BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Subject: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: kentborg at borg.org (Kent Borg)
- Date: Mon, 14 Sep 2026 09:49:08 -0700
- In-reply-to: <20260914115453.23e92726.Richard.Pieri@gmail.com>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com> <qh5h3x3w2kbe5voii3hcgo2vuapoxl7nrlvzgoug4nrsv2kr3v@mhmssfwu7rvo> <mFlzau6ezeaBP0gH7cGlxjM-oRrpyUc8glznQi72OZNepcPt-wIa5as8gnoeLwP9aUw6MPrmh3P8vutoMlhGvYQFdX4McXm4LKkiiX3RFoI=@cryptnet.net> <20260417142530.5ba22435.Richard.Pieri@gmail.com> <8f8940a4-6ef8-435f-85b4-684834f8b4b4@app.fastmail.com> <20260903203656.174df76c.Richard.Pieri@gmail.com> <f49ca5a7-3419-4509-90d5-ec219a25d589@app.fastmail.com> <20260904081559.0e8ae553.Richard.Pieri@gmail.com> <47b87f50-7632-4094-a197-dab54523d841@app.fastmail.com> <20260904140511.582fdbd0.Richard.Pieri@gmail.com> <beaccecd-bee0-4bec-bf6b-fcd825ca64c2@app.fastmail.com> <20260904151819.030790b7.Richard.Pieri@gmail.com> <c3e5aecd-ce1d-4d11-aaa8-1d559040f2ce@app.fastmail.com> <20260905123427.375ffb40.Richard.Pieri@gmail.com> <9d8da6a0-5516-4ea2-9762-0102f24d8941@app.fastmail.com> <20260914115453.23e92726.Richard.Pieri@gmail.com>
On 9/14/26 8:54 AM, Rich Pieri wrote: > AI helping the defenders more than the attackers Figuring out how the stuff we currently call AI pans out on the whole will be very interesting, it feels like a chess game where the rules are being made up as we go. For example, I'm not particularly worried that AI will wipe out humanity, at least not now, though I do worry we might be dumb enough give this software means to do so. For example, we might give them physical weapons. That seems a very bad idea. But I do really like the idea that AI does help defenders more. My key arguments: - Software security can approach perfect. Attackers don't get to break in, they always need to be *let* in. Where a physical lock can always be broken by applying yet more force, logic can be perfect, and the locks we build with logic can also be perfect. Well, at least to the extent we care, they can approach perfection. Slight catch is we need to care. This gives defenders an inherent high ground to fight from, and LLMs could be used to magnify that advantage. - Vulnerabilities are not the same as exploits. Only really bad ones are "10 out of 10", and I tend to have extremely little sympathy for those who built or adopted such crap. Most vulnerabilities need to be assembled with other vulnerabilities before attackers can accomplish anything. Every time a vulnerability is found defenders get a chance to fix that vulnerability whereas attackers need to assemble it with others. Therefore finding vulnerabilities (with an LLM or not) hands an advantage to defenders: fix it, once fixed link breaks the exploit chain. Whether defenders care, and whether their code is in good enough shape to do anything about it, are different questions. But keep in mind that other effects can kick in: If LLMs make it possible to write vulnerabilities far more quickly than before, then maybe defenders will use that to be deploy stupidity with even more efficiency?and that helps attackers. Another possibility is that there is such a large inventory of existing vulnerabilities that attackers can maybe harvest them faster than defenders can fix them. Short term advantages can be extremely real, though this one doesn't seem to have landed for real so far. Maybe it never will. Yet another consideration: Full exploit chains still need to be put to some use, and that is work. (Even vandalism is still work.) LLMs might well help attackers with other parts of their enterprises. The idea that we should slow down with this AI stuff seems reasonable, and when the AI inflated bubble crashes, that could help a lot. -kb
- Follow-Ups:
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: kentborg at borg.org (Kent Borg)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- References:
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- Prev by Date: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by Date: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Previous by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Index(es):
