Post B65xZxtlD2gCCMFf84 by shadowdancer@mstdn.social
(DIR) More posts by shadowdancer@mstdn.social
(DIR) Post #B65xZxN9AIakZCzcIK by rysiek@mstdn.social
0 likes, 0 repeats
Will the rate of vulns being found "thanks to AI" be higher than the rate of vulns being introduced by vibe-coding shit?No. It will not. You know it as well as I do.Why? Because the incentives have not changed.What remains heavily incentivised is excreting more code and slapping more and more random features, not quality control and robustness.I've linked this before, but it remains so very on-topic and on-point, so here it is again:https://freakonometrics.hypotheses.org/89367#InfoSec #AI #Mythos
(DIR) Post #B65xZxtlD2gCCMFf84 by shadowdancer@mstdn.social
0 likes, 0 repeats
@rysiekOkay, but it'll sure get interesting when AI starts to look for vulns in all that vibe coded crap.
(DIR) Post #B65xZyB8ASZf4ENXCi by rysiek@mstdn.social
0 likes, 0 repeats
@shadowdancer thing is, nobody is going to be fixing them
(DIR) Post #B65xZyJzdVfBViWc1A by shadowdancer@mstdn.social
0 likes, 1 repeats
@rysiekYeah, well no human at least. AI generated fixes on the other hand... 😉Oh boy, we're heading straight to hell.
(DIR) Post #B65xZyYsk9ZaFtUVE0 by rysiek@mstdn.social
0 likes, 0 repeats
Oh and a reminder that the whole "wow Mythos is such much special at finding vulns amaze" shtick is largely just Anthropic's hype.https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier> We tested Anthropic Mythos's showcase vulnerabilities on small, cheap, open-weights models. They recovered much of the same analysis. AI cybersecurity capability is very jagged: it doesn't scale smoothly with model size, and the moat is the system into which deep security expertise is built, not the model itself. #AI #Mythos #InfoSec