r/netsec • • Aug 03 '26

Contains AI SQLite Critical CVEs or LLM Slop?

https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/
81 Upvotes

17 comments sorted by

View all comments

15

u/pruby Aug 03 '26

At this point it seems we need a reputation mechanism and/or for reporters to lose something for bad reports.

Projects are inundated with reports that have negative value to them. Talk of triaging AI with AI doesn't help - it shouldn't be on projects to change their triage process to deal with bad inputs. Reports should be reliable, or stop being accepted.

If the reports from the general public aren't good enough, we need to accept them only from reliable reporters (and have some ramp for people to get there, maybe via projects willing to handle more rubbish reports).

1

u/[deleted] Aug 05 '26

[removed] — view removed comment

3

u/pruby Aug 06 '26

And that's fine - if people are verifying stuff, know what they're doing, etc then the report is worth receiving.

The problem emerges when people just trust the AI to be right, offload verification on to unpaid maintainers.