Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right, but if you can embed bad packages in LLMs, you can surely embed any kind of vulnerability imaginable.




I'm not thinking about deliberately embedded vulnerabilities, just accidental/emergent ones. The modern equivalent of devs copy-pasting stackoverflow answers that happen to contain SQL injection vulns.

Does the distinction make any difference?

Yes, you'd take different actions to avoid each.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: