Former Go Security team lead Filippo Valsorda argues that the traditional norms around vulnerability reports — responsiveness, attribution, and coordinated disclosure — are becoming obsolete. The core premise: LLMs can now perform security research as well as most human researchers, making the 'scarce insight' and confidentiality advantages of responsible disclosure far less meaningful. Attackers have the same LLM access as defenders, so embargoes matter less. The new focus should be on triage, rapid remediation, and prevention, including running LLM-based analysis in CI pipelines. He references curl's recent suspension of its vulnerability reporting channels as a sign of the times, even if it feels uncomfortable.

6m read timeFrom words.filippo.io
Post cover image
32K Impressions