‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. 0xbadcafebee · · focus · HN ↗
    "Ignore the comments, look at the code" - 100% agree. The comments and "explanations" will end up confusing you and often being wrong. But the code doesn't lie.

    "NEVER upload any non-public information" - He's talking about how if you give Claude/GPT some secret info (like research, credentials, etc), it will train on it and give the same info to someone else. This is 100% the case for the free and consumer versions of these models, which is what most people use. For Enterprise plans they're not supposed to be doing this, but it's possible they will screw up and do it anyway.

    1. wahern · · focus · HN ↗
      Lies, damn lies, and comments.

      The discourse has moved on for now, but 10-20 years ago when, why, and how to comment code was a hot topic. I'm sure the discourse will circle back, especially given how comments can be used to steer these models.

      1. eichin · · focus · HN ↗
        mmm, in my circles commenting (at a higher level than the code, I think obviously? and yeah, comment maintenance is non-trivial) was valuable, but also "if the comments and the code disagree, treat both as wrong".
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.