oss-sec mailing list archives

Re: Coordinated Disclosure in the LLM Age


From: ROI AI <sales () roiai ca>
Date: Sun, 24 May 2026 04:58:26 -0700

In case you have forgotten, this discussion *started* with a maintainer 
suspecting that LLM-detected vulnerabilities


I replied to this thread because I reported a dozen issues to OpenStack, which the OP is a VMT lead for.  He has yet to 
claim any of the issues I've reported are invalid or duplicate. I believe people are overclaiming this.  I also believe 
duplicates, when found, are a good sign for prioritization.    



I was also disappointed to see a serious security bug I reported on OpenStack pushed to public.  If I had know that 
would happen, I wouldn't have reported it.  I don't want to be a part of what I feel to be negligent and unprofessional 
activities.  My goal was not credit, but rather to improve the security of OpenStack as I wanted to see it as a 
solution to sovereign cloud.  Pushing it to public undermined that.

 
Using LLMs, I am farming careless engineers who reveal security sensitive info in bug reports, commit comments, and 
code reviews.  This 'public' attitude is just making it much easier for me to do so.


Security sensitive communication should remain in a restricted discussion area and teams should be using LLMs to 
analyze it for further issues to close.




-- Jacob
Confidential communication. No warranties or commitments unless in a signed agreement. If received in error, notify 
sender and delete. Unauthorized use prohibited.




Current thread: