OpenSSH 10.5/10.5p1(openssh.org) |
OpenSSH 10.5/10.5p1(openssh.org) |
Oh, that's a nice new feature:)
Can you cite that? I see them specifically welcoming AI security reports; I don't see any evidence that other AI submissions are not welcome.
For example, I found this on a Google search, here is a thread from Theo, the project leader, about LLM output and copyright, where he says they can't accept it into the tree on copyright grounds. https://marc.info/?l=openbsd-tech&m=177425035627562&w=2
Elsewhere in the thread he implies using it for a code review tool is ok
"Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes."
Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them.
So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release.
As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports.
> so using AI like ASAN etc. is welcome.
AddressSanitizer is not "AI", nor does it use AI. [0]
[0] https://static.googleusercontent.com/media/research.google.c...
And why?
Ouch.
AI is here, and it's not going anywhere. It's not going to be pretty, but the people that are going to be hit the hardest are those who cannot -- or worse, refuse to -- adapt.
I'm sympathetic -- I feel both a loss and an existential dread. I've also never, in my 30 years in my field, seen something sweep the technology space so quickly and change things so much overnight, and I see no chance of it stopping anytime soon.