‹ BackHN Continuity

Thread

Data-only attacks are easier than you think (2024)

102 points · 45 comments · segfaultbuserr

  1. mgaldys4 · · focus · HN ↗
    Data-only attacks are somewhat low-hanging fruit. Classical static analysis could already find them before AI got this strong, and LLMs make identification even easier. But the real threat is risk buried in business logic, especially abuse of normal business logic. Take e-commerce refund abuse. Bug hunters would not even call it a risk, yet fraud rings have arbitraged millions off this kind of logic. And because the logic is legitimate business logic, it is very hard to detect.
    1. hilariously · · focus · HN ↗
      I still remember me and my friends on club live finding that the games you could just submit the scores for and get free xbox stuff, and then doing some research online years later we found the entire thing was setup by employees to abuse themselves with plausible deniability.

      Club live lost msft millions of dollars by itself.

      1. pixl97 · · focus · HN ↗
        Lol, heh, how long before we find AI is setting up hidden doors like this to extract money from software they make via external methods.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.