back to article What do Tensor Flow, Caffe and Torch have in common? Open CVEs

Dabblers with prominent artificial intelligence tools have been warned and/or reminded to check their dependencies because some have open vulnerabilities. That warning came from Qixue Xiao and Deyue Zhang (from Quihoo's 360 Security Research Lab), Kang Li (University of Georgia) and Weilin Xu (University of Virginia), who …

  1. Korev Silver badge
    Joke

    OpenCV

    Maybe the developer should get updating their openCVs...

  2. richard nicholson

    "Sooner or later, dependency hell creates a problem for everyone"

    Not really.

    Real software engineers use OSGi™.

    Dependency Hell is tamed -- and as an aside the most power Microservice Architecture known to man.

  3. IneptAdept

    Dependable mistakes rise again

    You can always depend on people to make the same mistake again and again and again

    Leftpad anyone ?

    1. Yet Another Anonymous coward Silver badge

      Re: Dependable mistakes rise again

      Is it a mistake?

      OpenCV is an image processing package. It works well on tiny hardware, or doing intensive tasks on big hardware. Do I really want its speed halved to protect every call from malicous arguments and buffer overflows?

      If you are a public internet facing services at a bank then you want security to be the main priority, but if you are an AI research project inside a private server I want a library to be fast and efficient. In the same way that I want my travel laptop to be light and fast, not to be waterproof, radiation hardened, explosive atmosphere safe and rated for Ptarmigan security

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like