news.volyx.in

AI is breaking two vulnerability cultures (jefftk.com)

430 points by speckx · 113 days ago · 173 comments on HN

Article summary

The article discusses how AI is changing the landscape of vulnerability disclosure and patching, highlighting the tension between two approaches: coordinated disclosure and the 'bugs are bugs' culture. With AI-assisted scanning, the traditional 90-day disclosure window may no longer be effective, and shorter embargoes may be necessary. The author argues that AI can speed up both attackers and defenders, making it possible to have shorter embargoes. The article also mentions the potential impact on projects like Debian, which may need to adapt to the new reality.

Main themes

  • Vulnerability disclosure
  • AI-assisted scanning
  • Coordinated disclosure
  • Patch management
  • Debian and Linux security
  • AI-driven security risks

What commenters say

  • The rise of AI-assisted scanning is breaking not two, but three vulnerability cultures, including the culture of delaying upgrades and staying on stable versions for as long as possible.
  • Debian's approach to shipping security patches quickly may not be enough to keep up with the increasing rate of vulnerability discovery, and the project may need to radically overhaul its approach.
  • Shorter embargoes may not be effective in preventing vulnerabilities from being exploited, as organizations that can patch quickly will still have an advantage, while others will take days or weeks to update.
  • The increasing rate of vulnerability discovery may be due to AI-assisted scanning, but it could also be caused by the increasing complexity of software and the introduction of new vulnerabilities through AI-generated code.
  • Correlation between AI-assisted scanning and the rise of vulnerabilities does not necessarily imply causation, and more investigation is needed to determine the underlying cause of the problem.
  • Even if all code commits are scanned as safe by AI, black hats can still analyze commits and diffs to find vulnerabilities for people who haven't patched yet, making it impossible to achieve complete security through AI-powered scanning alone.
  • The use of AI to scan code commits before release could potentially lead to a state where all new code is vulnerability-free, but this would require significant advances in AI technology and widespread adoption.
  • The effectiveness of AI-powered scanning in preventing vulnerabilities may be limited by the fact that more advanced AI models may be released in the future, which could find vulnerabilities in previously scanned code.