‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. simoncion · · focus · HN ↗
    My favorite part of the video so far is about thirteen minutes in... when GKH mentions that these tools just do static code analysis -which isn't anything new- and then starts quoting executives from LLM manufacturers and LG Research [0] who acknowledge -in writing- that they believe what they've done with the data that has been hoovered up to enable the manufacture of LLMs is probably not legal.

    [0] ...which is apparently somehow involved in LLM manufacturing...

    1. simoncion · · focus · HN ↗
      Two good parts from later on:

      * «We've observed that these things have a 50% false positive rate. Coverity tried so hard but couldn't get people to buy their software, and it had a 20% false positive rate. No one is going to buy something with a 50% false positive rate.»

      * «If you're going to use these tools, run them locally. The open-weights models that you can run locally are quite good enough. Anything you upload to the SAAS ones will be shared with other people... we've seen so many examples of it happening.»

      In regards to the first point, I think he's failing to consider the fact that you can get most upper management to buy anything by providing them enough food, drugs, sex, and/or fear... but -otherwise-, yeah.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.