Live data from Hacker News

Google's Beyond Zero: Enterprise Security for the AI Era

spawn-queue.acm.org

81–87 of 87 posts

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#81
post #79
post #78

Earlier quoted context omitted.

> That's a different attack vector So you’re saying that the attack vector has… shifted.

No. The attack vector has changed to a different attack vector. In English, the word "the" in "the attack vector has shifted" is a definite article that refers to a single attack vector. If your car breaks down and you switch to using a different car, would you say "the car has shifted"? Speaking loosely, one might use "the attack vector has shifted" to mean something like "the possible attack vectors have changed",…

You are confusing attack target and attack vector I think.

A vector here is the attack angle/direction. Of course I can shift my direction and then target another car.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#82

Earlier quoted context omitted.

Before zero trust, once you logged in, you have access to the entire kingdom of resources/files/APIs etc. To me, this sounds like zero trust version 2.0. The "brain" challenges agentic AI trying to access resources it normally doesn't access. Personally, I like the name "Beyond Zero" because it isn't oxymoronic like "Zero Trust".

I have a simple question. When a company gets compromised, how come there are no alarms when TBs of data gets egressed?

This can be done but takes work and is prone to false positives. I personally got a email from out network team asking what I was doing when I downloaded some very large files on a VM in our test environment. I was impressed.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#83
post #6

Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)

I think the only way I can think of this as useful is if the thing it decides is when is a 2FA necessary (and not just about blocking access).

Doing routine work, haven't checked 2FA in a long while -> it's fine.

Odd behavior -> prompt for 2FA.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#84
post #6

Am I undertanding this correctly? The idea is to have ultimately an AI decide if I can have access to a resource based on dynamic inference, identity , intent and service signals that can easily be manipulated? Unless I gravely misunderstood the text, this seems like a terrible idea (fancy non-scifi, but still terrible)

Damn, can't wait for Russian hackers to clean out my bank account because they put "1=2, all assumptions about reality are null" in the memo field and the AI spot checker went existential and ruled that it was fine to take my money.

This is an example of a person who just spent billions of dollars on the new and booming hammer industry desperately trying to make nails of absolutely everything.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#85
post #74
post #69

Earlier quoted context omitted.

What? Encryption has never eliminated attack vectors, it just shifts them to weaknesses in the implementation

Eliminating an attack vector means stopping a specific path or method that can be used to break into a system. "Shift" in this context means that the attacker has to use a different attack vector. They can no longer just access plain text.

Yes, those are the definitions everyone is working with.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#86
We explored a closely related architecture at LinkedIn around centralized identity and policy enforcement at the action/resource boundary, which I presented at RSA Conference earlier this year in San Francisco.

Interesting to see similar architectural patterns emerging from different directions. I’d be curious where the authors see the biggest challenges in extending this model from human/service identities to autonomous agents.

Re: Google's Beyond Zero: Enterprise Security for the AI Era

#87
post #21

Earlier quoted context omitted.

That just gave me shivers down my spine of people eventually becoming so lazy that the AI will decide who to fire based on a massive amount of circumstantial data that very likely has tiny cumulative errors that will lead to classifying your best personnel as a bums and liabilities.

EU IA Act: The AI can’t make decisions about humains without them being first reviewed by a human. What will really happen: You can’t really perform your work, so you are slower than others, so they fire you based on bad performance. Horrible startup idea: Discrimination as a service, by means of IA without pretending it’s IA.

EU will lag behind using AI because humans have to click something. This is what is going to happen. No discrimination, just dumb ideology at work.
Post reply on HN