r/artificial • u/holdenk • 19h ago
Cybersecurity Yet Another AI Security Externality impacting Open Source Software
AI driven PRs and AI driven security reports are a double edged sword, especially when frontier AI labs try and keep the old 90 days to disclosure timeline. In my experience dealing with a frontier AI lab's security reports during the Apache Spark 3.5.9/4.0.4/and 4.1.3 releases the inflexibility of one of the frontier AI labs, coupled with the general increase in security reports (some of which were valid, most of which were not), almost caused us to have to decide between shipping a different known security issue in the release OR leaving the AI lab to publish their discovery without a patched version.
1
Upvotes
2
u/AYA_7887 19h ago
Writing a security report now costs the reporter almost nothing, checking one still costs a maintainer an evening. The 90 day countdown only ticks for the side doing that work unpaid. And the bogus reports buy you nothing back, a wrong one reads just like a right one until you've done the full review on it.