[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
Kent Borg
kentborg at borg.org
Mon Sep 14 12:49:08 EDT 2026
On 9/14/26 8:54 AM, Rich Pieri wrote:
> AI helping the defenders more than the attackers
Figuring out how the stuff we currently call AI pans out on the whole
will be very interesting, it feels like a chess game where the rules are
being made up as we go. For example, I'm not particularly worried that
AI will wipe out humanity, at least not now, though I do worry we might
be dumb enough give this software means to do so. For example, we might
give them physical weapons. That seems a very bad idea.
But I do really like the idea that AI does help defenders more.
My key arguments:
- Software security can approach perfect. Attackers don't get to break
in, they always need to be *let* in. Where a physical lock can always be
broken by applying yet more force, logic can be perfect, and the locks
we build with logic can also be perfect. Well, at least to the extent we
care, they can approach perfection. Slight catch is we need to care.
This gives defenders an inherent high ground to fight from, and LLMs
could be used to magnify that advantage.
- Vulnerabilities are not the same as exploits. Only really bad ones are
"10 out of 10", and I tend to have extremely little sympathy for those
who built or adopted such crap. Most vulnerabilities need to be
assembled with other vulnerabilities before attackers can accomplish
anything. Every time a vulnerability is found defenders get a chance to
fix that vulnerability whereas attackers need to assemble it with
others. Therefore finding vulnerabilities (with an LLM or not) hands an
advantage to defenders: fix it, once fixed link breaks the exploit
chain. Whether defenders care, and whether their code is in good enough
shape to do anything about it, are different questions.
But keep in mind that other effects can kick in: If LLMs make it
possible to write vulnerabilities far more quickly than before, then
maybe defenders will use that to be deploy stupidity with even more
efficiency…and that helps attackers.
Another possibility is that there is such a large inventory of existing
vulnerabilities that attackers can maybe harvest them faster than
defenders can fix them. Short term advantages can be extremely real,
though this one doesn't seem to have landed for real so far. Maybe it
never will.
Yet another consideration: Full exploit chains still need to be put to
some use, and that is work. (Even vandalism is still work.) LLMs might
well help attackers with other parts of their enterprises.
The idea that we should slow down with this AI stuff seems reasonable,
and when the AI inflated bubble crashes, that could help a lot.
-kb
More information about the Discuss
mailing list