Top
Best
New

Posted by vslira 15 hours ago

Going Dark, and the era of law enforcement hacking(blog.cryptographyengineering.com)
356 points | 159 commentspage 4
0xDEFACED 11 hours ago|
i wonder how many open source projects have alphabet boys building trust as contributors for eventual backdoor planting
twothreeone 11 hours ago||
But Matthew, think of the kids!!1

Honestly though, framing this as a "tech issue" doesn't help IMHO, it just muddies the water. Ever since RSA was invented privacy has been about educating people on how to use it effectively and _why they should care_. If voters now are choosing authoritarianism over democracy and individual freedom, I think we have to face the reality that after almost 50 years of fighting battle after battle on the technology front, we've largely lost the war on the home front in this regard.

newsomix9xl 10 hours ago||
So I've read dozens of complaints that AI produces insecure code.

I, for one, usually tell my AI to start with secure code, make it small, and modular.

This is the first article I've seen that now says the opposite ! AI will make code too secure!

Since the small amount of AI coding I've done often results in buggy code (even a shell script written today) with the AI go-to solution of "write more buggy code to fix", this seems counterintuitive.

firefax 7 hours ago||
Nononono no more of this shit

I remember walking into some shitty congresscritter's office with a fucking years old one pager, with a few more citations written on the bottom in pen because I wasn't going to bother making it pretty this time around.

You should have seen his face when i asked him straight up: dude, you seem to have a problem processing information. Are you having some kind of medical issue? Because I'm not the last staffer: If you abuse my time, I am never coming back here again to add more citations to a fucking one pager from 1999 -- I'm making it my mission to remove you if you fuck this up on purpose ever again.

(Or something to that effect -- I've been told I can get a bit aggressive in my rhetoric.)

This was approximately 2016 and that individual is no longer in office.

I stand by my words.

rowyourboat 4 hours ago|
What one pager, what words? This story needs more context if it is going to make sense
bell-cot 14 hours ago||
> Defenders are now in the process of patching every bug they can find, often with AI helping them. Entire development toolchains are being rebuilt to incorporate powerful vulnerability scanning before software reaches the testing phase. This does not mean that every bug will be found: even calculating the number of bugs in a piece of code is probably uncomputable. In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.

> Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.

His conclusion sounds extremely optimistic to me.

bahmboo 14 hours ago|
The number of remotely-exploitable defects is going to drop by 1 or 2 orders of magnitude. We now have amazing machines that will find pretty much all the a priori knowable ones. They outperform even the most gifted h@x0rs. So that just leaves a small pool of leetrs to scour a very barren landscape. And that pool is also shrinking as we rely more and more on the ai tools.

Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.

Ancapistani 14 hours ago||
It all boils down to money/resources, like always.

Pre-AI, the advantage went to the entities with the largest budget to hire the best and brightest security engineers.

Post-AI, it'll go to the entities with the largest inference budget.

Right now we're in a transitionary period where it's kind of a tossup which approach is more practical, but at the end of the day - it's still all about how much money you can throw at the problem. I'm just hoping the threshold climbs high enough it's no longer practical for governments to be able to compromise individual actors' devices because doing so would waste a 0-day that's far, far more valuable than prosecuting one arbitrary person is worth.

fragmede 14 hours ago||
It's not as simple as money, people are motivated by other things as well. There's no amount of money you could pay me to intentionally hurt children, but I'd do a lot of things to protect them. And a lot of things people say they're doing in the name of protecting them but has ulterior motives, so it's complicated.
Ancapistani 13 hours ago||
I agree, but broadly speaking it doesn’t change much that what I described breaks down at the level of an individual. There are very few instances where the global talent pool is small enough that individual beliefs become a constraint.

There’s (almost) always someone else out there that is willing to do it, and there’s (almost) always a dollar amount that you can’t turn down.

BoingBoomTschak 14 hours ago||
Childish, nation-states as powerful as the US have access to much more potent stuff. Maybe they'll be forced to rely more on their Intel ME/AMD PSP/modem (cf https://redmine.replicant.us/projects/replicant/wiki/ModemIs...) backdoor and ANT James Bond catalog.
elisbce 9 hours ago||
Considering the amount of AI slop being generated today and LOCs that no one actually reviewed, I doubt we will run out of vulnerabilities to exploit...
trhway 13 hours ago||
article read to me like a typical rehash of a typical offense-defense cycle. AI would have written a better article.

I personally welcome such spiraling offense-defense cycles as it is one of the main drivers of the technological progress.

fenestella 6 hours ago|
[flagged]
More comments...