this post was submitted on 02 Jun 2026
172 points (99.4% liked)

Technology

85059 readers
4052 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Rothe@piefed.social 38 points 9 hours ago (3 children)

LLMs are such a huge security liability, and noone seems to know how to properly secure them, probably because it is impossible. Yet very soon they will be incorporated in everything. Jensen Huang wants to sell you a box with an LLM controlling every single thing in your house.

[–] BrianTheeBiscuiteer@lemmy.world 11 points 5 hours ago

Even a human support tech shouldn't have that much power. That should be a request to a completely different team that gets hard off of telling people "No".

[–] kryptonianCodeMonkey@lemmy.world 5 points 5 hours ago (1 children)

It's not impossible. It's actually pretty simple. You just don't give it access to credentials or resources or sensitive information of any kind. Does that make them basically useless? Yep. But then you don't create massive security risks and legal liabilities with gross negligence either, so... gotta weigh those things against each other.

[–] naught@sh.itjust.works 1 points 4 hours ago (1 children)

You can do this and still use it to generate insecure code or even malicious code! Humans suck at reviewing

[–] boonhet@sopuli.xyz 1 points 4 hours ago

Unironically not a bad idea to have LLMs review eachothers code before committing. And then human review the PR.

[–] one_old_coder@piefed.social 1 points 3 hours ago

noone seems to know how to properly secure them, probably because it is impossible

Most likely because all the AI engineers are idiots without any coding experience to begin with.