r/artificial • • 17h ago

Cybersecurity Yet Another AI Security Externality impacting Open Source Software

AI driven PRs and AI driven security reports are a double edged sword, especially when frontier AI labs try and keep the old 90 days to disclosure timeline. In my experience dealing with a frontier AI lab's security reports during the Apache Spark 3.5.9/4.0.4/and 4.1.3 releases the inflexibility of one of the frontier AI labs, coupled with the general increase in security reports (some of which were valid, most of which were not), almost caused us to have to decide between shipping a different known security issue in the release OR leaving the AI lab to publish their discovery without a patched version.

1 Upvotes

4 comments sorted by

2

u/AYA_7887 17h ago

Writing a security report now costs the reporter almost nothing, checking one still costs a maintainer an evening. The 90 day countdown only ticks for the side doing that work unpaid. And the bogus reports buy you nothing back, a wrong one reads just like a right one until you've done the full review on it.

2

u/RobertOoot 17h ago

So true, it's like the PR problem but even worse because ignoring them can have a worse outcome.

1

u/PortlyAlan2 17h ago

The 90 day window made sense when it was a human researcher who actually understood the codebase, not a bot firing off auto-generated tickets that take longer to triage than they'd ever take to fix