Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
Retr0id
3mo ago
0 comments
Share
It's going to be fun if someone finds a security vulnerability in a commonly-emitted-by-LLMs code pattern. That'll be a lot harder to remediate than "Update dependency xyz"
undefined | Better HN
0 comments
default
newest
oldest
MangoToupe
3mo ago
> if someone finds a security vulnerability in a commonly-emitted-by-LLMs code pattern
how do you distinguish this from injecting a vulnerable dependency to a dependency list?
Retr0id
OP
3mo ago
You can more easily check for known-vulnerable dependencies
MangoToupe
3mo ago
Right, but if you can embed bad packages in LLMs, you can surely embed
any kind of vulnerability imaginable
.
1 more reply
j
/
k
navigate · click thread line to collapse