• merc@sh.itjust.works
    link
    fedilink
    arrow-up
    73
    arrow-down
    1
    ·
    2 days ago

    If you read the discord chat logs, it makes sense. He’s being bombarded by security vulnerabilities discovered via LLMs, from people who barely know how to code and can’t even explain the flaw that their LLM discovered. He’s a solo maintainer, and his choice is either to leave these security vulnerabilities open, or to turn to LLMs to try to keep up with the need for patches.

    I don’t think he made the right choice, but I think he’s probably a much better programmer than me.

    • Dr. Moose@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      1 day ago

      I don’t think he made the right choice, but I think he’s probably a much better programmer than me.

      I’m a senior dev that works with LLMs these days and been running dozen people teams before and reading slop code is a skill that needs to be built through months/years of work no matter how good of a programmer you are - it’s a different skill set.

    • FlexibleToast@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      2 days ago

      This is about to be a big thing. LLMs are very good at finding exploits and creating scripts to exploit them. Now a script kiddy is much more powerful. Companies are trying to figure out how to respond. Red Hat’s Project Lightwell is one such project.

      https://www.redhat.com/en/lightwell