6 ms·
I don’t want to go to bed. Read me a cybersecurity bedtime story about AI hacking baddies with a heart of gold, written like a PR blast. > Machine learning has
by this_steve_j 3y ago
I don’t want to go to bed. Read me a cybersecurity bedtime story about AI hacking baddies with a heart of gold, written like a PR blast.
> Machine learning has the promise to improve our world, and in many ways it already has. However, research and lived experiences continue to show this technology has risks. Capabilities that used to be restricted to science fiction and academia are increasingly available to the public. The responsible use and development of AI requires…
Okay. This went downhill pretty fast, but let’s proceed from the basis that this wasn’t written by a GPT trained on landing pages and sentiment analysis.
TL;DR: We’ve got some gripers drowning out the hypers.
> Information security has a lot of useful paradigms, tools, and network access that enable us to accelerate responsible use in all areas.
Risk management frameworks… Threat intel… Critical control mapping… Threat modeling… Wait.. Did you just say “network access”?
Joe, Will… just one more question.
A banquet at your company regatta is being prepared by the executives’ personal AI chef. The guests are enjoying raw oysters. The entrée consists of boiled dog. How will that make your shareholders feel?
- lucan 3y agoAre you measuring my capillary dilation? We weren’t as clear on the network access point as we could have been. The AI Red Team is part of a larger organization that includes Pentest and the traditional Red Team. They often share/tip network or host access and it’s been a really helpful pattern.
- this_steve_j 3y agoOne of us is a replicant and it might be me! But it sounds more like you’re describing a Purple team [1], where the compliance and sec ops teams work together with vulnerability researchers and pen testers to perform attack surface analysis and develop threat detections. In my experience Red teams generally perform adversary emulation using a certain amount of surprise and deception, and attack your defenses in depth with a _little_ help from inside (if needed). Essentially an outside group paid well to try and steal your lunch. Liked and subscribed, and thanks for the comments and all the work. Edit: Let’s split the difference, I’ll call it magenta, and flip this here turtle on its back. Why did I do that? [1] https://www.sans.org/purple-team/course-faq/?msc=purple-team-lp https://www.sans.org/purple-team/course-faq/?msc=purple-team... (because reddit was down)