Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

AI "cyber models" aren't going to solve our security problems. "If we just patch all the vulnerabilities then we're safe" is a convenient story but it's also not true. If you're worried about cybersecurity, the solution involves hard work, not just more tokens.

36,308 Aufrufe • vor 9 Tagen •via X (Twitter)

49 Kommentare

Profilbild von MikeTalonNYC
MikeTalonNYCvor 9 Tagen

but... hard work is hard!

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

This is the core problem isn’t it

Profilbild von Josh Long (the JoshMeister)
Josh Long (the JoshMeister)vor 8 Tagen

I promise, I independently conceived this before I watched to where you said “GPT Zoolander.” Great minds… 🧠‍🤝‍🧠

Profilbild von Zack Korman
Zack Kormanvor 8 Tagen

Hahaha that’s amazing

Profilbild von izan
izanvor 9 Tagen

Zack is actually a cyber model and you should all buy his pinup calendar

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

“I’ll show you what a cyber model really looks like”

Profilbild von izan
izanvor 9 Tagen

"Paint me like one of those Mistral AI"

Profilbild von Marius Reinecker
Marius Reineckervor 9 Tagen

Nah, it's fine. When they go rouge, they just change colour. Harmless. We should really worry about when they go rogue, though.

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

That’d be kinda dope if they did

Profilbild von Marius Reinecker
Marius Reineckervor 9 Tagen

😉I know very well how rogue is spelled bc I've been playing pen&paper RPGs forever. It's also to my eternal regret not having put more effort into learning French at school when I had the chance. Oh, and I'm autistic. There's that, too.

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

lol sorry I missed the joke

Profilbild von Marius Reinecker
Marius Reineckervor 9 Tagen

You were busy paying attention to the important things. But there are niches in CS for folks like me and being pedantic is an advantage.

Profilbild von ShrekOverflow
ShrekOverflowvor 8 Tagen

Unfortunately, the current security response seems to be like so:

Profilbild von Zack Korman
Zack Kormanvor 8 Tagen

This is extremely accurate and an extremely good fit. And honestly so painful to watch because it’s exactly how most security teams work

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

Hah thank you! The job of security involves work. Stunning news

Profilbild von Kamil Staszewski
Kamil Staszewskivor 9 Tagen

It's the first thing companies does now. Instead of changing practices that lead to bugs, we rather call "cyber-llm scan .", close eyes and then fix those mistakes with the help of coding-llm. Rarely, we look back, adapt our coding practices, add more checks to CI, improve or introduce regular security practices that were established in the past.

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

Yea. “Just one more LLM bro. I promise it will fix it bro”

Profilbild von Kamil Staszewski
Kamil Staszewskivor 9 Tagen

It costs shit ton of money. If it wasn't for sub, on a decent size codebase (150k loc) llm based application scan can cost to up to 2k USD using current models. That's what keeps companies from abusing it. I'm aware of that number cause I had to calculate it at work recently.

Profilbild von GS-InfoSec
GS-InfoSecvor 8 Tagen

Part of the reason for the limited use is adoption. I believe they will be very good at things like risk and compliance. That is where we will really see an impact that reduces noise. Find all the bugs, and patch everything has never been a good strategy. Big picture correlation, assessment, and strategy is going to supercharge imo.

Profilbild von Zack Korman
Zack Kormanvor 8 Tagen

@techspence I mean I agree, but there are entire products that have to be built out to really support that (especially just getting the right data into the right place). And that isn't there yet, that I know of

Profilbild von GS-InfoSec
GS-InfoSecvor 8 Tagen

@techspence A lot of companies are tackling IT debt, immature data gov, and security/privacy issues to get in position for AI. They aren’t ready. They don’t have the people with the AI skills.

Profilbild von Carmen
Carmenvor 4 Tagen

Imagine if regular companies said "our cyber defenses are shit, let's hope we don't get hacked." Would you still trust them?

Profilbild von Shasheen_B
Shasheen_Bvor 8 Tagen

It’s all about the bloody secrets. The best models still do not solve fundamental problems. They have amplified it.

Profilbild von Tyler
Tylervor 9 Tagen

GRC bros in shambles

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

Hahah I gave them some credit!

Profilbild von Tyler
Tylervor 8 Tagen

Fair in your treatment, as usual.

Profilbild von Dirty Indy 🟥🟧🟨
Dirty Indy 🟥🟧🟨vor 8 Tagen

Train your Pokémon’s

Profilbild von Erik Ex Plano
Erik Ex Planovor 9 Tagen

Agreed. And the most important piece (IMNSHO) is architecture: selecting what kinds of pieces you use and how they all fit together to meet the org’s requirements. LLMs seem to be pretty shit at this.

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

Yea a lot of orgs with horrible architectures are in trouble. A lot of orgs with good architecture are mostly fine even if they do a much worse job

Profilbild von Clément
Clémentvor 8 Tagen

ClaudeStrike wen

Profilbild von Zack Korman
Zack Kormanvor 8 Tagen

Oh my god that is admittedly a good name

Profilbild von darkmage
darkmagevor 9 Tagen

Spending tokens is hard work though :D

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

Depends how poorly you spend them

Profilbild von darkmage
darkmagevor 9 Tagen

I hard agree that the term "cyber model" makes no sense. I can see where your issue is now. The AI companies have usurped cyber security thrones and are now attempting to lord-over the discussion. On a political-level, this is definitely undesirable. Thats the first 1min32sec

Profilbild von darkmage
darkmagevor 9 Tagen

3min in Sure, the cybersecurity field is broad and includes more than the "cyber models" typically are designed for. This nuance is understood and expected. The spearhead of defense is certainly offense, and the expectation is that great offense means great defense (IMHO)

Profilbild von darkmage
darkmagevor 9 Tagen

4min in Not sure where this is going because I haven't heard anything new yet. This video is clearly not for me. Best of luck

Profilbild von Zack Korman
Zack Kormanvor 9 Tagen

As a general rule my videos about cybersecurity are for non-cyber people and my videos about not-cyber are for people in cyber.

Profilbild von darkmage
darkmagevor 9 Tagen

This explains everything! You are filling a vital role.

Profilbild von Mona Lisa
Mona Lisavor 9 Tagen

We do, they work for the mossad

Profilbild von Shez Malik
Shez Malikvor 9 Tagen

most of what gets u hacked is working as intended

Profilbild von learner
learnervor 8 Tagen

We can’t. I’m pretty sure all Fortune 500 companies still have vulns from 200X

Profilbild von Jon Towles {MVP}
Jon Towles {MVP}vor 5 Tagen

One could argue if you patch the vulnerabilities you’re safe for a little bit and then not again. Shit look at windows, just set a record for the most patches ever. It’s never finite. The complacency with a side of hubris is what actually gets you into trouble

Profilbild von Ryan McCormick
Ryan McCormickvor 9 Tagen

I agree with most, we've always sucked at security & the answers have largely been available. But once there are no vulnerabilities it's all configuration. Configuration can be audited perpetually. The next phase is cryptographic certification of computation and capability.

Profilbild von Carl Sue
Carl Suevor 8 Tagen

Man, I'd love to debate you on this. I think we see the future similarly, but I disagree with pushing existing frameworks as they stand. They fill a gap now, but not all will be AI resilient, and I think the cybersecurity-as-a-department mindset might be short-lived.

Profilbild von Zack Korman
Zack Kormanvor 8 Tagen

What would you do instead

Profilbild von Carl Sue
Carl Suevor 8 Tagen

We can both agree on many of your points, especially for companies that have deployed a solution but not truly implemented a complete one. IMHO, the solution is not limited to using AI to get these things implemented properly. A better direction is to use some resources to keep tech debt at a reasonable level of degradation while pushing most resources toward building more correct capabilities. Everyone is in a different maturity on where bringing in AI makes the most sense, which is why the big players push threat modeling hardest for “security-focused models.” Reducing costs there lets companies identify the next area that can be modernized and either companies like yours will build for that gap or in a lot of cases I think the functionality will be built in house and slowly dissolve into other parts of the business. As an example it’s better to build say an autonomous credentials management system that reports into a security architect then fund an IAM service if you’re in a position that you have neither or a partially built environment and need to fill the gap.

Profilbild von CyberBox
CyberBoxvor 8 Tagen

@ZackKorman Agreed. Tool sprawl and shelfware stem from weak operational lifecycle. AI won't fix context. True ROI needs continuous posture validation, tight API orchestration, and detection engineering.

Profilbild von Carl Sue
Carl Suevor 8 Tagen

@ZackKorman It also needs investment into things like micro harnesses which adapt a workflow instead of just adding another tool. Simplify security while insisting on high standards.

Profilbild von Jonathan Yantis
Jonathan Yantisvor 8 Tagen

The core risk I see at most enterprises is broad permission graphs and ease of lateral movements. A cyber critical model has near infinite paths to their goals once inside most enterprises.

Ähnliche Videos