infosec and LLM reliant apps are in this weird space where things are moving both extremely fast and extremely slow.
Pentest service power by LLMs? 1000 new ones every day.
Logging what your LLM does and enforcing privs? Too boring, ship it.
@ZackKorman it's like orgs forget the years of incidents and security nightmare the moment a new technology is out. I'm pretty sure they could've put the config files into an LLM and get it flagged and yet they didn't.
@jonaasw1@meshtimes_@ProofofMaro@covacut people have been building fancy cyberdecks and posting them for a literal decade plus, it's just the algo that's better at promoting them now
@IceSolst actual genius marketing, make mythos seem scary/powerful so they can actually charge more for it to offset all the freloaders/subscription users
i need to figure out a way to add some salt(ing) whenever i am throwing delicious private information into the gaping mouth of the eternal knowledge devourers that are LLMs
@IceSolst surely nothing goes wrong whenever someone gives full unrestricted access to their agents. surely there haven't been hundreds of cases of this happening.
@aiamblichus the CEO of an AI lab is also its biggest hype man and marketer. They'll skirt around and bend the truth to secure funding. In their heard of hearts, they maybe even believe what they're saying.
remember when you were 15 and made a list of all the things you wanted to learn? how unrealistic it was? how's that list doing now? are you still learning? because you should.
@C2IRIS the industry is also quite young so there hasn't been that much time for greybeards show up. VR wasn't even a career path until 15-20 years ago.