2061, mark the date
HN user
narginal
I have just seen too much infrastructure set up to 'find bugs,' effectively sitting and doing nothing- either the wrong thing gets audited, or tons of compute gets thrown at a code base and nobody ever checks in on or verifies.
This seems like a human/structural issue that an AI won't actually fix - attackers/defenders alike will gain access to the same models, feels a little bit like we are back to square one
Just like how fuzzers will find all the bugs, right? Right?? There's definitely infrastructure at these big companies that isn't sitting in a while loop 'fuzzing' right? Why is it news that vulnerability research will continue to get harder, exactly? It has always been this way, exploits will get more expensive, and the best researchers will continue with whatever tools they find useful.
Big mistake. Having previously worked at small security startups that would actually like to participate in these activities, the individuals at these companies that are actually capable enough to pull this off are led by management, CEOs, and PE firms that have no idea what they're doing. Good luck holding any of these people accountable when something goes wrong. They only want that sweet government contract money. There is a reason I no longer work with these small security startups, and it stems from lack of leadership from the top down, and that these companies largely don't actually want to do good. The good people tend to leave.
tldr: even if this was a good idea, you will end up with entities that are allowed to conduct cyber operations, but otherwise don't have the ability to conduct them skillfully. When things go wrong, there will be no accountability.