3 ms·
This is straightforwardly incorrect. Of course it's not binary. AI costs money to run, and it takes time. Even if you say that AI is 10x as efficient at finding
by insanitybit 2mo ago
This is straightforwardly incorrect. Of course it's not binary. AI costs money to run, and it takes time. Even if you say that AI is 10x as efficient at finding 0days, that just means that a $1M dollar exploit now costs $100K. Even if you say it's 100x as efficient, that's $10K. You can easily combine security technologies such that cost of exploitation is still in the >$1M range.
This is obvious. AI doesn't drive the cost to zero and exploitation has always been about cost. Tokens cost money, not everyone has $10M to burn on chaining bespoke 0days.
Consider that if the cost of exploitation was truly 0, then the cost of perfect software would be 0 because you could exhaust an infinite search space of vulnerabilities for 0 cost. Your conclusion could never follow from your premise.
- bottlepalm 2mo agoYou have some weird way of thinking that offense/defense is like this fixed cost thing. It's a lottery ticket, and your costs estimate tries to quantify that. The thing is when AI goes to hack 'all the things' it only needs to pick the weakest link in the stack and your house of cards falls down. The other flaw in your plan is that people make mistakes, a lot of them, all time, constantly, and saying I spend $x on security won't save you. AI already hacked Hugging Face with brand new zero days like it was nothing. The real bad actors - malicious AI will find the one flaw, on that one server, in the corner you never thought about and turn your network inside out with it faster than it takes you to have the standup meeting about the weird anomaly detected while you all were at lunch.
- insanitybit 2mo agoYou're just stating things that are obviously wrong. It's a lottery ticket? So... exploitation is no better than random? > The thing is when AI goes to hack 'all the things' it only needs to pick the weakest link in the stack and your house of cards falls down Yes, but you can... mitigate the risks? I've explained this. > The other flaw in your plan is that people make mistakes, a lot of them, all time Yes, you mitigate the risks. That's why you layer things. > I spend $x on security won't save you No one is saying this. > AI already hacked Hugging Face with brand new zero days like it was nothing. No, it cost OpenAI money, and those zero days are unsurprising and probably are like ~O(10K) at human level. > The real bad actors - malicious AI will find the one flaw, on that one server, in the corner you never thought about and turn your network inside out with it faster than it takes you to have the standup meeting about the weird anomaly detected while you all were at lunch. Science fiction and not supported. The vulnerabilities found by AI are not surprising in the slightest. I've made my point abundantly clear.
- bottlepalm 2mo ago> Science fiction Maybe a month ago it was science fiction, hugging face makes it fact. Time to move your goal posts again.
- insanitybit 2mo agoI've explained myself gratuitously at this point.