Whonix AI security usage?

Yes, quite heavily. Enough so that at least one person thought (incorrectly, thankfully) that we had become a vibecoded project:

We have a pretty sophisticated set of both human and automated safeguards so that we can use AI to find security issues and harden our code while avoiding the risks that usually come with vibecoding. (We’re quite enthusiastic about AI’s capabilities, but also treat it as an external contributor, meaning we generally assume its output is vulnerable and/or malicious until proven otherwise.)

We use the best we have access to. At the moment I believe that’s a slightly older version of Claude Opus (we tried newer versions but they didn’t give us as good of results).

I am not aware of the project having done this. I doubt we’d be able to get access to those kinds of tools due to our somewhat niche status. That being said, new models are coming out that are very good at finding vulns while being not-so-good at exploiting them, and those are becoming easier to access, so hopefully we’ll adopt them once we can get to them.

That’s an overview of how contributors (maintainers included) are to use AI in their work. It’s basically “you don’t have to use AI, but if you do, here’s what we expect from you.”

1 Like