Post B6BTr1h0WXxZDFGW1o by keepassxc@fosstodon.org
 (DIR) More posts by keepassxc@fosstodon.org
 (DIR) Post #B6BLDvMLL0pcdwRYps by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       RE: https://mastodon.social/@bagder/116554421875449945"All modern AI models are good at this now. Anyone with time and some experimental spirits can find security problems now. The high quality chaos is real."Second that. The number of confidential security reports for KeePassXC has also gone up (though nothing major yet). Those AI reports used to be slop, but they are now mostly legitimate . We don't know which models are being used by the reporters, but occasionally, we get the same things reported multiple times within the span of just days.RT: https://mastodon.social/users/bagder/statuses/116554421875449945
       
 (DIR) Post #B6BM0z0YYquK9He7DE by dzwiedziu@mastodon.social
       0 likes, 0 repeats
       
       @keepassxc> Those AI reports used to be slop, but they are now mostly legitimate.1 in 5 doesn't look as “mostly legitimate”.To drive the point further, from the quoted blog post:> The report concluded it found five “Confirmed security vulnerabilities”. I think using the term confirmed is a little amusing when the AI says it confidently by itself. Yes, the AI thinks they are confirmed, but the curl security team has a slightly different take.»
       
 (DIR) Post #B6BMBAHjUKZm1HXF5c by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @dzwiedziu The reports we get these days are mostly legitimate now (not all, but most). Legitimate doesn't necessarily mean "high impact".
       
 (DIR) Post #B6BTr1UbGg2EalSbgm by chronocide@sunny.garden
       0 likes, 0 repeats
       
       @keepassxc Have you found them to be helpful compared to pre-LLM reports?
       
 (DIR) Post #B6BTr1h0WXxZDFGW1o by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @Chronocide We didn’t receive that many before, so unclear. They are helpful in the sense that some issue was found that people previously missed. Most are low-hanging fruit like hypothetical integer overflows and mismatches between code and documentation etc.
       
 (DIR) Post #B6BU0KVFxMP49tCmJs by keepassxc@fosstodon.org
       0 likes, 0 repeats
       
       @Chronocide KeePassXC is in the convenient position of having a rather low attack surface to begin with.