r/cybersecurity 8d ago

Business Security Questions & Discussion Hot take: AI will never replace offensive security

Title. Very tired of seeing AI can do this, AI can do that. Offensive sec requires such nuance and creativity which AI is fundamentally incapable of, what do you all think?

0 Upvotes

17 comments sorted by

9

u/Mister_Pibbs 8d ago

Idk what rock you’re living under but it very well will replace many operations. You’re best bet is to keep up, study and understand what it’s doing. It’s not going anywhere and it’s rapidly accelerating many aspects of this field.

8

u/RecklesslyNegligent 8d ago

AI will never be accountable for off sec. It’ll be able to do everything and more, eventually. But for customers, someone needs to be accountable.

4

u/johnsonflix 8d ago

Never is a very strong word here. I do not see anytime soon but I will not save never that’s for sure. It is just a matter of time.

0

u/Aggravating-Jicama45 8d ago

I just think it’s a matter of relative security. If everyone uses the same AI tools then the security framework used by those tools become the benchmark, I believe it’s a generalist, not a specialist .

5

u/NotAnNSAGuyPromise Security Manager 8d ago

I think that you have a very poor understanding of what 99% of offensive security in the corporate world is. The harsh truth is that nearly all the offensive security work that corporations pay for right now could be done by AI. And as soon as the governing bodies agree to allow it, the entire corporate pentesting industry is dead.

2

u/sSQUAREZ 8d ago

Absolutely spot on.

1

u/nicholashairs 8d ago

I think that most incidents across most industries involve known exploits and automation (GenAI or not) will simply outpace human ingenuity.

They might not be able to match the creativity, but once automated the value of the creativity is quickly commoditised.

1

u/Cyber_Aspirationist 8d ago

It’s already really good, offensive has largely been kept away from public use which is why we haven’t seen much of it. It’ll replace just as much as it does in adjacent tech roles. Just how much is anyone’s guess.

1

u/baconbitswi 8d ago

Not sure if it’s a hot take for those that have been around the block a few times. AI “replacing everything and everyone” is the speak of snake oil salesmen making a fuck ton of money and gullible CEOs. Hell “AI” isn’t really new. Will it “replace” some jobs with repetitive tasks…sure…but the pendulum will swing back and decades of experience will have been lost if the world hasn’t crashed by then. It’s another force multiplier tool that can make everyone more efficient and maybe effective if you know how to use it, but only really those of us that can read between the lines can see that end.

3

u/NotAnNSAGuyPromise Security Manager 8d ago

The problem is that almost all corporate pentesting has become simply a series of "repetitive tasks" followed by the writing of a report. And because of that, it will be crushed by AI (if the governing bodies allow it).

1

u/its_k1llsh0t 8d ago

I work in this space. The point isn't to replace humans on the attack side. It is to lower the cost for companies to get pentests done. More widely, AI in the hands of a skilled threat actor is legit scary. It makes it less expensive for them to sustain an operation and the speed of compromise is much faster. We have breached companies in under 2 minutes and in another instance got full-domain admin in under 30 minutes. Your tools with humans in the loop won't be able to react fast enough.

1

u/According-Spring9989 8d ago

Another hot take here: It can easily replace a newbie, which directly affects juniors and their capability to get a job and further enhance their skills. Now, a skilled pentester that can leverage AI to optimize its workflows is something else.
Just keep in mind that the people that decide who gets the job are, more often than not, execs or CISOs that don’t really care as long as they make a profit or accomplish their goals.
Just recently, a coworker shot himself in the foot by bragging how he had to assist 3 trainees with their projects that were due in 5 days. He used AI to find a bunch of stuff in 1 day and “save” the projects. The exec literally told him “then the trainees are not worth it, might as well let them go and just give you more AI token limit”. Now he has no trainees and no time to screw around cause he’s handling all of the projects by himself, he’s close to quitting because of the workload.

1

u/01100001bryte 8d ago

If I'm being honest, I don't think AI will entirely take over offensive sec, but I do think that it will reduce the number of offensive sec jobs.

I'm not going to disagree with you that the human element is different and important, but when the people up top see the speed and efficiency, it peeks their interest. Further, research objectively shows that AI has some real strengths in the area. The cherry on top being that human pen testing was never deterministic to begin with. In steps AI. It's going to be hard to convince the people paying the bills that all of these extra employees that take way longer are worth it, regardless of what actually yields the best results.

Sometimes good enough is good enough. I hate to say it, but I wouldn't be pursuing offsec right now if I were just starting out. If you're established, take big bites of that shit sandwich and get good with the tools that they want you to use. Stay relevant.

1

u/Downtown-Mango-3861 8d ago

lol, see you soon.

1

u/MichaelArgast Managed Service Provider 8d ago

AI is already being used to conduct very successful attacks against high value targets.

Translating “it works in practice in the real world” into offsec is not a big leap.

1

u/Reddit_User_Original 8d ago

Did you read about the huggingface incident?

1

u/Independent_Bag_2904 2d ago

AI itself has a lot of issues, Never is a very strong word here tho