top 50 comments

sorted by: hot top controversial new old
[–] 182 points 9 months ago (5 children)

couldn't ai, then also, break code faster than we could fix it ?

  • source
  • hideshow 7 child comments
  • [–] 45 points 9 months ago* (1 child)

    I mean, at a high level it is very much the concept of ICE from Gibson et al back in the day.

    Intrusion Countermeasures Electronics. The idea that you have code that is constantly changing and updating based upon external stimuli. A particularly talented hacker, or AI, can potentially bypass it but it is a very system/mental intensive process and the stronger the ICE, the stronger the tools need to be.

    In the context of AI on both sides? Higher quality models backed by big ass expensive rigs on one side should work for anything short of a state level actor... if your models are good (big ol' "if" that).

    Which then gets into the idea of Black ICE that is actively antagonistic towards those who are detected as attempting to bypass it. In the books it would fry brains. In the modern day it isn't overly dissimilar from how so many VPN controlled IPs are just outright blocked from services and there is always the risk of getting banned because your wifi coffee maker is part of a botnet.

    But it is also not hard to imagine a world where a counter-DDOS or hack is run. Or a message is sent to the guy in the basement of the datacenter to go unplug that rack and provide the contact information of whoever was using it.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 9 months ago (1 child)

    In the context of AI on both sides? Higher quality models backed by big ass expensive rigs on one side should work for anything short of a state level actor… if your models are good (big ol’ β€œif” that).

    Turns out Harlan Ellison was a goddamn prophet when he wrote I Have No Mouth And I Must Scream.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (3 replies)
    [–] 97 points 9 months ago* (5 children)

    Genius strategy:

    • Replace Juniors
    • Old nerds knowing stuff die out
    • Now nobody knows anything about programming and security
    • Everything's now a battle between LLMs
  • source
  • hideshow 9 child comments
  • load more comments (1 reply)
    [–] 71 points 9 months ago (2 children)
  • load more comments (1 reply)
    [–] 62 points 9 months ago

    Execs and managers showing Dunning-Kruger in full effect.

  • source
  • [–] 46 points 9 months ago (1 child)

    At this point, they're just rage baiting and saying random shit to squeeze that bubble before it bursts.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 43 points 9 months ago

    AI is opening so many security HOLES. Its not solving shit. AI browsers and MCP connectors are wild west security nightmares. And that's before you even trust any code these things write.

  • source
  • [–] 35 points 9 months ago

    As usual, the biggest advocates for AI are the ones who understand its limitations the least.

  • source
  • [–] 32 points 9 months ago* (2 children)

    I have worked as a pentester and eventually a Red Team lead before leaving foe gamedev, and oh god this is so horrifiying to read.

    The state of the industry was alredy extremely depressing, which is why I left. Even without all of this AI craze, the fact that I was able to get from a junior to Red Team Lead, in a corporation with hundreds of employees, in a span of 4 years is already fucked up, solely because Red Teaming was starting to be a buzz word, and I had passion for the field and for Shadowrun while also being good at presentations that customers liked.

    When I got into the team, the "inhouse custom malware" was a web server with a script that pools it for commands to run with cmd.exe. It had a pretty involved custom obfuscation, but it took me lile two engagements and the guy responsible for it to leave before I even (during my own research) found out that WinAPI is a thing, and that you actually should run stuff from memory and why. And I was just a junior at the time, and this "revelation" got me eventually a unofficial RT Lead position, with 2 MDs per month for learning and internal development, rest had to be on engagements.

    And even then, we were able to do kind of OK in engagements, because the customers didn't know and also didn't care. I was always able to come up with "lessons learned", and we always found out some glaring sec policy issues, even with limited tools, but the thing is - they still did not care. We reported something, and two years ago they still had the same bruteforcable kerberos tickets. It already felt like the industry is just a scam done for appearances, and if it's now just AIs talking to the AIs then, well, I don't think much would change.

    But it sucks. I love offensive security, it was really interresting few years of my carreer, but ot was so sad to do, if you wanted to do it well :(

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 32 points 9 months ago
    [–] 31 points 9 months ago (6 children)

    I tried using AI in my rust project and gave up on letting it write code. It does quite alright in python, but rust is still too niche for it. Imagine trying to write zig or Haskell, it would make a terrible mess of it.

    Security is an afterthought in 99.99% of code. AI barely has anything to learn from.

  • source
  • hideshow 8 child comments
  • [–] 35 points 9 months ago (2 children)

    If you're using Hannah Montana Linux you can just open a terminal and type "write me ____ in the language ____" and the Hannai Montanai will produce perfectly working code every time.

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
  • load more comments (4 replies)
    [–] 30 points 9 months ago (4 children)

    SchrΓΆdinger's AI: It's so smart it can build perfect security, but it's too dumb to figure out how to break it.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 29 points 9 months ago (1 child)

    Ha ha ha ha ha!

    Oh wait, you're serious. Let me laugh even harder.

    HA HA HA HA HA!

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [+] 20 points 9 months ago* (last edited 4 months ago)
    [–] 20 points 9 months ago

    Not with any of the current models, none of them are concerned with security or scaling.

  • source
  • [–] 16 points 9 months ago

    Ah yes, I'm sure AI just patched that software so that other AI could use that patched software and make things so much more secure. What a brilliant idea from an Ex-CISA head.

  • source
  • [–] 16 points 9 months ago (3 children)

    It takes a good person with a gun AI to stop a bad person with a gun AI.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 16 points 9 months ago (1 child)

    Because then Security would be non-existent.

  • source
  • hideshow 2 child comments
  • [–] 15 points 9 months ago

    ahahahaha

    Oh, you're serious. Let me laugh even harder.

    AHAHAHAHA

  • source
  • [–] 13 points 9 months ago

    Fix what code? The code it broke or wrote like shit in the first place?

  • source
  • [–] 13 points 9 months ago

    Clearly she's never seen AI code.

  • source
  • [–] 13 points 9 months ago

    Is that why she's Ex-CISA? 🀣

  • source
  • [–] 13 points 9 months ago

    One of the most idiotic takes I've read in a long time

  • source
  • [–] 13 points 9 months ago

    Ron Howard narrator: Actually, they would need more.

  • source
  • [+] 10 points 9 months ago* (last edited 2 months ago)
    [–] 9 points 9 months ago (1 child)
    load more comments (1 reply)
    [–] 8 points 9 months ago (2 children)

    Except that most risks are from bad leadership decisions. Exhibit A: patches exist for so many vulnerabilities that remain unpatched because of bad business decisions.

    I think in a theoretical sense, she is correct. However, in practice things are much different.

  • source
  • hideshow 3 child comments
  • [–] 10 points 9 months ago (1 child)

    My old job had so many unpatched servers, mostly Linux ones. Because of the general idea that "Linux is safe anyway". And because of how Windows updates would often break critical infrastructure, so they were staggered and phased.

    But we've seen plenty of infected Linux packages since, so it's almost a given there's huge open holes in that security somewhere.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • load more comments (1 reply)
    [–] 7 points 9 months ago (1 child)

    If an AI can be used for automatic scalable defense, it can also be used offensively. It'll just be another digital arms race between blackhats and everyone else.

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 6 points 9 months ago

    The look on her face in the thumbnail matches the title perfectly.

  • source
  • [–] 6 points 9 months ago (1 child)

    I just asked an AI what the minimum wage was in 2003 in the UK and it told me that it was Β£4.50 and that on a 40 hour work week, that came out to 18k a year... But sure, trust it to write and fix code...

  • source
  • hideshow 1 child comment
  • load more comments (1 reply)
    [–] 6 points 9 months ago

    Who is paying her?

  • source
  • load more comments
    view more: next β€Ί