pull down to refresh

I have actually audited a grand total of zero projects. Not even pointed an LLM at them and told it to look for vulnerabilities or backdoors.

My excuse used to be that I wasn't a developer, so how was I suppose to audit the codebase of something like boltz or phoenix?

Instead, I "verified" by looking at what people I assumed were capable of such audits said. Notably, I did not check to see if they actually did audit any code.

This doesn't sound very cypherpunk does it?

Do you think there is less trust involved if a non-dev uses an LLM to perform some basic probing of the software they use or is that mostly an illusory sort of security?

(I'd be curious to read your piece about this if you care to link)