3 ms·
Assuming an equal level of impact per token spent, the scales have tipped in favour of the attacker. White hats are constrained by needing to pay for their own
by bigfatkitten 9d ago
Assuming an equal level of impact per token spent, the scales have tipped in favour of the attacker.
White hats are constrained by needing to pay for their own tokens, only using (expensive) vendors who meet governance and risk requirements etc. Black hats are free to take over accounts and steal services from wherever they can.
- brookst 9d agoFor white hats, how has the cost of a thorough security review changed since, say, five years ago?
- bigfatkitten 8d agoThe price has gone up if you’re getting AI to do it. In terms of finding low hanging fruit, reasonably good code scanning tools have been around for a while. The thing that’s changed for attackers is speed. The things that got you hacked yesterday are the same things getting you hacked today. Finding and weaponising things like memory corruption bugs required an enormous amount of relatively hard to find skill, and considerable time. An idiot can now throw tokens at the problem and have something they can reliably use within minutes or hours.