I am 4ra1n, an independent security researcher
Currently unaffiliated with any company or organization
我是 4ra1n,独立安全研究员,目前无工作
My CVE and Acknowledgments: SECURITY-en.md
我获得的 CVE 和致谢信息记录:SECURITY-zh.md
Reported and had multiple RCE vulnerabilities confirmed in well-known products through Bug Bounty and SRC programs
在 Bug Bounty 和 SRC 提交过多个知名产品 RCE 漏洞并确认
I believe that before the AI era, security research and code auditing primarily reflected a researcher's technical expertise. Discovering vulnerabilities required deep knowledge of software internals, extensive manual analysis, and significant experience. With the rise of large language models and AI agents, the barrier to vulnerability discovery has been significantly lowered. In many cases, the capability of the underlying model contributes as much as, or even more than, the individual researcher's own expertise. As a result, vulnerability counts alone have become a less reliable indicator of technical ability than they once were.
我认为在 AI 时代之前,安全研究和代码审计主要反映的是研究者个人的技术水平。发现漏洞需要深入了解软件内部实现、进行大量的人工分析,并积累丰富的经验。随着大语言模型和 AI 智能体的兴起,漏洞发现的门槛被大幅降低。在很多情况下,底层模型的能力与研究者的个人能力相比,贡献相当甚至更多。因此,与过去相比,漏洞数量作为衡量技术能力的指标已不再那么可靠。