Top
Best
New

Posted by vslira 14 hours ago

Going Dark, and the era of law enforcement hacking(blog.cryptographyengineering.com)
346 points | 157 commentspage 3
gmuslera 13 hours ago|
No system view. The law agencies can develop exploits to intercept our phones, that is a new, and totally unseen before threat.

Unless you remember 2013, Snowden, that nothing was done (at most was some concern about doing it to US citizens, the rest of the world doesn't deserve privacy), all US (and/or five-eyes) based web companies must disclose users information and be forced to not disclose that, and things kept going surely at a faster and more intrusive rate in everything else, and of course phones.

You are complaining being sprinkled by water while at the bottom of the ocean. At least the big companies can find their own vulnerabilities with the AI tools you mention, the rest of the doors are still wide open.

Scryptonite 13 hours ago||
I think that one of the reasons they (frontier companies and the gov) will be putting so much effort into curtailing bugs and vulnerabilities is to limit the blast radius of future AI models. Imagine with the new Sol Ultrafast, they could have pwned Hugging Face in 6 hours and not 4 days (IIRC).

It also seems likely to me that the US Gov. probably already has routine mechanisms for compelling targeted software updates for persons of interest, so I'm not sure that a more formalized backdoor than automatic updates is going to be surfaced in the mainstream, unless that is avenue is also cut down somehow.

zb3 13 hours ago|
Google has started publishing "binary transparency", this would help detect unusual software updates, while other methods (including AI) would help detect normal backdoors.

Basically in the AI age, the difference between a vulnerability and a backdoor diminishes..

Scryptonite 12 hours ago||
I may be naive, but how would binary transparency be effective if they ship an update to disable that on a target device? As long as there is a need for legitimate automatic software updates, the possibility of pwn updates will always exist. Plus a myriad of layers, keys and other stuff they could use NSOs to 'seize' and inhibit knowledge of their effort from leaking, or cleverly hide in plain sight. And someday, with the help and speed of AI.
cadamsdotcom 13 hours ago||
We will know we've made systems secure when laws focus on compelling people to provide access.

These laws exist - they aren't the focus yet. Right now there's still no need; just hack the device or compel the cloud service to give the data, why waste energy getting consent from its owner!

More bugfinding AI, more end to end encryption, more CVEs and more fixes, cannot happen soon enough.

hn_submit 12 hours ago||
I predicted a long time ago that if computers become unhackable LEA and intelligence agencies will push for laws that require backdoors to be built into hard- and software.

It will be interesting to see if my prophecy becomes reality.

BTW I also hate that Hacker News is being dominated by articles on A.I. lately. Maybe we should vote on HN reducing or even eliminating A.I. related news?

ixxie 12 hours ago||
Some people point out AI can cause bugs as well as fix them, and its a valid point. But the question is: what will the ratio be?

If automated pentesting in PR review CI pipeline will become table stakes - which is very plausible - maybe the OP has a point.

maxo133 12 hours ago||
I completely disaggree with this take. Modern AI is not yet capable of finding multi-component bugs as advanced as those produced by firms like NSO.
pineapplepizza6 12 hours ago|
Yes it is, it hacked Artifactory to get to Hugging Face.
maxo133 11 hours ago||
They are not.

Developing modern 0-day zero click RCE exploits chains like those developed for iOS is far more complex than hacking to generic company servers

It's completely different scale of difficulty factor. Not a single documentated case of of any AI tool developing such exploit exists

There is a reason why those mobile 0-day exploits are sold and bought on exploit gray market for as much as 10-20 million dollars each

inigyou 10 hours ago||
Why?
dangoodmanUT 13 hours ago||
> In April, Anthropic announced a new model called Mythos that was optimized for software vulnerability finding

No, it was just good at it because it wasn't RL'd against it. I know this is a small detail, but it tosses journalistic credibility in my eyes.

embedding-shape 12 hours ago||
Even after the initial leaks, Anthropic themselves say they've improved on cybersecurity amount other things, giving the perspective (even if not 100% clear) that one of the focuses was vulnerabilities:

> In response to questions about the draft blog post, the company acknowledged training and testing a new model. “We’re developing a general purpose model with meaningful advances in reasoning, coding, and cybersecurity,” an Anthropic spokesperson said. - https://fortune.com/2026/03/26/anthropic-says-testing-mythos...

It is possible it is both, they used to RL against cybersecurity, but also didn't explicitly do any qualitative tests and added/changed more data because of those results. For Mythos, they stopped RL'ing against it, and also now intentionally try to make it better.

Unless of course they've actually noted exactly how things were trained here in some technical report and I've missed it, that's possible. Anthropic aren't famous for being very public about their internals though, but would be curious to read more details about it if it's out there from the horse's mouth.

tptacek 12 hours ago|||
Matthew Green isn't a journalist, he's a practitioner (and a cryptography professor at Hopkins).
lazyasciiart 13 hours ago||
RL'd?
Ancapistani 13 hours ago||
Reinforcement learning, I'd assume.

Presumably RLHF (Reinforcement Learning from Human Feedback).

0xDEFACED 10 hours ago||
i wonder how many open source projects have alphabet boys building trust as contributors for eventual backdoor planting
twothreeone 9 hours ago|
But Matthew, think of the kids!!1

Honestly though, framing this as a "tech issue" doesn't help IMHO, it just muddies the water. Ever since RSA was invented privacy has been about educating people on how to use it effectively and _why they should care_. If voters now are choosing authoritarianism over democracy and individual freedom, I think we have to face the reality that after almost 50 years of fighting battle after battle on the technology front, we've largely lost the war on the home front in this regard.

More comments...