Posted by vslira 15 hours ago
Honestly though, framing this as a "tech issue" doesn't help IMHO, it just muddies the water. Ever since RSA was invented privacy has been about educating people on how to use it effectively and _why they should care_. If voters now are choosing authoritarianism over democracy and individual freedom, I think we have to face the reality that after almost 50 years of fighting battle after battle on the technology front, we've largely lost the war on the home front in this regard.
I, for one, usually tell my AI to start with secure code, make it small, and modular.
This is the first article I've seen that now says the opposite ! AI will make code too secure!
Since the small amount of AI coding I've done often results in buggy code (even a shell script written today) with the AI go-to solution of "write more buggy code to fix", this seems counterintuitive.
I remember walking into some shitty congresscritter's office with a fucking years old one pager, with a few more citations written on the bottom in pen because I wasn't going to bother making it pretty this time around.
You should have seen his face when i asked him straight up: dude, you seem to have a problem processing information. Are you having some kind of medical issue? Because I'm not the last staffer: If you abuse my time, I am never coming back here again to add more citations to a fucking one pager from 1999 -- I'm making it my mission to remove you if you fuck this up on purpose ever again.
(Or something to that effect -- I've been told I can get a bit aggressive in my rhetoric.)
This was approximately 2016 and that individual is no longer in office.
I stand by my words.
> Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.
His conclusion sounds extremely optimistic to me.
Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.
Pre-AI, the advantage went to the entities with the largest budget to hire the best and brightest security engineers.
Post-AI, it'll go to the entities with the largest inference budget.
Right now we're in a transitionary period where it's kind of a tossup which approach is more practical, but at the end of the day - it's still all about how much money you can throw at the problem. I'm just hoping the threshold climbs high enough it's no longer practical for governments to be able to compromise individual actors' devices because doing so would waste a 0-day that's far, far more valuable than prosecuting one arbitrary person is worth.
There’s (almost) always someone else out there that is willing to do it, and there’s (almost) always a dollar amount that you can’t turn down.
I personally welcome such spiraling offense-defense cycles as it is one of the main drivers of the technological progress.