• voronaam@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    20 hours ago

    I am sorry, to enroll a primary maintainers need to open a Pull Request with a Yaml file containing their email address?

    And people do that? Here is an example PR: https://github.com/anthropics/oss-scanner/pull/139/changes

    Did Anthropic just created a largest ever publicly available collection of email addresses of primary maintainers of OSS projects matching this criteria

    established projects that have a critical impact on infrastructure and user security

    (Quote from Anthropic)

    Is it an invitation for every bad actor to scrape pull requests of this single repo, extract email addresses and target those with every fishing/hacking/account takeover attack imaginable?

    Is not that insane?

  • vane@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    18 hours ago

    They are hungry for active projects, want to distill better datasets.

  • Zedstrian@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    61
    arrow-down
    7
    ·
    1 day ago

    It’s not free; doing so provides Anthropic with free access to training data for its models.

    • DrCake@lemmy.world
      link
      fedilink
      English
      arrow-up
      52
      ·
      1 day ago

      I think it’s safe to assume that any public code on the internet is already in their training dataset.

      At this point anything that is public in general, probably all the posts in the “fediverse” have been taken already

  • NoLemurs@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    “The outputs of this opt-in vulnerability scanner will be fully model-generated, without human review or triage,” Anthropic explained. “This will enable faster and more frequent scanning, but means that it is possible reports will be incorrect or invalid.”

    When I saw the headline, I was wondering about this specifically. This may make this service not super useful.

    My experience with AI security reviews is that they’re fantastic at finding faults, but they always find a list of things to complain about. If there are no real/serious faults they’ll start finding things that kind of have the same shape as a security issue, but really aren’t if you dig into them. I’ve regularly had an LLM generate a list of 10-15 issues ranging in severity from “nits” to “critical” where none of them were actual issues.

    Periodic reviews seem like they could get annoying really quickly, becoming more of a maintenance burden than a help.

  • CosmoNova@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    9
    ·
    1 day ago

    It‘s pointless. The pace at which games are decompiled with AI in the modding community tells me that each and every software will be figured out and broken into within a few years or even months. The digital world will be turned upside down. All data could be leaked, entire hedge funds and banks could get wiped with a mouse click and governments could be toppled over night when pension funds of millions suddenly disappear. The AI ouroboros is a vortex that could swallow the entire internet including everything we put in it. Moving fast and breaking things may just break our way of life forever.