> In case you have forgotten, this discussion *started* with a maintainer 
suspecting that LLM-detected vulnerabilities


I replied to this thread because I reported a dozen issues to OpenStack, which 
the OP is a VMT lead for.  He has yet to claim any of the issues I've reported 
are invalid or duplicate. I believe people are overclaiming this.  I also 
believe duplicates, when found, are a good sign for prioritization.    



I was also disappointed to see a serious security bug I reported on OpenStack 
pushed to public.  If I had know that would happen, I wouldn't have reported 
it.  I don't want to be a part of what I feel to be negligent and 
unprofessional activities.  My goal was not credit, but rather to improve the 
security of OpenStack as I wanted to see it as a solution to sovereign cloud.  
Pushing it to public undermined that.

 
Using LLMs, I am farming careless engineers who reveal security sensitive info 
in bug reports, commit comments, and code reviews.  This 'public' attitude is 
just making it much easier for me to do so.


Security sensitive communication should remain in a restricted discussion area 
and teams should be using LLMs to analyze it for further issues to close.




-- Jacob
Confidential communication. No warranties or commitments unless in a signed 
agreement. If received in error, notify sender and delete. Unauthorized use 
prohibited.



Reply via email to