9 ms·
I don't think that's relevant. You can still find security issues in software nobody uses. The question is a matter of impact because of how used the software
by andrewjf 4mo ago
I don't think that's relevant. You can still find security issues in software nobody uses.
The question is a matter of impact because of how used the software is.
- VorpalWay 4mo agoWay fewer people are going to look at obscure things, so a lower percentage of issues will likely have been found. There is less fame and fotune in spending security research time on obscure software. Most small libraries won't be covered by any bug bounty programs either for example.
- andrewjf 4mo agoYou don't need other people anymore to find security issues, you can do it yourself with AI.
- rhdnfjtkfmf 4mo agoEven accepting the premise, is it not immediately obvious to you that folks will be spending more money and effort aiming AI at higher-impact targets? This isn’t all-or-nothing.