AI generated code creates a new security attack vector

Adam Crockett 🌀 - Dec 31 '22 - - Dev Community

My new best friend ChatGPT has so far helped me to write a blender plug-in even when I have no python experience and I know that it works, but I can’t test it or understand if any of this code is secure in terms of python idiom.

So there in lies the “why” we need experienced people to operate factory machines, it’s one thing to spew out code but you still need experience to quality control and sanity check, something AI still has to work hard on.

However here’s the issue, I’m happy to release my blender plugin without that experience, for all I know I have to trust this AI is not injecting malicious code unintentionally and that’s interesting isn’t it.

There are no human errors in AI because there are no humans but it may still be possible for a bad actor to inject nasty bits of code that might not be checked to the same degree… this code suffers from the aging product problem, I didn’t write it but I must trust my peers and that’s the trust that could be exploited and it’s new and kind of scary 😦

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Terabox Video Player