upvote
I trust them but it's immediately evident the instruction it gives to future bad actors: buy HN accounts, post false "security check passed" comments.

Is there a VirusTotal.com-but-LLM-analysis that folks could link to instead where we'd trust the prompts were sent and the responses were indeed received from the stated models? Hopefully run by someone with quite the budget and/or reputation.

reply
I disagree. I thought of it as a noble public service. But as with everything else on the internet buyer beware.
reply
Agree. I see it as informative to newcomers as to what they should do themselves.

This is how people learn.

reply
Right. Dude even included the prompt. Exemplary for this community I would hope.
reply
Someone could come into this post and leave a comment saying they're a security researcher, that they audited the codebase, and include a summary of their findings. And that person could be lying.

I think saying that it contributes nothing because a) someone could do it themselves, b) the output might be slop, and/or c) they could be lying, is a bit silly. Those things apply to basically everything posted on the internet.

Whether an LLM security review is actually valuable is an entirely different discussion.

reply
Sure, though I'd be more understanding of someone with little in the way of technical chops posting "here's my alleged LLM output" than someone saying "I'm a security researcher, looks great" when they've never linked any of their publications or anything. That's why I see this as a newer, slightly more dangerous spin on the old issue. (mitigation suggestion in my sibling comment)
reply
Mythos alone proves the future of cybersecurity and software is agentic, and if you don’t believe that, run it back in 2 years when you are fired for someone who does..

+1 at least he cited his sources lol

reply
Friend, you have upvote / downvote with which you can signal to a person the value of their comment. Pontification from a four month old account at that.. nah.
reply
What does their account age have to do with what they said?
reply