| [09:57:52] | <Greg[m]> | That's great |
| [10:04:25] | <symbioquine[m]> | > So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t. |
| [10:04:25] | <symbioquine[m]> | I assume this means they've been testing whether Mythos identifies existing known/fixed bugs when run against older versions of the code. However, my impression is that those CVE/fixes were probably part of the training data so I wonder if that's really a valid experiment. |
| [10:05:57] | <mstenta[m]> | It's a very optimistic post - maybe TOO optimistic :-) |
| [10:06:23] | <symbioquine[m]> | Yeah, it sounds a bit like confirmation bias talking there - they want to believe it's that good. |
| [10:09:27] | <mstenta[m]> | And it is pretty plainly endorsing a specific company/model |
| [10:09:35] | <symbioquine[m]> | I predict the attacker/defender asymmetry will still persist, however it is good if the margin gets slimmer. |
| [10:09:39] | <mstenta[m]> | So you have to take that for what it is |
| [10:09:53] | <mstenta[m]> | Yea, that was my takeaway too... |
| [10:12:07] | <symbioquine[m]> | It will if they only use "AI" on the defense side, but with it also being used to author more code (even ignoring the problem of exceeding non-human-comprehensibility) that feels like an open question. |
| [10:12:23] | <symbioquine[m]> | s/non-// |
| [10:13:04] | <symbioquine[m]> | Really depends how cheap it is to re-validate the whole codebase with the top-of-the-line tool upon each change that gets released. |
| [10:13:30] | <symbioquine[m]> | * top-of-the-line tool(s), * - and act on the output - upon each |
| [10:14:08] | <symbioquine[m]> | * whole codebase (and dependency closure - obviously) with the, * top-of-the-line tool(s), * - and act on the output - upon each |
| [10:14:59] | <mstenta[m]> | Yep always a moving target |
| [10:16:02] | <mstenta[m]> | We also need to expect that the "bad guys" find novel ways to use these new tools as well |
| [10:16:37] | <mstenta[m]> | "If I were an attacker, how would I hide a vulnerability in this pull request?" |
| [10:17:06] | <mstenta[m]> | the cat and mouse game is eternal |
| [10:23:47] | <symbioquine[m]> | I predict there will also be attempts to poison the training data as part of very long game attacks - e.g. so as to make it blind to certain backdoors. |
| [10:24:19] | <symbioquine[m]> | * training data (of the models used for defense) as part |
| [11:30:16] | * farmBOT has joined #farmos |