A small test finds AI coding helpers write login pages that are easy to break intoیک آزمایش کوچک نشان می‌دهد دستیارهای کدنویسی هوش مصنوعی صفحات login می‌نویسند که نفوذ به آن‌ها آسان است

Five popular AI coding helpers built login systems with real security holes when asked plainly. Researchers attacked the code and got in; the holes shrank only after the tools were given official security rules and told to recheck their work.5 دستیار محبوب کدنویسی هوش مصنوعی، وقتی به‌سادگی از آن‌ها خواسته شد، سیستم‌های login با حفره‌های امنیتی واقعی ساختند. پژوهشگران به این کدها حمله کردند و توانستند نفوذ کنند؛ این حفره‌ها فقط زمانی کوچک‌تر شدند که به ابزارها قوانین رسمی امنیتی داده شد و از آن‌ها خواسته شد کار خود را دوباره بررسی کنند.

ترجمهٔ ماشینی است؛ برای دقت به متن اصلی انگلیسی مراجعه کنید.

Why it matters

A lot of software today is written with help from AI tools. A login page is where your password and your account live, so mistakes there are expensive. This test suggests those tools aim first at making something that works, not something safe, unless you ask them clearly. It was a small test, so treat it as a warning sign rather than a measurement: if you use an AI tool to write login code, check the result yourself and ask the tool to review its own work against real security rules.بخش زیادی از نرم‌افزارهای امروزی با کمک ابزارهای هوش مصنوعی نوشته می‌شوند. صفحه login جایی است که رمز عبور و حساب کاربری شما در آن قرار دارد، پس اشتباه در آنجا هزینه‌بر است. این آزمایش نشان می‌دهد این ابزارها، مگر آنکه به‌روشنی از آن‌ها خواسته شود، ابتدا به‌دنبال ساختن چیزی هستند که کار کند، نه چیزی که امن باشد. این یک آزمایش کوچک بود، پس باید آن را بیشتر یک هشدار در نظر گرفت تا یک اندازه‌گیری دقیق: اگر از ابزار هوش مصنوعی برای نوشتن کد login استفاده می‌کنید، نتیجه را خودتان بررسی کنید و از ابزار بخواهید کار خودش را در برابر قوانین واقعی امنیتی مرور کند.

Who's behind it: Ishpuneet Singh, Shreyas Mahajan, Gurjot Singh and Maninder Singh.

Summary by the Lemma AI · how we grade

Read the original paper (arxiv.org)