DrWhax

@drwhax@infosec.exchange · Joined ⁨Nov⁩ ⁨2022⁩

professional troublemaker

Hart voor Internetvrijheid
hviv.nl/
Languages
NL/EN/ES
GPG
0x2C9686C23DF31CBF602F2906748800B2AB826D05

Replying to @⁨zimzat@mastodon.social⁩

@zimzat No one wants to fund it is what I think.

Suhosin did something like this for PHP, now it's just jvoisin maintaining snufflepagus: github.com/jvoisin/snuffleupag

I don't remember if there was something similar for other languages. Grsecurity for the Linux Kernel, that's the three I know :/

github.com/jvoisin/snuffleupagus
Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! - jvoisin/snuffleupagusGitHubGitHub - jvoisin/snuffleupagus: Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! - jvoisin/snuffleupagus

Replying to @⁨alice_pea_3526@mastodon.social⁩

@alice_pea_3526 the parrots are pretty good at pattern recognition which is where I think they shine. Some smaller projects as well, but architecture wise, you'll have to handhold them a lot. Its almost like having a junior that's good in some incredibly niche things, but you'll be iterating a lot over code.

I think curl maintainer said something similar, the reports used to be bad from LLM's and they suddenly got a lot better. It still requires a pair of human eyes to understand if its not hallucinating.

I wish it was better at eliminating whole bug classes tho, that'd be the ideal situation?

Replying to @⁨fabrice@fosstodon.org⁩

DrWhax@drwhax@infosec.exchange

@koehntopp this parrot is really good at pattern recognition, it can code and fix some I think given enough constraints and a feedback loop of adversarial review, but it still might not be up to the style of the codebase or it might even introduce new vulnerabilities. I still think we also haven't it fully figured out yet? I think this needs more benchmarks that are reproducible in some fashion

Replying to @⁨koehntopp@infosec.exchange⁩

@koehntopp this parrot is really good at pattern recognition, it can code and fix some I think given enough constraints and a feedback loop of adversarial review, but it still might not be up to the style of the codebase or it might even introduce new vulnerabilities. I still think we also haven't it fully figured out yet? I think this needs more benchmarks that are reproducible in some fashion

Replying to @⁨failedLyndonLaRouchite@mas.to⁩

@failedLyndonLaRouchite They are, but they have flaws and the way these models are created is quite shit and there's a lot of things to say about that. It's not that I say, anthropic good, or openai good. It's more to say, we're entering an era with a lot of shit going to be thrown at people, companies and maintainers and I don't think people realize what's about to hit them!

Replying to @⁨macattackmicmac@mastodon.social⁩

@macattackmicmac for that particular session it was roughly 122 USD in API costs, but since it was subsidized, it was only $20 in a subscription: gist.github.com/DrWhax/465da15

gist.github.com/DrWhax/465da154f2ac1575cfc72aa71aa979e6
GitHub Gist: instantly share code, notes, and snippets.Gistgist:465da154f2ac1575cfc72aa71aa979e6GitHub Gist: instantly share code, notes, and snippets.