well. It can probe a site for example, look at the results, and iterate on them. It's an incredibly effective tool for both finding exploits and testing them out in the wild.
In fact, you can ask piefed devs about their recent security debacle that an LLM exposed and gave a step by step guide for exploiting.
I know how finding vulnerabilities works. I was using static analysis as an example of why exploiting them is the hard part, something that you don’t seem to disagree with.
And I gave you a concrete example of how LLMs both find and exploit these vulnerabilities. It's quite evident that your disagreement stems from not having actually used these tools to find vulnerabilities.
That’s always the issue with LLMs. One have to be an expert in the topic so they aren’t fooled by their answers.
And don’t get me wrong, they are legitimately useful. But going back to my premise, finding a vulnerability has never been the benchmark, exploiting it is. And if you are good at your craft, you should be perfectly able to spot such vulnerability because you are trained to avoid it. Exploiting it is a whole different thing, and way more complex.
What I'm saying here is that the way you actually use LLMs is by having them go through the steps of the exploit. It makes a hypothesis and then it tries it, and then you see the result. There's nothing to be fooled by here because the steps it takes either work or they don't.
The reason LLMs are much better at finding these vulnerabilities is because a human can't keep a large codebase in their head all at once. If you look at a project like Lemmy for example, there's a ton of code in it. You have to be an expert in what that code is doing, how the moving pieces relate to each other, and the domain itself to find the exploit. The LLM can zero in on the problems much easier, and actually take the steps to try the exploit. For example, for the case I mentioned with piefed, the issue was very subtle way the oauth token was being misused. It wasn't localized in one place where auth was done, but manifested in a different part of the codebase that relied on it. Something like that would take a lot of dedicated work to find manually.
The reason LLMs are much better at finding these vulnerabilities is because a human can't keep a large codebase in their head all at once.
They aren’t better. These aren’t things that humans cannot do, or struggle to do. They might be faster, but they definitely aren’t better.
But again, LLM output looks better the less the operator knows about the topic.
Also, why would context size matter here? Even if the vulnerable chain was sparse, that doesn’t mean that the whole codebase needs to be part of the context.
Something like that would take a lot of dedicated work to find manually.
Or not. Maybe for you it would be, but not for a trained researcher. My point here is that one cannot evaluate the capabilities of a machine if they don’t fully understand the process. That’s the “fooled” part. Because even if the final output works, there may be a lot of intermediate steps that aren’t necessary or make no sense or they are plain wrong. But I digre
... Show more...
The reason LLMs are much better at finding these vulnerabilities is because a human can't keep a large codebase in their head all at once.
They aren’t better. These aren’t things that humans cannot do, or struggle to do. They might be faster, but they definitely aren’t better.
But again, LLM output looks better the less the operator knows about the topic.
Also, why would context size matter here? Even if the vulnerable chain was sparse, that doesn’t mean that the whole codebase needs to be part of the context.
Something like that would take a lot of dedicated work to find manually.
Or not. Maybe for you it would be, but not for a trained researcher. My point here is that one cannot evaluate the capabilities of a machine if they don’t fully understand the process. That’s the “fooled” part. Because even if the final output works, there may be a lot of intermediate steps that aren’t necessary or make no sense or they are plain wrong. But I digress: again, the benchmark here is not about finding vulnerabilities because that’s the easy part, it’s about exploiting them.
Yes, these are absolutely things humans struggle to do. And finding more exploits faster is literally better.
Again, you just keep ignoring what I write here and you clearly don't understand how these tools are actually used. You're not just having LLM come up with some hypothesis at random here. You use the tool to do the attack. I don't know why this bit of information is so hard for you to process.
Also, it should be obvious why it's hard to find correlations in a large set of data than in a small one. Go think about why where's waldo is hard for humans.
Or not. Maybe for you it would be, but not for a trained researcher.
Maybe you should stop trying to debate a topic you're very clearly not qualified to have an opinion on. It doesn't matter if there are intermediate steps which are necessary to make or not. The discussion is about exploits. Either you get unauthorized access or you don't. Either you have a hole in your system or you don't.
And as I've repeatedly explained to you, and you studiously ignored, finding and ex
... Show more...
Yes, these are absolutely things humans struggle to do. And finding more exploits faster is literally better.
Again, you just keep ignoring what I write here and you clearly don't understand how these tools are actually used. You're not just having LLM come up with some hypothesis at random here. You use the tool to do the attack. I don't know why this bit of information is so hard for you to process.
Also, it should be obvious why it's hard to find correlations in a large set of data than in a small one. Go think about why where's waldo is hard for humans.
Or not. Maybe for you it would be, but not for a trained researcher.
Maybe you should stop trying to debate a topic you're very clearly not qualified to have an opinion on. It doesn't matter if there are intermediate steps which are necessary to make or not. The discussion is about exploits. Either you get unauthorized access or you don't. Either you have a hole in your system or you don't.
And as I've repeatedly explained to you, and you studiously ignored, finding and exploiting these vulnerabilities is part of the same process. The LLM tests what it does against a live system, and it builds the exploit step by step.
Also, here's what Linus has to say on the subject since you're just going to ignore anything I say. theregister.com/security/2026/…
Maybe you should stop trying to debate a topic you're very clearly not qualified to have an opinion on.
I worked in security for a decade. I think I am entitled to my own opinion, even if you don’t like or don’t understand it.
Anyway, I have made my point. Cheers.
Edit: lol, straight from your link
Linux kernel boss Linus Torvalds has declared the project’s security mailing list has become “almost entirely unmanageable” due to multiple researchers using AI to find bugs and then filling the list with duplicate reports.
worked in security for a decade. I think I am entitled to my own opinion, even if you don’t like or don’t understand it.
Not only do I understand your opinion, I've also spent a lot of time explaining the problems with your claims here.
Also, not sure what the lol here is. What the part you highlighted supports my point which is it's becoming much easier to find exploits, hence why you see more duplicate reports.
Again, I'm not disagreeing that you can use LLMs to audit all these things. All I'm saying is that software is by far the easiest place to apply models and actually try out exploits end to end.
I believe your intent. Reponses before your clarification are justified in operating under a general cybersecurity definition, not one tied only to a narrower scope of just software.
Claiming context is obvious is flawed. Obvious is a local term. It may have been obvious to you, it was not obvious from the statement itself.
Your internal context should not be treated as globally shared context.
i_am_not_a_robot
in reply to ☆ Yσɠƚԋσʂ ☆ • • •iocase
in reply to i_am_not_a_robot • • •We live in a post-truth post-logic post-reason era.
What ever makes the line go up more. That's the answer.
☆ Yσɠƚԋσʂ ☆
in reply to i_am_not_a_robot • • •MrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •It stops here.
☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •MrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •MrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I know what you are talking about, I'm just confused why did you say it. Purely out of context and not respectful.
While I was showing a screenshot of the inner-reasoning behind a censor, you start talking about me being some type of politically stressed when I don't give a heck about your "colors". Just chill and stop randomly attack people you don't even know who are and what thinks.
☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •If you knew what I was talking about then there would be nothing to be confused about. If you don't know what a color revolution is or the history of the US trying to overthrow the government in China, then spend the time to educate yourself instead of clowning around on here. Here's some reading you can start with in fact:
Tiananmen Square Massacre – Facts, Fiction and Propaganda
World AffairsMrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •Please stop. Go touch grass. I don't care about your doctrine and what's inside your brain. What I shared has nothing to do about your provocatory comment. I will no further answer to your disrespectful provocations.
Have a nice day.
☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •MrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •MrSoup
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to MrSoup • • •queermunist she/her
in reply to MrSoup • • •Ultimately, your opinion doesn't matter. China is winning and there's nothing you can do about it.
@yogthos@lemmy.ml is doing you a favor by trying to prepare you for the new world that China is creating. We just want you to understand what is happening; this is hospice care for the US empire. The empire is dying no matter how hard you try to deny the changes to our material reality. If you don't want to listen, that's fine! You'll live in the new world whether you accept it or not.
MrSoup
in reply to queermunist she/her • • •Guys, are you all hallucinating or something? Who the hell bring up China or USA and its winning or not something? The US empire? The new world? Are you ok?
I'm talking about their implementetion of censoring. Isn't this a tech community?
You guys really seems out of touch. Seems everything about USA vs China or your vision of it. Get out, do stuff with your friends, meet new people and do fun stuff. Don't get mad at people online about something you entirely made up. I didn't talk about anything you pointed.
queermunist she/her
in reply to MrSoup • • •Why are you talking about "their implementetion of censoring"? It has nothing to do with the OP.
The OP is about China matching Anthropic and you can't engage with that topic because you hate China so much.
MrSoup
in reply to queermunist she/her • • •Why would I hate China? I don't get why are you putting words up in my mouth.
Because it's fun. Don't you test systems or play with software?
mabeledo
in reply to MrSoup • • •No. This is just common lemmy.ml behavior.
davel
in reply to MrSoup • • •MrSoup
in reply to davel • • •I'm sorry, this link doesn't work:
davel
in reply to MrSoup • • •Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
- 📺 The Tiananmen Square "Massacre" Never Happened: , part 2, — [Sources]
- Edit to add: YouTube took down for “violating YouTube’s terms of
... Show more...Oh, sorry. The poster deleted their post which broke the link to the comment. Copypasta:
Only someone misinformed about the 1989 protest and US/CIA/NED-orchestrated, murderously violent riot would ask this, which to be fair is 99% of Westerners.
>[Chinese Intellectual’s founder] Liang [Heng] had come from his New York office, where he serves as the magazine's foreign editor, to Washington Thursday and Friday to address the board of directors at the National Endowment for Democracy -- a substantial financial backer of the magazine -- to tell it what he knows, what he thinks and what will possibly happen.
>After his arrival in the United States, he earned his master's degree in literature from Columbia University and secured an initial $200,000 grant from the NED, a private corporation created in 1983 to "strengthen democratic efforts worldwide," to start his magazine.
>That is not to say [Gene] Sharp has not seen any action. In 1989, he jetted off to China to witness the uprising in Tiananmen Square. In the early 1990s, he sneaked into a Myanmar rebel camp at the invitation of Robert Helvey, a retired Army colonel who advised the opposition there. They met when Helvey was on a fellowship at Harvard; the military man thought the professor had ideas that could avoid war.
A Note on the Tiananmen Protests
Qiao Collective(Nitter addon enabled: Twitter links via https://nitter.privacytools.io)
MrSoup
in reply to davel • • •Those YouTube links don't work anymore and in its patreon are not present (at least without paying).
Though it was an interesting read (of the working links).
davel
in reply to MrSoup • • •Lemmy - ProleWiki
ProleWikiMrSoup
in reply to davel • • •brucethemoose
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I guess that’s why they literally need to censor the topic from the model UI?
The knowledge is in the open weights, though, at least for older GLM releases.
ghost_laptop
in reply to MrSoup • • •MrSoup
in reply to ghost_laptop • • •Chill out man, you don't even know me and you are talking shit about me. I'm no "orientalist dog" and I don't know who you are referring to with "your people".
I'm simply showing an interesting inner-analysis the LLM do when talking about censored stuff. It is always fun to try LLMs limits an see what have been censored and here there is also an inner reasoning which is cut-off.
Learn respect and how to talk to people before making stupid assumptions.
davel
in reply to MrSoup • • •Previously:
MrSoup
in reply to davel • • •mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I disagree. Finding them has been the easy part. We’ve been using static analysers that could find common vulnerabilities for decades now, and LLMs are pretty good at text tokenisation, searching and matching.
Exploiting them is the hard part. Most researchers would tell you that once they suspect there’s something that can be exploited, there’s a laborious process that comes afterwards, consisting mostly of a lot of trial and error, and progressive discovery.
☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •You're entitled to your opinion, but finding vulnerabilities goes far beyond simply doing static analysis. LLMs are able to find vulnerabilities that emerge from subtle interactions between different features, where things like keys and security credentials aren't handled properly, and finding these by hand in a large codebase is nearly impossible.
The very process of finding these vulnerabilities gives you a path towards making an exploit. And the LLM can actually do this laborious process largely autonomously as well. It can probe a site for example, look at the results, and iterate on them. It's an incredibly effective tool for both finding exploits and testing them out in the wild.
In fact, you can ask piefed devs about their recent security debacle that an LLM exposed and gave a step by step guide for exploiting.
mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •That’s always the issue with LLMs. One have to be an expert in the topic so they aren’t fooled by their answers.
And don’t get me wrong, they are legitimately useful. But going back to my premise, finding a vulnerability has never been the benchmark, exploiting it is. And if you are good at your craft, you should be perfectly able to spot such vulnerability because you are trained to avoid it. Exploiting it is a whole different thing, and way more complex.
☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •What I'm saying here is that the way you actually use LLMs is by having them go through the steps of the exploit. It makes a hypothesis and then it tries it, and then you see the result. There's nothing to be fooled by here because the steps it takes either work or they don't.
The reason LLMs are much better at finding these vulnerabilities is because a human can't keep a large codebase in their head all at once. If you look at a project like Lemmy for example, there's a ton of code in it. You have to be an expert in what that code is doing, how the moving pieces relate to each other, and the domain itself to find the exploit. The LLM can zero in on the problems much easier, and actually take the steps to try the exploit. For example, for the case I mentioned with piefed, the issue was very subtle way the oauth token was being misused. It wasn't localized in one place where auth was done, but manifested in a different part of the codebase that relied on it. Something like that would take a lot of dedicated work to find manually.
mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •They aren’t better. These aren’t things that humans cannot do, or struggle to do. They might be faster, but they definitely aren’t better.
But again, LLM output looks better the less the operator knows about the topic.
Also, why would context size matter here? Even if the vulnerable chain was sparse, that doesn’t mean that the whole codebase needs to be part of the context.
... Show more...Or not. Maybe for you it would be, but not for a trained researcher. My point here is that one cannot evaluate the capabilities of a machine if they don’t fully understand the process. That’s the “fooled” part. Because even if the final output works, there may be a lot of intermediate steps that aren’t necessary or make no sense or they are plain wrong. But I digre
They aren’t better. These aren’t things that humans cannot do, or struggle to do. They might be faster, but they definitely aren’t better.
But again, LLM output looks better the less the operator knows about the topic.
Also, why would context size matter here? Even if the vulnerable chain was sparse, that doesn’t mean that the whole codebase needs to be part of the context.
Or not. Maybe for you it would be, but not for a trained researcher. My point here is that one cannot evaluate the capabilities of a machine if they don’t fully understand the process. That’s the “fooled” part. Because even if the final output works, there may be a lot of intermediate steps that aren’t necessary or make no sense or they are plain wrong. But I digress: again, the benchmark here is not about finding vulnerabilities because that’s the easy part, it’s about exploiting them.
☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •Yes, these are absolutely things humans struggle to do. And finding more exploits faster is literally better.
Again, you just keep ignoring what I write here and you clearly don't understand how these tools are actually used. You're not just having LLM come up with some hypothesis at random here. You use the tool to do the attack. I don't know why this bit of information is so hard for you to process.
Also, it should be obvious why it's hard to find correlations in a large set of data than in a small one. Go think about why where's waldo is hard for humans.
Maybe you should stop trying to debate a topic you're very clearly not qualified to have an opinion on. It doesn't matter if there are intermediate steps which are necessary to make or not. The discussion is about exploits. Either you get unauthorized access or you don't. Either you have a hole in your system or you don't.
And as I've repeatedly explained to you, and you studiously ignored, finding and ex
... Show more...Yes, these are absolutely things humans struggle to do. And finding more exploits faster is literally better.
Again, you just keep ignoring what I write here and you clearly don't understand how these tools are actually used. You're not just having LLM come up with some hypothesis at random here. You use the tool to do the attack. I don't know why this bit of information is so hard for you to process.
Also, it should be obvious why it's hard to find correlations in a large set of data than in a small one. Go think about why where's waldo is hard for humans.
Maybe you should stop trying to debate a topic you're very clearly not qualified to have an opinion on. It doesn't matter if there are intermediate steps which are necessary to make or not. The discussion is about exploits. Either you get unauthorized access or you don't. Either you have a hole in your system or you don't.
And as I've repeatedly explained to you, and you studiously ignored, finding and exploiting these vulnerabilities is part of the same process. The LLM tests what it does against a live system, and it builds the exploit step by step.
Also, here's what Linus has to say on the subject since you're just going to ignore anything I say. theregister.com/security/2026/…
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
Simon Sharwood (theregister)mabeledo
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I worked in security for a decade. I think I am entitled to my own opinion, even if you don’t like or don’t understand it.
Anyway, I have made my point. Cheers.
Edit: lol, straight from your link
Great job guys!
☆ Yσɠƚԋσʂ ☆
in reply to mabeledo • • •Not only do I understand your opinion, I've also spent a lot of time explaining the problems with your claims here.
Also, not sure what the lol here is. What the part you highlighted supports my point which is it's becoming much easier to find exploits, hence why you see more duplicate reports.
Cheers.
TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •That was not obvious to me. LLMs have been used for finding hardware, firmware, RF, software, and social exploits.
RAM side-channel attacks are a good example of software exploits that are harder to exploit than find the vulnerability.
☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •Your original comment was:
☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •TrippinMallard
in reply to ☆ Yσɠƚԋσʂ ☆ • • •I believe your intent. Reponses before your clarification are justified in operating under a general cybersecurity definition, not one tied only to a narrower scope of just software.
Claiming context is obvious is flawed.
Obvious is a local term.
It may have been obvious to you, it was not obvious from the statement itself.
Your internal context should not be treated as globally shared context.
☆ Yσɠƚԋσʂ ☆
in reply to TrippinMallard • • •