‹ BackHN Continuity

Thread

Data-only attacks are easier than you think (2024)

102 points · 45 comments · segfaultbuserr

  1. mgaldys4 · · focus · HN ↗
    Data-only attacks are somewhat low-hanging fruit. Classical static analysis could already find them before AI got this strong, and LLMs make identification even easier. But the real threat is risk buried in business logic, especially abuse of normal business logic. Take e-commerce refund abuse. Bug hunters would not even call it a risk, yet fraud rings have arbitraged millions off this kind of logic. And because the logic is legitimate business logic, it is very hard to detect.
    1. eru · · focus · HN ↗
      Going on a bit of a tangent:

      'Classic' non-AI fuzzers like AFL are still insanely useful and powerful, as are static analysis tools.

      LLMs make all of these much, much easier to use. The other night, before I went to bed I told Kimi to go and fuzz filesystem code in the latest Linux kernel. I woke up to 26 crashes with reproducers and fixes. I'm still busy reviewing and upstreaming them. (Some have already landed.)

      1. billypilgrim · · focus · HN ↗
        Similar use case here! Combining AI with fuzzers is so powerful, especially for creating a special fuzzing harness, or generating seeds for hard to reach code. That was taking hours/days and was frustratingly boring work before. Unfortunately the Codex models refuse a lot for me, I’m mostly using the cheapest models because they refuse the least, have you found Kimi to be a good alternative? Any other you tested that you can recommend? Thinking of switching.
        1. eru · · focus · HN ↗
          So Codex with Daybreak Blue refuses less. You need to join OpenAI's cybersecurity program. But it seems to be pretty simple: I just told them that I do some Linux kernel work for fun, but that codex refuses anything that touches C and the kernel.

          I've also tried DeepSeek and now Mimo. DeepSeek was really quite useful before the price increase, because I didn't care too much about burning a lot of tokens. But it was less useful since, especially since my timezone here in Singapore is the same as in China, so my waking and working hours have a lot of overlap with their peak pricing. However, it's gotten a bit cheaper effectively, because their new flash model is supposedly as good as the old pro model.

          Which cheap models are you using (especially those that refuse less)?

          So far I've only really used Mimo to drive Sashiko, which is a kernel review tool. I haven't used it for actually writing code.

          Kimi is pretty decent overall. But I haven't given it really hard work. Running a fuzzer is pretty simple, and so's the other stuff I asked it so far.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.