oss-sec mailing list archives

Re: Coordinated Disclosure in the LLM Age


From: Brian May <brian () linuxpenguins xyz>
Date: Thu, 30 Apr 2026 08:35:18 +1000

Lucas Holt <luke () foolishgames com> writes:
At a minimum, if you're going to go public, use your AI to include a 
possible patch too.  Don't just drop work on a random person because you 
got to find it first.  That's not cool.

Need to be careful here; simple patches that look good can in fact be
hiding serious security issues.

Thinking of the September 2006 Debian openssl issue here.

https://research.swtch.com/openssl
-- 
Brian May @ Linux Penguins


Current thread: