you are viewing a single comment's thread
view the rest of the comments
[–] 3 points 2 weeks ago (2 children)

Nobody is ignoring anything.

It’s not a license, it’s a policy.

AI tends to “discover” previously discovered vulnerabilities, or obvious vulnerabilities. It also tends to hallucinate vulnerabilities. I’m not saying it’s useless at discovering vulnerabilities, just that a human audit is better.

The policy also doesn’t say you can’t use AI to audit a code base, or even a single diff, so that point is moot.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 1 week ago (1 child)

    AI tends to “discover” previously discovered vulnerabilities,

    Friend - your information is very out-of-date. It's accelerating the discovery of vulnerabilities like crazy. I'm not saying we've hit singularity (or even that we will) but to brush it all off as "it only finds things we already knew about" is copium at this point.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 0 points 1 week ago* (last edited 1 week ago)

    Well it’s a good thing I didn’t say that then. xD

    I think you’re also missing the bigger point that the policy does not prevent you from auditing your code base with AI. That is completely, 100% allowed under this policy.

    Reading comprehension is important.

  • source
  • parent