Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CAKtE3zecEsfMQKjnAcdVwUCTfXKOZ4_UXV_KvgA=ZL6PG3jZ_A@mail.gmail.com>
Date: Tue, 20 Jun 2023 17:06:15 -0500
From: Travis Biehn <tbiehn@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: The AI chatgpt writes insecure code

On Tue, Jun 20, 2023 at 16:47 Alan Coopersmith <alan.coopersmith@...cle.com>
wrote:

> On 6/20/23 09:22, Georgi Guninski wrote:
> > chatgpt is an AI language model and it can write code.
> >
> > As expected, it was trained on insecure code and it writes
> > insecure code.
>
> Also as previously reported:
>
> https://www.theregister.com/2023/04/21/chatgpt_insecure_code/
> https://arxiv.org/abs/2304.09655
>
> --
>          -Alan Coopersmith-                 alan.coopersmith@...cle.com
>           Oracle Solaris Engineering - https://blogs.oracle.com/solaris
>
>
ChatGPT will indeed generate ‘average’ quality code. That’s absolutely
ending up on GitHub and in dependency repositories. IMO, the situation
hasn’t changed for us, more code than ever before growing super-linearly
and tools that produce a bunch of noise.
On the other side - future coding buddies will be able to use Retrieval
Augmented Generation for policy following to generate high quality code
with more reliability.

-Travis

-- 
Twitter <https://twitter.com/tbiehn> | LinkedIn
<http://www.linkedin.com/in/travisbiehn> | GitHub <http://github.com/tbiehn>
| TravisBiehn.com <http://www.travisbiehn.com>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.