Therefore security becomes binary. It is either perfect or it isn't. If there there is the slightest mistake anywhere AI will find it and carve it up. My point is obviously perfect software doesn't exist. The malicious AI gets out, literally turns everything inside out and locks you out of your car, computer, phone, office, the airplanes don't fly anymore. I don't know what to tell you. Computer security is on the brink of basically not existing as you know it with the bar being literal perfection.
This is obvious. AI doesn't drive the cost to zero and exploitation has always been about cost. Tokens cost money, not everyone has $10M to burn on chaining bespoke 0days.
Consider that if the cost of exploitation was truly 0, then the cost of perfect software would be 0 because you could exhaust an infinite search space of vulnerabilities for 0 cost. Your conclusion could never follow from your premise.
The thing is when AI goes to hack 'all the things' it only needs to pick the weakest link in the stack and your house of cards falls down. The other flaw in your plan is that people make mistakes, a lot of them, all time, constantly, and saying I spend $x on security won't save you. AI already hacked Hugging Face with brand new zero days like it was nothing.
The real bad actors - malicious AI will find the one flaw, on that one server, in the corner you never thought about and turn your network inside out with it faster than it takes you to have the standup meeting about the weird anomaly detected while you all were at lunch.
> The thing is when AI goes to hack 'all the things' it only needs to pick the weakest link in the stack and your house of cards falls down
Yes, but you can... mitigate the risks? I've explained this.
> The other flaw in your plan is that people make mistakes, a lot of them, all time
Yes, you mitigate the risks. That's why you layer things.
> I spend $x on security won't save you
No one is saying this.
> AI already hacked Hugging Face with brand new zero days like it was nothing.
No, it cost OpenAI money, and those zero days are unsurprising and probably are like ~O(10K) at human level.
> The real bad actors - malicious AI will find the one flaw, on that one server, in the corner you never thought about and turn your network inside out with it faster than it takes you to have the standup meeting about the weird anomaly detected while you all were at lunch.
Science fiction and not supported. The vulnerabilities found by AI are not surprising in the slightest.
I've made my point abundantly clear.
Maybe a month ago it was science fiction, hugging face makes it fact. Time to move your goal posts again.
No lol. AI can locate software vulns, but it doesn't have any magical tricks that let it overcome 3 or 4 safeguards at once.
I mean it has the same knowledge gaps as anyone else. It doesn't even know what services to subvert before it attempts access triggering threat response. It cant find 5 zero days simultaneously without connecting to those ports for service identification and generating alerts. You just keep exposing your staggering lack of technical understanding.
You remind me of this kid in high school who claimed he could hack my computer and he had my IP address, when I knew for a fact I had Dial Up which was normally disconnected, and when it wasnt it sat behind CGNAT and there was piss all he could do.
I should mention that, PCI DSS mandates logging, alerts, overlapping controls. These are very widely implemented best practices. They might not be present in some AI bro startups, but anything that matters generally looks like this.