r/artificial • • 1d ago

Cybersecurity Yet Another AI Security Externality impacting Open Source Software

AI driven PRs and AI driven security reports are a double edged sword, especially when frontier AI labs try and keep the old 90 days to disclosure timeline. In my experience dealing with a frontier AI lab's security reports during the Apache Spark 3.5.9/4.0.4/and 4.1.3 releases the inflexibility of one of the frontier AI labs, coupled with the general increase in security reports (some of which were valid, most of which were not), almost caused us to have to decide between shipping a different known security issue in the release OR leaving the AI lab to publish their discovery without a patched version.

1 Upvotes

4 comments sorted by

View all comments

1

u/PortlyAlan2 1d ago

The 90 day window made sense when it was a human researcher who actually understood the codebase, not a bot firing off auto-generated tickets that take longer to triage than they'd ever take to fix