• Wildmimic@anarchist.nexus
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    1 day ago

    That depends. If an coding LLM finds a vulnerability, would you have been able to find it yourself? And the more important part is: do i blindly merge whatever i get thrown at me or do i critically engage with it, analyze why this is a security issue and how to prevent it in the future?

    The thing is: an LLM can NEVER replace secure design. The best LLM can’t do shit if you have designed your software without security in mind from the start. And this also means this area will never be fully solved by machines, outside of them becoming able to code the thing securely from start to finish (and even then the design which is the basis of that software has to take security into account, or whatever you get will be insecure by default). This is one of the areas that can be massively enhanced by AI, but it can’t replace people that are able to design secure systems.