Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In regard to “cyber”, there is, IMO, no valid reason whatsoever to train a model to autonomously create exploit chains.

Field testing is a real thing in literally all industries.

Except, apparently, the software industry. When it comes to software security and protecting your sensitive data, the solution is "trust me bro, I got my team of the best lawyers on it".



> Field testing is a real thing in literally all industries.

I’m fairly confident that, if a company that makes door locks want to field test their locks, they test the lock and maybe the door. For some reason the software industry likes to hire someone to test the lock but also to bug the conference room, poison the food in the fridge, blackmail the receptionist, and try to intimidate third party vendors into giving away keys to all the other locks, and maybe steal a few cars while they’re at it.

I’m not objecting so much to the attempts to exploit one target. I am objecting to the fact that people treat the exploit chains as such a big deal. And the recent models are clearly going massively overboard.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: