Damus
Michael Kennedy · 7w
Do you know whether extensive Opus work looking for vulnerabilities in CPython or Django have been run? Putting Mythos aside, Opus is very good at this. I'd be interested to know whether it found anyt...
Glyph profile picture
@nprofile1q... One major point that the third article makes is an argument of cost-effectiveness. There’s not really any evidence that Opus, or for that matter Mythos, is a material cost improvement over just paying security researchers for their time to look for bugs using other methods, like inspection and fuzzing. And that’s just considering direct monetary costs. There’s definitely no reason to invoke the massive externalities (environmental, psychological, political) of AI workflows for this.
1
Michael Kennedy · 7w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqpfe56vzppw077dd04ycr8mx72dqdk0m95ccdfu2j9ak3n7m89nrsrv5raw Hey Glyph! Fair, but if Glasswing spent $1M on security research for this Firefox thing, a similar question then could be, has the PSF/Core devs spent a dedicated $1M discovery process ...