Загрузка видео...

Не удалось загрузить видео

На главную

AI "cyber models" aren't going to solve our security problems. "If we just patch all the vulnerabilities then we're safe" is a convenient story but it's also not true. If you're worried about cybersecurity, the solution involves hard work, not just more tokens.

36,308 просмотров • 9 дней назад •via X (Twitter)

Комментарии: 49

Фото профиля MikeTalonNYC
MikeTalonNYC9 дней назад

but... hard work is hard!

Фото профиля Zack Korman
Zack Korman9 дней назад

This is the core problem isn’t it

Фото профиля Josh Long (the JoshMeister)
Josh Long (the JoshMeister)8 дней назад

I promise, I independently conceived this before I watched to where you said “GPT Zoolander.” Great minds… 🧠‍🤝‍🧠

Фото профиля Zack Korman
Zack Korman8 дней назад

Hahaha that’s amazing

Фото профиля izan
izan9 дней назад

Zack is actually a cyber model and you should all buy his pinup calendar

Фото профиля Zack Korman
Zack Korman9 дней назад

“I’ll show you what a cyber model really looks like”

Фото профиля izan
izan9 дней назад

"Paint me like one of those Mistral AI"

Фото профиля Marius Reinecker
Marius Reinecker9 дней назад

Nah, it's fine. When they go rouge, they just change colour. Harmless. We should really worry about when they go rogue, though.

Фото профиля Zack Korman
Zack Korman9 дней назад

That’d be kinda dope if they did

Фото профиля Marius Reinecker
Marius Reinecker9 дней назад

😉I know very well how rogue is spelled bc I've been playing pen&paper RPGs forever. It's also to my eternal regret not having put more effort into learning French at school when I had the chance. Oh, and I'm autistic. There's that, too.

Фото профиля Zack Korman
Zack Korman9 дней назад

lol sorry I missed the joke

Фото профиля Marius Reinecker
Marius Reinecker9 дней назад

You were busy paying attention to the important things. But there are niches in CS for folks like me and being pedantic is an advantage.

Фото профиля ShrekOverflow
ShrekOverflow8 дней назад

Unfortunately, the current security response seems to be like so:

Фото профиля Zack Korman
Zack Korman8 дней назад

This is extremely accurate and an extremely good fit. And honestly so painful to watch because it’s exactly how most security teams work

Фото профиля Zack Korman
Zack Korman9 дней назад

Hah thank you! The job of security involves work. Stunning news

Фото профиля Kamil Staszewski
Kamil Staszewski9 дней назад

It's the first thing companies does now. Instead of changing practices that lead to bugs, we rather call "cyber-llm scan .", close eyes and then fix those mistakes with the help of coding-llm. Rarely, we look back, adapt our coding practices, add more checks to CI, improve or introduce regular security practices that were established in the past.

Фото профиля Zack Korman
Zack Korman9 дней назад

Yea. “Just one more LLM bro. I promise it will fix it bro”

Фото профиля Kamil Staszewski
Kamil Staszewski9 дней назад

It costs shit ton of money. If it wasn't for sub, on a decent size codebase (150k loc) llm based application scan can cost to up to 2k USD using current models. That's what keeps companies from abusing it. I'm aware of that number cause I had to calculate it at work recently.

Фото профиля GS-InfoSec
GS-InfoSec8 дней назад

Part of the reason for the limited use is adoption. I believe they will be very good at things like risk and compliance. That is where we will really see an impact that reduces noise. Find all the bugs, and patch everything has never been a good strategy. Big picture correlation, assessment, and strategy is going to supercharge imo.

Фото профиля Zack Korman
Zack Korman8 дней назад

@techspence I mean I agree, but there are entire products that have to be built out to really support that (especially just getting the right data into the right place). And that isn't there yet, that I know of

Фото профиля GS-InfoSec
GS-InfoSec8 дней назад

@techspence A lot of companies are tackling IT debt, immature data gov, and security/privacy issues to get in position for AI. They aren’t ready. They don’t have the people with the AI skills.

Фото профиля Carmen
Carmen4 дней назад

Imagine if regular companies said "our cyber defenses are shit, let's hope we don't get hacked." Would you still trust them?

Фото профиля Shasheen_B
Shasheen_B8 дней назад

It’s all about the bloody secrets. The best models still do not solve fundamental problems. They have amplified it.

Фото профиля Tyler
Tyler9 дней назад

GRC bros in shambles

Фото профиля Zack Korman
Zack Korman9 дней назад

Hahah I gave them some credit!

Фото профиля Tyler
Tyler8 дней назад

Fair in your treatment, as usual.

Фото профиля Dirty Indy 🟥🟧🟨
Dirty Indy 🟥🟧🟨8 дней назад

Train your Pokémon’s

Фото профиля Erik Ex Plano
Erik Ex Plano9 дней назад

Agreed. And the most important piece (IMNSHO) is architecture: selecting what kinds of pieces you use and how they all fit together to meet the org’s requirements. LLMs seem to be pretty shit at this.

Фото профиля Zack Korman
Zack Korman9 дней назад

Yea a lot of orgs with horrible architectures are in trouble. A lot of orgs with good architecture are mostly fine even if they do a much worse job

Фото профиля Clément
Clément8 дней назад

ClaudeStrike wen

Фото профиля Zack Korman
Zack Korman8 дней назад

Oh my god that is admittedly a good name

Фото профиля darkmage
darkmage9 дней назад

Spending tokens is hard work though :D

Фото профиля Zack Korman
Zack Korman9 дней назад

Depends how poorly you spend them

Фото профиля darkmage
darkmage9 дней назад

I hard agree that the term "cyber model" makes no sense. I can see where your issue is now. The AI companies have usurped cyber security thrones and are now attempting to lord-over the discussion. On a political-level, this is definitely undesirable. Thats the first 1min32sec

Фото профиля darkmage
darkmage9 дней назад

3min in Sure, the cybersecurity field is broad and includes more than the "cyber models" typically are designed for. This nuance is understood and expected. The spearhead of defense is certainly offense, and the expectation is that great offense means great defense (IMHO)

Фото профиля darkmage
darkmage9 дней назад

4min in Not sure where this is going because I haven't heard anything new yet. This video is clearly not for me. Best of luck

Фото профиля Zack Korman
Zack Korman9 дней назад

As a general rule my videos about cybersecurity are for non-cyber people and my videos about not-cyber are for people in cyber.

Фото профиля darkmage
darkmage9 дней назад

This explains everything! You are filling a vital role.

Фото профиля Mona Lisa
Mona Lisa9 дней назад

We do, they work for the mossad

Фото профиля Shez Malik
Shez Malik9 дней назад

most of what gets u hacked is working as intended

Фото профиля learner
learner8 дней назад

We can’t. I’m pretty sure all Fortune 500 companies still have vulns from 200X

Фото профиля Jon Towles {MVP}
Jon Towles {MVP}5 дней назад

One could argue if you patch the vulnerabilities you’re safe for a little bit and then not again. Shit look at windows, just set a record for the most patches ever. It’s never finite. The complacency with a side of hubris is what actually gets you into trouble

Фото профиля Ryan McCormick
Ryan McCormick9 дней назад

I agree with most, we've always sucked at security & the answers have largely been available. But once there are no vulnerabilities it's all configuration. Configuration can be audited perpetually. The next phase is cryptographic certification of computation and capability.

Фото профиля Carl Sue
Carl Sue8 дней назад

Man, I'd love to debate you on this. I think we see the future similarly, but I disagree with pushing existing frameworks as they stand. They fill a gap now, but not all will be AI resilient, and I think the cybersecurity-as-a-department mindset might be short-lived.

Фото профиля Zack Korman
Zack Korman8 дней назад

What would you do instead

Фото профиля Carl Sue
Carl Sue8 дней назад

We can both agree on many of your points, especially for companies that have deployed a solution but not truly implemented a complete one. IMHO, the solution is not limited to using AI to get these things implemented properly. A better direction is to use some resources to keep tech debt at a reasonable level of degradation while pushing most resources toward building more correct capabilities. Everyone is in a different maturity on where bringing in AI makes the most sense, which is why the big players push threat modeling hardest for “security-focused models.” Reducing costs there lets companies identify the next area that can be modernized and either companies like yours will build for that gap or in a lot of cases I think the functionality will be built in house and slowly dissolve into other parts of the business. As an example it’s better to build say an autonomous credentials management system that reports into a security architect then fund an IAM service if you’re in a position that you have neither or a partially built environment and need to fill the gap.

Фото профиля CyberBox
CyberBox8 дней назад

@ZackKorman Agreed. Tool sprawl and shelfware stem from weak operational lifecycle. AI won't fix context. True ROI needs continuous posture validation, tight API orchestration, and detection engineering.

Фото профиля Carl Sue
Carl Sue8 дней назад

@ZackKorman It also needs investment into things like micro harnesses which adapt a workflow instead of just adding another tool. Simplify security while insisting on high standards.

Фото профиля Jonathan Yantis
Jonathan Yantis8 дней назад

The core risk I see at most enterprises is broad permission graphs and ease of lateral movements. A cyber critical model has near infinite paths to their goals once inside most enterprises.

Похожие видео