Загрузка видео...
Не удалось загрузить видео
AI "cyber models" aren't going to solve our security problems. "If we just patch all the vulnerabilities then we're safe" is a convenient story but it's also not true. If you're worried about cybersecurity, the solution involves hard work, not just more tokens.
36,308 просмотров • 9 дней назад •via X (Twitter)
Комментарии: 49

but... hard work is hard!

This is the core problem isn’t it

I promise, I independently conceived this before I watched to where you said “GPT Zoolander.” Great minds… 🧠🤝🧠

Hahaha that’s amazing

Zack is actually a cyber model and you should all buy his pinup calendar

“I’ll show you what a cyber model really looks like”

"Paint me like one of those Mistral AI"

Nah, it's fine. When they go rouge, they just change colour. Harmless. We should really worry about when they go rogue, though.

That’d be kinda dope if they did

😉I know very well how rogue is spelled bc I've been playing pen&paper RPGs forever. It's also to my eternal regret not having put more effort into learning French at school when I had the chance. Oh, and I'm autistic. There's that, too.

lol sorry I missed the joke

You were busy paying attention to the important things. But there are niches in CS for folks like me and being pedantic is an advantage.

Unfortunately, the current security response seems to be like so:

This is extremely accurate and an extremely good fit. And honestly so painful to watch because it’s exactly how most security teams work

Hah thank you! The job of security involves work. Stunning news

It's the first thing companies does now. Instead of changing practices that lead to bugs, we rather call "cyber-llm scan .", close eyes and then fix those mistakes with the help of coding-llm. Rarely, we look back, adapt our coding practices, add more checks to CI, improve or introduce regular security practices that were established in the past.

Yea. “Just one more LLM bro. I promise it will fix it bro”

It costs shit ton of money. If it wasn't for sub, on a decent size codebase (150k loc) llm based application scan can cost to up to 2k USD using current models. That's what keeps companies from abusing it. I'm aware of that number cause I had to calculate it at work recently.

Part of the reason for the limited use is adoption. I believe they will be very good at things like risk and compliance. That is where we will really see an impact that reduces noise. Find all the bugs, and patch everything has never been a good strategy. Big picture correlation, assessment, and strategy is going to supercharge imo.

@techspence I mean I agree, but there are entire products that have to be built out to really support that (especially just getting the right data into the right place). And that isn't there yet, that I know of

@techspence A lot of companies are tackling IT debt, immature data gov, and security/privacy issues to get in position for AI. They aren’t ready. They don’t have the people with the AI skills.

Imagine if regular companies said "our cyber defenses are shit, let's hope we don't get hacked." Would you still trust them?

It’s all about the bloody secrets. The best models still do not solve fundamental problems. They have amplified it.

GRC bros in shambles

Hahah I gave them some credit!

Fair in your treatment, as usual.

Train your Pokémon’s

Agreed. And the most important piece (IMNSHO) is architecture: selecting what kinds of pieces you use and how they all fit together to meet the org’s requirements. LLMs seem to be pretty shit at this.

Yea a lot of orgs with horrible architectures are in trouble. A lot of orgs with good architecture are mostly fine even if they do a much worse job

ClaudeStrike wen

Oh my god that is admittedly a good name

Spending tokens is hard work though :D

Depends how poorly you spend them

I hard agree that the term "cyber model" makes no sense. I can see where your issue is now. The AI companies have usurped cyber security thrones and are now attempting to lord-over the discussion. On a political-level, this is definitely undesirable. Thats the first 1min32sec

3min in Sure, the cybersecurity field is broad and includes more than the "cyber models" typically are designed for. This nuance is understood and expected. The spearhead of defense is certainly offense, and the expectation is that great offense means great defense (IMHO)

4min in Not sure where this is going because I haven't heard anything new yet. This video is clearly not for me. Best of luck

As a general rule my videos about cybersecurity are for non-cyber people and my videos about not-cyber are for people in cyber.

This explains everything! You are filling a vital role.

We do, they work for the mossad

most of what gets u hacked is working as intended

We can’t. I’m pretty sure all Fortune 500 companies still have vulns from 200X

One could argue if you patch the vulnerabilities you’re safe for a little bit and then not again. Shit look at windows, just set a record for the most patches ever. It’s never finite. The complacency with a side of hubris is what actually gets you into trouble

I agree with most, we've always sucked at security & the answers have largely been available. But once there are no vulnerabilities it's all configuration. Configuration can be audited perpetually. The next phase is cryptographic certification of computation and capability.

Man, I'd love to debate you on this. I think we see the future similarly, but I disagree with pushing existing frameworks as they stand. They fill a gap now, but not all will be AI resilient, and I think the cybersecurity-as-a-department mindset might be short-lived.

What would you do instead

We can both agree on many of your points, especially for companies that have deployed a solution but not truly implemented a complete one. IMHO, the solution is not limited to using AI to get these things implemented properly. A better direction is to use some resources to keep tech debt at a reasonable level of degradation while pushing most resources toward building more correct capabilities. Everyone is in a different maturity on where bringing in AI makes the most sense, which is why the big players push threat modeling hardest for “security-focused models.” Reducing costs there lets companies identify the next area that can be modernized and either companies like yours will build for that gap or in a lot of cases I think the functionality will be built in house and slowly dissolve into other parts of the business. As an example it’s better to build say an autonomous credentials management system that reports into a security architect then fund an IAM service if you’re in a position that you have neither or a partially built environment and need to fill the gap.

@ZackKorman Agreed. Tool sprawl and shelfware stem from weak operational lifecycle. AI won't fix context. True ROI needs continuous posture validation, tight API orchestration, and detection engineering.

@ZackKorman It also needs investment into things like micro harnesses which adapt a workflow instead of just adding another tool. Simplify security while insisting on high standards.

The core risk I see at most enterprises is broad permission graphs and ease of lateral movements. A cyber critical model has near infinite paths to their goals once inside most enterprises.



