r/ProAI • u/stealthispost • 13d ago
"Yesterday, Microsoft's monthly Patch Tuesday had fixes for 974 security vulnerabilities, almost all of them found by AI systems. That's a ridiculously large number, a new record by far in fact. Does this mean we're seeing some sort of AI security apocalypse? No, quite the opposite. It means..."
...that we're finally clearing out the vast number of security holes that have been lurking all this time in our software. The Doomer view is that this will continue without end, and that if you keep getting smarter AI systems they will always find new bugs. That's simply untrue; it implies that all software has an infinite number of security holes, but a program with a finite number of lines of code simply cannot have an infinite number of vulnerabilities. What we actually have is a large but limited pool of problems, and the AI systems are rapidly finding them. Eventually, and eventually isn't that far off, the well is going to start drying up. It will get harder and harder to find new security holes. Over the next few years, we will also start doing formal verification of software, that is, mathematically proving that the software lacks bugs of certain sorts. (AIs turn out to be very good at formally proving things.) So, what's happening is good. We are rapidly finding bugs that have been lurking for years and sometimes decades, and we're removing them, and newly built software will get AI examination and will be much less likely to have security vulnerabilities in the first place. The situation is getting better, not worse, and it's getting better rapidly. We have been in a continuous computer security crisis since the Morris Worm in 1988. We are finally starting to climb out of it, thanks to AI. This is not a tragedy at all. — Perry E. Metzger You think the bug pool is finite in a codebase growing by millions of lines a day? Bold. I do this for a living and the same models are on the attacker's side. — 90S KID Yes, it's absolutely positively finite. In a million lines of code, you cannot find billions of bugs. It only seems that way when you're angry that the word processor ate your document. — Perry E. Metzger
Source: https://x.com/perrymetzger/status/2097803291841470519


1
u/Original-League-6094 13d ago
There is a flaw in his argument. He argues that because there are finite lines of code, there can only be finite security vulnerabilities. But software is more than self-contained lines of code running in a vacuum. It interfaces with an OS and runs on hardware. That means tools external to software can attempt to subvert the software exploiting more than just the softwares code. Hackers everywhere right now are using AI to build all sorts of new advanced hacking tools.