Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
undefined | Better HN
0 points
MangoToupe
5mo ago
0 comments
Share
> if someone finds a security vulnerability in a commonly-emitted-by-LLMs code pattern
how do you distinguish this from injecting a vulnerable dependency to a dependency list?
0 comments
default
newest
oldest
Retr0id
5mo ago
You can more easily check for known-vulnerable dependencies
MangoToupe
OP
5mo ago
Right, but if you can embed bad packages in LLMs, you can surely embed
any kind of vulnerability imaginable
.
Retr0id
5mo ago
I'm not thinking about deliberately embedded vulnerabilities, just accidental/emergent ones. The modern equivalent of devs copy-pasting stackoverflow answers that happen to contain SQL injection vulns.
MangoToupe
OP
5mo ago
Does the distinction make any difference?
1 more reply
j
/
k
navigate · click thread line to collapse