Remix.run Logo
bell-cot 7 hours ago

> Defenders are now in the process of patching every bug they can find, often with AI helping them. Entire development toolchains are being rebuilt to incorporate powerful vulnerability scanning before software reaches the testing phase. This does not mean that every bug will be found: even calculating the number of bugs in a piece of code is probably uncomputable. In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.

> Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.

His conclusion sounds extremely optimistic to me.

bahmboo 7 hours ago | parent [-]

The number of remotely-exploitable defects is going to drop by 1 or 2 orders of magnitude. We now have amazing machines that will find pretty much all the a priori knowable ones. They outperform even the most gifted h@x0rs. So that just leaves a small pool of leetrs to scour a very barren landscape. And that pool is also shrinking as we rely more and more on the ai tools.

Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.

Ancapistani 7 hours ago | parent [-]

It all boils down to money/resources, like always.

Pre-AI, the advantage went to the entities with the largest budget to hire the best and brightest security engineers.

Post-AI, it'll go to the entities with the largest inference budget.

Right now we're in a transitionary period where it's kind of a tossup which approach is more practical, but at the end of the day - it's still all about how much money you can throw at the problem. I'm just hoping the threshold climbs high enough it's no longer practical for governments to be able to compromise individual actors' devices because doing so would waste a 0-day that's far, far more valuable than prosecuting one arbitrary person is worth.

fragmede 6 hours ago | parent [-]

It's not as simple as money, people are motivated by other things as well. There's no amount of money you could pay me to intentionally hurt children, but I'd do a lot of things to protect them. And a lot of things people say they're doing in the name of protecting them but has ulterior motives, so it's complicated.

Ancapistani 6 hours ago | parent [-]

I agree, but broadly speaking it doesn’t change much that what I described breaks down at the level of an individual. There are very few instances where the global talent pool is small enough that individual beliefs become a constraint.

There’s (almost) always someone else out there that is willing to do it, and there’s (almost) always a dollar amount that you can’t turn down.