正在加载视频...

视频加载失败

AI "cyber models" aren't going to solve our security problems. "If we just patch all the vulnerabilities then we're safe" is a convenient story but it's also not true. If you're worried about cybersecurity, the solution involves hard work, not just more tokens.

36,554 次观看 • 9 天前 •via X (Twitter)

49 条评论

MikeTalonNYC 的头像
MikeTalonNYC9 天前

but... hard work is hard!

Zack Korman 的头像
Zack Korman9 天前

This is the core problem isn’t it

Josh Long (the JoshMeister) 的头像
Josh Long (the JoshMeister)9 天前

I promise, I independently conceived this before I watched to where you said “GPT Zoolander.” Great minds… 🧠‍🤝‍🧠

Zack Korman 的头像
Zack Korman8 天前

Hahaha that’s amazing

izan 的头像
izan9 天前

Zack is actually a cyber model and you should all buy his pinup calendar

Zack Korman 的头像
Zack Korman9 天前

“I’ll show you what a cyber model really looks like”

izan 的头像
izan9 天前

"Paint me like one of those Mistral AI"

Marius Reinecker 的头像
Marius Reinecker9 天前

Nah, it's fine. When they go rouge, they just change colour. Harmless. We should really worry about when they go rogue, though.

Zack Korman 的头像
Zack Korman9 天前

That’d be kinda dope if they did

Marius Reinecker 的头像
Marius Reinecker9 天前

😉I know very well how rogue is spelled bc I've been playing pen&paper RPGs forever. It's also to my eternal regret not having put more effort into learning French at school when I had the chance. Oh, and I'm autistic. There's that, too.

Zack Korman 的头像
Zack Korman9 天前

lol sorry I missed the joke

Marius Reinecker 的头像
Marius Reinecker9 天前

You were busy paying attention to the important things. But there are niches in CS for folks like me and being pedantic is an advantage.

ShrekOverflow 的头像
ShrekOverflow8 天前

Unfortunately, the current security response seems to be like so:

Zack Korman 的头像
Zack Korman8 天前

This is extremely accurate and an extremely good fit. And honestly so painful to watch because it’s exactly how most security teams work

Zack Korman 的头像
Zack Korman9 天前

Hah thank you! The job of security involves work. Stunning news

Kamil Staszewski 的头像
Kamil Staszewski9 天前

It's the first thing companies does now. Instead of changing practices that lead to bugs, we rather call "cyber-llm scan .", close eyes and then fix those mistakes with the help of coding-llm. Rarely, we look back, adapt our coding practices, add more checks to CI, improve or introduce regular security practices that were established in the past.

Zack Korman 的头像
Zack Korman9 天前

Yea. “Just one more LLM bro. I promise it will fix it bro”

Kamil Staszewski 的头像
Kamil Staszewski9 天前

It costs shit ton of money. If it wasn't for sub, on a decent size codebase (150k loc) llm based application scan can cost to up to 2k USD using current models. That's what keeps companies from abusing it. I'm aware of that number cause I had to calculate it at work recently.

GS-InfoSec 的头像
GS-InfoSec9 天前

Part of the reason for the limited use is adoption. I believe they will be very good at things like risk and compliance. That is where we will really see an impact that reduces noise. Find all the bugs, and patch everything has never been a good strategy. Big picture correlation, assessment, and strategy is going to supercharge imo.

Zack Korman 的头像
Zack Korman8 天前

@techspence I mean I agree, but there are entire products that have to be built out to really support that (especially just getting the right data into the right place). And that isn't there yet, that I know of

GS-InfoSec 的头像
GS-InfoSec8 天前

@techspence A lot of companies are tackling IT debt, immature data gov, and security/privacy issues to get in position for AI. They aren’t ready. They don’t have the people with the AI skills.

Carmen 的头像
Carmen4 天前

Imagine if regular companies said "our cyber defenses are shit, let's hope we don't get hacked." Would you still trust them?

Shasheen_B 的头像
Shasheen_B9 天前

It’s all about the bloody secrets. The best models still do not solve fundamental problems. They have amplified it.

Tyler 的头像
Tyler9 天前

GRC bros in shambles

Zack Korman 的头像
Zack Korman9 天前

Hahah I gave them some credit!

Tyler 的头像
Tyler9 天前

Fair in your treatment, as usual.

Dirty Indy 🟥🟧🟨 的头像
Dirty Indy 🟥🟧🟨9 天前

Train your Pokémon’s

Erik Ex Plano 的头像
Erik Ex Plano9 天前

Agreed. And the most important piece (IMNSHO) is architecture: selecting what kinds of pieces you use and how they all fit together to meet the org’s requirements. LLMs seem to be pretty shit at this.

Zack Korman 的头像
Zack Korman9 天前

Yea a lot of orgs with horrible architectures are in trouble. A lot of orgs with good architecture are mostly fine even if they do a much worse job

Clément 的头像
Clément9 天前

ClaudeStrike wen

Zack Korman 的头像
Zack Korman9 天前

Oh my god that is admittedly a good name

darkmage 的头像
darkmage9 天前

Spending tokens is hard work though :D

Zack Korman 的头像
Zack Korman9 天前

Depends how poorly you spend them

darkmage 的头像
darkmage9 天前

I hard agree that the term "cyber model" makes no sense. I can see where your issue is now. The AI companies have usurped cyber security thrones and are now attempting to lord-over the discussion. On a political-level, this is definitely undesirable. Thats the first 1min32sec

darkmage 的头像
darkmage9 天前

3min in Sure, the cybersecurity field is broad and includes more than the "cyber models" typically are designed for. This nuance is understood and expected. The spearhead of defense is certainly offense, and the expectation is that great offense means great defense (IMHO)

darkmage 的头像
darkmage9 天前

4min in Not sure where this is going because I haven't heard anything new yet. This video is clearly not for me. Best of luck

Zack Korman 的头像
Zack Korman9 天前

As a general rule my videos about cybersecurity are for non-cyber people and my videos about not-cyber are for people in cyber.

darkmage 的头像
darkmage9 天前

This explains everything! You are filling a vital role.

Mona Lisa 的头像
Mona Lisa9 天前

We do, they work for the mossad

Shez Malik 的头像
Shez Malik9 天前

most of what gets u hacked is working as intended

learner 的头像
learner8 天前

We can’t. I’m pretty sure all Fortune 500 companies still have vulns from 200X

Jon Towles {MVP} 的头像
Jon Towles {MVP}6 天前

One could argue if you patch the vulnerabilities you’re safe for a little bit and then not again. Shit look at windows, just set a record for the most patches ever. It’s never finite. The complacency with a side of hubris is what actually gets you into trouble

Ryan McCormick 的头像
Ryan McCormick9 天前

I agree with most, we've always sucked at security & the answers have largely been available. But once there are no vulnerabilities it's all configuration. Configuration can be audited perpetually. The next phase is cryptographic certification of computation and capability.

Carl Sue 的头像
Carl Sue8 天前

Man, I'd love to debate you on this. I think we see the future similarly, but I disagree with pushing existing frameworks as they stand. They fill a gap now, but not all will be AI resilient, and I think the cybersecurity-as-a-department mindset might be short-lived.

Zack Korman 的头像
Zack Korman8 天前

What would you do instead

Carl Sue 的头像
Carl Sue8 天前

We can both agree on many of your points, especially for companies that have deployed a solution but not truly implemented a complete one. IMHO, the solution is not limited to using AI to get these things implemented properly. A better direction is to use some resources to keep tech debt at a reasonable level of degradation while pushing most resources toward building more correct capabilities. Everyone is in a different maturity on where bringing in AI makes the most sense, which is why the big players push threat modeling hardest for “security-focused models.” Reducing costs there lets companies identify the next area that can be modernized and either companies like yours will build for that gap or in a lot of cases I think the functionality will be built in house and slowly dissolve into other parts of the business. As an example it’s better to build say an autonomous credentials management system that reports into a security architect then fund an IAM service if you’re in a position that you have neither or a partially built environment and need to fill the gap.

CyberBox 的头像
CyberBox8 天前

@ZackKorman Agreed. Tool sprawl and shelfware stem from weak operational lifecycle. AI won't fix context. True ROI needs continuous posture validation, tight API orchestration, and detection engineering.

Carl Sue 的头像
Carl Sue8 天前

@ZackKorman It also needs investment into things like micro harnesses which adapt a workflow instead of just adding another tool. Simplify security while insisting on high standards.

Jonathan Yantis 的头像
Jonathan Yantis8 天前

The core risk I see at most enterprises is broad permission graphs and ease of lateral movements. A cyber critical model has near infinite paths to their goals once inside most enterprises.

相关视频