I've written tailored offensive security tools and malware for Red Teams for around a decade and now work in the AI space. The argument that LLMs will enable "super powered" malware and that existing security solutions won't be able to keep up, is completely overblown. I see 0 evidence of this being possible with the current incarnation of "AI" or LLMs. "Vide coded" malware will be easier to detect if the people crea…
I too write automated offensive tooling. We actually wrote a project, vulnhuntr, that found the first autonomously-discovered 0day using AI. Feed it a GitHub repo and it tracks down user input from source to sink and analyzes for web-based vulnerabilities. Agree this article is incredibly cringy and standard best practices in network and development security will use the same AI efficiency gains to keep up (more or l…
The Rise of 'Vibe Hacking' Is the Next AI Nightmare
51–56 of 56 posts
Re: The Rise of 'Vibe Hacking' Is the Next AI Nightmare
#52Earlier quoted context omitted.
Is it even possible to shut it down?
Of course it is. If enough people were truly enraged by it, if some leader were to rile up the mob enough, it could be shut down. Revolts have occurred in other parts of the world, and things are getting sufficiently bad that a sizable enough revolt could shut AI down. All we need is a sufficient number of people who are angry enough at AI.
Re: The Rise of 'Vibe Hacking' Is the Next AI Nightmare
#53Earlier quoted context omitted.
Is it even possible to shut it down?
It's just software running on a server...this isn't a Johnny Depp movie [1]. Just flip the power switch on the racks. [1] https://www.youtube.com/watch?v=0jg3mSf561w
LLM code already runs on millions of servers and other devices, across thousands of racks, hundreds of data centers, distributed across the globe under dozens of different governments, etc. The open source models are globally distributed and impossible to delete. The underlying math is public domain for anyone to read.
Re: The Rise of 'Vibe Hacking' Is the Next AI Nightmare
#54Earlier quoted context omitted.
Bro in 2006 there wasn't any blogosphere. You had IRC.. I can’t find anything of the sort and do you have a link to this discovery that you say was made via LLM?
Bro, I've been a practitioner since 1996 and ran a fucking security blog in 2006.
Re: The Rise of 'Vibe Hacking' Is the Next AI Nightmare
#55Earlier quoted context omitted.
Bro, I've been a practitioner since 1996 and ran a fucking security blog in 2006.
Unless the blog was Phrack, you shouldn't be surprised I never heard of your blog unless it is something you think I would know.. This stuff didn't have such a public community back then like it does now..
I want to stop being elliptical and just say directly: you have strange and counterfactual ideas about the security research community of the mid-aughts. 2006-2008 was the height of the security blogosphere. This stuff definitely had a huge community.
Re: The Rise of 'Vibe Hacking' Is the Next AI Nightmare
#56Earlier quoted context omitted.
It's just software running on a server...this isn't a Johnny Depp movie [1]. Just flip the power switch on the racks. [1] https://www.youtube.com/watch?v=0jg3mSf561w
Eh, it's exactly the Johnny Depp movie that would simplify this into "just flip the power switch". LLM code already runs on millions of servers and other devices, across thousands of racks, hundreds of data centers, distributed across the globe under dozens of different governments, etc. The open source models are globally distributed and impossible to delete. The underlying math is public domain for anyone to read.
The power switch is still king, even if it's millions of power switches versus one.