On 9/11/26 06:13, Martin Hecht wrote:
Our society strongly depends on connected IT systems comprising our infrastructure nowadays. Now, these powerful algorithms are able to find tons of vulnerabilities in software, and they are acting on the same public internet to which many critical systems are connected.

I'm concerned if we (the humanity) manage to close all those vulnerabilities before these algorithms take over essential parts of our infrastructure, or if we find ways to really contain the algorithms reliably (which seems to be close to impossible, given the fact that there are also bad actors around). Sorry for being slightly off-topic, but I believe protecting critical IT systems as good as we can will soon become more important than ever before.

I agree that protecting critical IT systems is important. But I think that's *always* been important. We should be protecting *all* IT systems, too. Way too many have thought "I won't get attacked" and then get successfully attacked.

Over the next few years AI-enabled attacks will be painful for many. AI makes attacks much cheaper, so attacks will greatly proliferate. However, AI also makes finding & fixing the vulnerabilities cheaper. Defenders will *NOT* be able to claim "I won't be attacked" (they already are), so they'll need to seriously find & fix vulnerabilitie. It's true that current AI systems aren't good at fixing *complex* vulnerabilities (1Password found a success rate of only 26.0%), but most vulnerabilities aren't complex, and humans can step in to fix complex vulnerabilities once they are *known* about.

Beyond these next few years, I think we're going to see systems become *dramatically* more secure. But it's going to be a rocky few years getting there.

The "rocky time" can easily be prepared for, though. I encourage everyone to do the following, assisted by AI:

1. Find & fix vulnerabilities.

2. Speed component update response. I argue this further here: https://www.linkedin.com/pulse/accelerate-deployment-vulnerability-tsunami-david-a-wheeler-eapge/

3. Harden systems so even break-ins will be less effective.

I'd encourage others to do the same. The "vulnpocalypse" is starting. Like many storms, if you're ready, it will be far less damaging. I look forward to the end-state: WAY more secure software.

--- David A. Wheeler


Reply via email to