Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release



On 9/14/26 8:54 AM, Rich Pieri wrote:
> AI helping the defenders more than the attackers

Figuring out how the stuff we currently call AI pans out on the whole 
will be very interesting, it feels like a chess game where the rules are 
being made up as we go. For example, I'm not particularly worried that 
AI will wipe out humanity, at least not now, though I do worry we might 
be dumb enough give this software means to do so. For example, we might 
give them physical weapons. That seems a very bad idea.


But I do really like the idea that AI does help defenders more.

My key arguments:

- Software security can approach perfect. Attackers don't get to break 
in, they always need to be *let* in. Where a physical lock can always be 
broken by applying yet more force, logic can be perfect, and the locks 
we build with logic can also be perfect. Well, at least to the extent we 
care, they can approach perfection. Slight catch is we need to care. 
This gives defenders an inherent high ground to fight from, and LLMs 
could be used to magnify that advantage.

- Vulnerabilities are not the same as exploits. Only really bad ones are 
"10 out of 10", and I tend to have extremely little sympathy for those 
who built or adopted such crap. Most vulnerabilities need to be 
assembled with other vulnerabilities before attackers can accomplish 
anything. Every time a vulnerability is found defenders get a chance to 
fix that vulnerability whereas attackers need to assemble it with 
others. Therefore finding vulnerabilities (with an LLM or not) hands an 
advantage to defenders: fix it, once fixed link breaks the exploit 
chain. Whether defenders care, and whether their code is in good enough 
shape to do anything about it, are different questions.

But keep in mind that other effects can kick in: If LLMs make it 
possible to write vulnerabilities far more quickly than before, then 
maybe defenders will use that to be deploy stupidity with even more 
efficiency?and that helps attackers.

Another possibility is that there is such a large inventory of existing 
vulnerabilities that attackers can maybe harvest them faster than 
defenders can fix them. Short term advantages can be extremely real, 
though this one doesn't seem to have landed for real so far. Maybe it 
never will.

Yet another consideration: Full exploit chains still need to be put to 
some use, and that is work. (Even vandalism is still work.) LLMs might 
well help attackers with other parts of their enterprises.


The idea that we should slow down with this AI stuff seems reasonable, 
and when the AI inflated bubble crashes, that could help a lot.


-kb




Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org