Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. had a good conversation earlier that went something like this:

had a good conversation earlier that went something like this:

Scheduled Pinned Locked Moved Uncategorized
2 Posts 2 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Mike ShewardS This user is from outside of this forum
    Mike ShewardS This user is from outside of this forum
    Mike Sheward
    wrote last edited by
    #1

    had a good conversation earlier that went something like this:

    them: “is AI making pentesting easier?”

    me: “yes.”

    them: “why, because you can use it to look for vulnerabilities in code quicker?”

    me: “no, because it generates vulnerabilities in code quicker”

    Shafik YaghmourS 1 Reply Last reply
    1
    0
    • Mike ShewardS Mike Sheward

      had a good conversation earlier that went something like this:

      them: “is AI making pentesting easier?”

      me: “yes.”

      them: “why, because you can use it to look for vulnerabilities in code quicker?”

      me: “no, because it generates vulnerabilities in code quicker”

      Shafik YaghmourS This user is from outside of this forum
      Shafik YaghmourS This user is from outside of this forum
      Shafik Yaghmour
      wrote last edited by
      #2

      @SecureOwl

      It is even worse than that, so yes static analysis tools have gotten a lot better but the number of false positives are very large.

      So none of this can be automated you need a human in the loop and it is tiiiimmmmee consuming.

      We have been trying to solve this for decades and we are not close to be able to automate bug finding in a way that scales for large projects.

      1 Reply Last reply
      0
      • R ActivityRelay shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Don't have an account? Register

      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups