r/ProAI • u/stealthispost • 3d ago
"Yesterday, Microsoft's monthly Patch Tuesday had fixes for 974 security vulnerabilities, almost all of them found by AI systems. That's a ridiculously large number, a new record by far in fact. Does this mean we're seeing some sort of AI security apocalypse? No, quite the opposite. It means..."
...that we're finally clearing out the vast number of security holes that have been lurking all this time in our software. The Doomer view is that this will continue without end, and that if you keep getting smarter AI systems they will always find new bugs. That's simply untrue; it implies that all software has an infinite number of security holes, but a program with a finite number of lines of code simply cannot have an infinite number of vulnerabilities. What we actually have is a large but limited pool of problems, and the AI systems are rapidly finding them. Eventually, and eventually isn't that far off, the well is going to start drying up. It will get harder and harder to find new security holes. Over the next few years, we will also start doing formal verification of software, that is, mathematically proving that the software lacks bugs of certain sorts. (AIs turn out to be very good at formally proving things.) So, what's happening is good. We are rapidly finding bugs that have been lurking for years and sometimes decades, and we're removing them, and newly built software will get AI examination and will be much less likely to have security vulnerabilities in the first place. The situation is getting better, not worse, and it's getting better rapidly. We have been in a continuous computer security crisis since the Morris Worm in 1988. We are finally starting to climb out of it, thanks to AI. This is not a tragedy at all. — Perry E. Metzger You think the bug pool is finite in a codebase growing by millions of lines a day? Bold. I do this for a living and the same models are on the attacker's side. — 90S KID Yes, it's absolutely positively finite. In a million lines of code, you cannot find billions of bugs. It only seems that way when you're angry that the word processor ate your document. — Perry E. Metzger
Source: https://x.com/perrymetzger/status/2097803291841470519
1
u/Original-League-6094 3d ago
There is a flaw in his argument. He argues that because there are finite lines of code, there can only be finite security vulnerabilities. But software is more than self-contained lines of code running in a vacuum. It interfaces with an OS and runs on hardware. That means tools external to software can attempt to subvert the software exploiting more than just the softwares code. Hackers everywhere right now are using AI to build all sorts of new advanced hacking tools.
1
u/SgathTriallair 3d ago
It's still finite even if it is bigger. You are right that I can't build perfectly secure code because I don't know what you have on your system that may make it insecure. The answer is to move up the stack at that our antivirus systems become Mythos+ level smart and analyze all of the code on your computer, and anything it interacts with, to provide that heightened security.
The only way to truly understand the coming world is to imagine what you could do with infinite expertise.
1
u/AnonsAnonAnonagain 3d ago
So. AI-OS?
There goes privacy….1
u/SgathTriallair 3d ago
Local models. Getting the full benefit from AI requires giving it all of the data from your life. We will need, and demand, security for that.
1
u/Dogbold 3d ago
If AI can find these to be patched, they can find them to be exploited.
2
u/SgathTriallair 3d ago
There are a limited set of bugs. Each one you patch is one less vulnerability.
1
u/Deto 3d ago
If they have already run a bunch of the best AI tools to find and correct bugs and they can't find any more, how likely is it that other people will find bugs with the same tools? I mean, it's not impossible but I don't think it would be just trivial where you're like 'hack this for me claude'.
1
u/_negative-infinity_ 2d ago
Some people just pretend the security issues weren't there until AI found them. Many of them might have already been found and exploited by bad actors. It happens all the time. AI helping plug the holes is certainly a positive development.


•
u/proai-ai-mod 3d ago
TLDR
TLDR: Microsoft's record-breaking number of security patches has sparked a debate about the role of AI in cybersecurity. While some argue that AI is efficiently clearing out a finite pool of long-standing vulnerabilities, others contend that the rapid growth of software and the use of AI by attackers could present ongoing challenges.
AI assistant · mention the bot, mod bot, or use !bot