Site icon MSN Technology

Open source project curl is sick of users submitting “AI slop” vulnerabilities

a call to arms against the ai horde 1152x648

a call to arms against the ai horde

The ARS has arrived in the hacker for comments and will update this post if we get a response.

“More tools to eliminate this behavior”

In an interview to the ARS, Stanburg said he was happy that he had made 200 comments and about 400 400 reps by Wednesday morning. “I am so happy that the problem [is getting] Attention so that we might do something about it [and] Stanberg said teach the audience that it is a state of things.

Steinberg said that four such misleading this week, obviously, AI-generated weakness reports are apparently looking for either credibility or bug grace funds. He said, “One way you can tell is always such a good report. With friendly words, perfect English, humble, good bullet points … an ordinary person never does this in his first writing.”

Some AI reports are easier to find than others. “Someone mistakenly affixed to his signal,” said Stanburg, “and he eliminated it,” and made it dangerous. “

Steinberg said he has “talked [HackerOne] “And this week’s service has reached.” I would like to strengthen something, something to do. I want to help create infrastructure around them [AI tools] Better and give us more tools to eliminate this behavior.

Open Source Security firm’s comments with Tobius Holdt, Stanburg, in commercial comments XorSuggest that Big Grace programs could potentially use “existing networks and infrastructure”. “There may be a way to filter the signal and reduce the noise to review a report to pay for the security reporters,” Holdt said. Somewhere else, Steinberg said when AI notifications are not drowning us, [the] The trend does not look good. “

Steinburg is before Blog on your site Regarding AI-Infanted weakness reports, with more details about what they look and what they go wrong. Security developer at the Azgar Software Foundation added Seth Larson to Stanburg results His own examples and suggested stepsAs, as Noted by the register.

“If this is happening with a handful of projects that I have, I am suspected to have been widespread to open source projects,” Larson wrote in December. “This is a very trend.”

Source link

Exit mobile version