Security auditing in the age of (good enough) AI
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Security auditing in the age of (good enough) AI
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
suhacker256 · · focus · HN ↗
buu700 · · focus · HN ↗
nullsanity · · focus · HN ↗
[dead]
code-sonar · · focus · HN ↗
[dead]
michaelastreiko · · focus · HN ↗
[dead]
Segv77 · · focus · HN ↗
fovc · · focus · HN ↗
Similarly here, I'd argue that a verified implementation with correctness proofs, mechanical translation, and easily auditable theorems seems close to good enough? A lot rides on the Claude-built translator, I suppose, but the trusted code for that project seems to be tiny in comparison to what it would have been 2 years ago!
thephyber · · focus · HN ↗
"Good enough" in colloquial speak usually means the minimum required for some particular requirement.
For security, there is usually no exact threshold that differs between insecure and secure. It's a spectrum that involves costs and tradeoffs, which are subjective value judgements.
A SaaS startup in pre-seed mode with no customers will have VASTLY different value judgements than a bank that handles $trillions in assets. Hence they will make very different security choices and "good enough" will mean very different things in their different sectors.
jessebldr · · focus · HN ↗
[dead]
aftbit · · focus · HN ↗
firen777 · · focus · HN ↗
ethersteeds · · focus · HN ↗
PostOnce · · focus · HN ↗
bravetraveler · · focus · HN ↗
conception · · focus · HN ↗
Ozzie-D · · focus · HN ↗
[dead]
AndrewKemendo · · focus · HN ↗
You need to find a new way to do business with the assumption that you’re 100% eventually going to get pwned
So just assume that going forward and you’ll start to rethink your architecture
Cider9986 · · focus · HN ↗
AndrewKemendo · · focus · HN ↗
Overall though the point is any particular hole that you have will be exploited
so what used to be a game of “patch the hole” is going to need to change entirely
s0rrymybad · · focus · HN ↗
[dead]
MattPalmer1086 · · focus · HN ↗
This is why there are so many resilience initiatives in serious organisations. Assume it is gonna happen. Limit blast radius, ensure effective recovery.
shakna · · focus · HN ↗
ZeroDayDreamer · · focus · HN ↗
[dead]
portagescout · · focus · HN ↗
[dead]