There is virtually **no** AI slop security reports anymore submitted about #curl. They don't seem to happen any longer.

Almost everyone still uses AI though.

@bagder is that because you quit h1? or people finally gave up trying?
@Viss we went back to h1. I think primarily because the AI tooling got a lot better.
@bagder oh! interesting! did h1 implement any guard rails at all since or did they mention anything to you? i wager a torrrent of negative press about how they just let slop reports through probably put a dent in their revenue stream
@Viss they've done some minor tweaks, but I can't see how anything they've done is any factor here
@bagder iiiiiinteresting!

@Viss @bagder

LLMs are shockingly good at finding security vulnerabilities now

The reports they write are a bit meh, and coordination is still hard

@joshbressers @bagder i have a buuuuuunch of research in working on, and the title of the talk is 'claude is your insider threat now'. fingers crossed securityfest and sec-t let me in :D

@Viss @bagder

I will note though, I haven't seen the exploit prices come down yet

It's possible the markets haven't caught up, or it's bad at finding the really juicy stuff

I admit I haven't seen it find anything SUPER impressive yet

@joshbressers @bagder llms are at 'bad adhd intern levels now', it feels like, versus hallucinatory and outright intentional disinformation
@joshbressers @Viss @bagder It‘s a lot about edge cases in API use and things involving ‚malicious servers‘ - which…yeah, it‘s security, but…
@joshbressers @Viss @bagder LLMs have been used to find security issues with a lot of success, though usually they're used more like static analyzers: https://daniel.haxx.se/blog/2025/10/10/a-new-breed-of-analyzers/
A new breed of analyzers

(See how I cleverly did not mention AI in the title!) You know we have seen more than our fair share of slop reports sent to the curl project so it seems only fair that I also write something about the state of AI when we get to enjoy some positive aspects of this technology. … Continue reading A new breed of analyzers →

daniel.haxx.se
@mahid @joshbressers @bagder even still, if the human driving the thing around is a ponce and doesnt know shit, thats how you get slop into security reports. llms will happily give you "code that compiles", but is thousands of times less efficient than human code, and often made of elegantly construed bullshit - so unless theres an expert at the helm, shit goes bad fast.