‹ BackHN Continuity

Thread

Security auditing in the age of (good enough) AI

96 points · 16 comments · aray07

  1. Segv77 · · focus · HN ↗
    Good enough AI for security auditing feels like asking for "good enough" brakes. There's just no room for complacency.
    1. fovc · · focus · HN ↗
      Not sure I follow the analogy, so apologies if I'm reading it backwards, but we do in fact have standards for "good enough" brakes without being brake-maxxers.

      Similarly here, I'd argue that a verified implementation with correctness proofs, mechanical translation, and easily auditable theorems seems close to good enough? A lot rides on the Claude-built translator, I suppose, but the trusted code for that project seems to be tiny in comparison to what it would have been 2 years ago!

      1. thephyber · · focus · HN ↗
        I suspect you two are using the same words for different terms / connotations.

        "Good enough" in colloquial speak usually means the minimum required for some particular requirement.

        For security, there is usually no exact threshold that differs between insecure and secure. It's a spectrum that involves costs and tradeoffs, which are subjective value judgements.

        A SaaS startup in pre-seed mode with no customers will have VASTLY different value judgements than a bank that handles $trillions in assets. Hence they will make very different security choices and "good enough" will mean very different things in their different sectors.

      2. jessebldr · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.