On 9/11/26 06:13, Martin Hecht wrote:
Our society strongly depends on connected IT systems comprising our
infrastructure nowadays. Now, these powerful algorithms are able to
find tons of vulnerabilities in software, and they are acting on the
same public internet to which many critical systems are connected.
I'm concerned if we (the humanity) manage to close all those
vulnerabilities before these algorithms take over essential parts of
our infrastructure, or if we find ways to really contain the
algorithms reliably (which seems to be close to impossible, given the
fact that there are also bad actors around). Sorry for being slightly
off-topic, but I believe protecting critical IT systems as good as we
can will soon become more important than ever before.
I agree that protecting critical IT systems is important. But I think
that's *always* been important. We should be protecting *all* IT
systems, too. Way too many have thought "I won't get attacked" and then
get successfully attacked.
Over the next few years AI-enabled attacks will be painful for many. AI
makes attacks much cheaper, so attacks will greatly proliferate.
However, AI also makes finding & fixing the vulnerabilities cheaper.
Defenders will *NOT* be able to claim "I won't be attacked" (they
already are), so they'll need to seriously find & fix vulnerabilitie.
It's true that current AI systems aren't good at fixing *complex*
vulnerabilities (1Password found a success rate of only 26.0%), but most
vulnerabilities aren't complex, and humans can step in to fix complex
vulnerabilities once they are *known* about.
Beyond these next few years, I think we're going to see systems become
*dramatically* more secure. But it's going to be a rocky few years
getting there.
The "rocky time" can easily be prepared for, though. I encourage
everyone to do the following, assisted by AI:
1. Find & fix vulnerabilities.
2. Speed component update response. I argue this further here:
https://www.linkedin.com/pulse/accelerate-deployment-vulnerability-tsunami-david-a-wheeler-eapge/
3. Harden systems so even break-ins will be less effective.
I'd encourage others to do the same. The "vulnpocalypse" is starting.
Like many storms, if you're ready, it will be far less damaging. I look
forward to the end-state: WAY more secure software.
--- David A. Wheeler