Sloppy AI defenses take cybersecurity back to the 1990s, researchers say
scworld.com
scworld.com
The tools you're providing to your LLM agent must never have privileges greater than those you intend to afford to the user who is prompting / interacting with the agent.
You want to use an LLM to make a customer service bot? Sure, you can do that. But that bot MUST NOT UNDER ANY CIRCUMSTANCES be allowed to perform any action you wouldn't let the customer do himself. If it can read your CRM, you need to scope that access to exactly the same access you'd be willing to give the customer directly. Can it cancel orders? That tool must not be able to cancel any order you wouldn't let the customer cancel himself through your app or website.
Don't treat an LLM as if it could replace a human customer service agent, or a human researcher, or a human underwriter, or a human manager. Never make the mistake of believing that the LLM, with any level of clever prompt engineering or attempts at input sanitization, will be "good enough" at not getting fooled. If you trust it with the keys to the kingdom, in the same way that you'd trust a human with those keys, it's a matter of when—not if—you're going to get pwn3d.
Of course, holding this principle, if your autonomous agent can access the web, you must assume that literally anyone on the internet can call any of that agent's tools with arbitrary parameters.
AI is like a SQL without quotation marks though. You just have to assume the attacker gets complete DB access.
Or with more broader definiton - AI is like a Schrödinger’s protocol — it has rules and no rules at the same time. If you can’t find the edges, you can’t define the security. Nobody undertands it completely, yet they try to constraint it.
Things might be different on the business secrets side of things but where I was on the PII/PCI data protection side of things, cybersecurity = legal risk management.
"Known vulnerabilities are showing up at alarming rates because of these tools. It's just getting worse due to vibe coding and AI coding assistants," he said. "If you wanted to know what it was like to hack in the '90s, now's your chance."
I agree with everything except I assume hacking was more fun in the 1990s.
"It's the '90s all over again," said Bargury with a smile. "So many opportunities."
Hacking has been democratized!
Then came LLMs and now you have VCs trying to plug in logs and Jira to their product... researchers say.
Im so tired of LLM enthusiasts not seeing the issues with them and trying to make them solve everything. We need another todo app, this time with LLMs though!!! Fuck the energy consumption of this technology. Private companies want to build nuclear power plants? What could go wrong? Yall need a reality check.
I can tell you right now, that it's not going to be implemented correctly.