‹ BackHN Continuity

Thread

Security auditing in the age of (good enough) AI

96 points · 16 comments · aray07

  1. Segv77 · · focus · HN ↗
    Good enough AI for security auditing feels like asking for "good enough" brakes. There's just no room for complacency.
    1. fovc · · focus · HN ↗
      Not sure I follow the analogy, so apologies if I'm reading it backwards, but we do in fact have standards for "good enough" brakes without being brake-maxxers.

      Similarly here, I'd argue that a verified implementation with correctness proofs, mechanical translation, and easily auditable theorems seems close to good enough? A lot rides on the Claude-built translator, I suppose, but the trusted code for that project seems to be tiny in comparison to what it would have been 2 years ago!

      1. thephyber · · focus · HN ↗
        I suspect you two are using the same words for different terms / connotations.

        "Good enough" in colloquial speak usually means the minimum required for some particular requirement.

        For security, there is usually no exact threshold that differs between insecure and secure. It's a spectrum that involves costs and tradeoffs, which are subjective value judgements.

        A SaaS startup in pre-seed mode with no customers will have VASTLY different value judgements than a bank that handles $trillions in assets. Hence they will make very different security choices and "good enough" will mean very different things in their different sectors.

      2. jessebldr · · focus · HN ↗

        [dead]

    2. aftbit · · focus · HN ↗
      I don't get the analogy. Brakes that are good enough for a Honda Civic driven at regular speeds are not good enough for a fire truck or a race car, but there are in fact standards that are "good enough" for all of those.
      1. firen777 · · focus · HN ↗
        People on HN have a tendency to shove in analogies where it doesn't need one. Even worse when most of the time the analogies do not make sense.
        1. ethersteeds · · focus · HN ↗
          You could even say we are like a glass carpet: the color may be attractive but the texture is terrible...
    3. PostOnce · · focus · HN ↗
      There is an area where an AI audit can add some real value: the huge multitude companies that have never looked at security at all. Small businesses.
    4. bravetraveler · · focus · HN ↗
      This is why we all use ceramics in our daily-drivers, of course.
    5. conception · · focus · HN ↗
      All security is a negotiation of allocating resources. It always ends with “well, that’s good enough for this.” There is never a “Ahhhh we’re done!” It can always be “more secure”.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.