Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Will the number of CVEs in 2031 be higher or lower than 2026?

Will the number of CVEs in 2031 be higher or lower than 2026?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
evanpollpollpredictionscveinfosec
23 Indlæg 8 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • evan@cosocial.caE evan@cosocial.ca

    Will the number of CVEs in 2031 be higher or lower than 2026?

    https://www.cve.org/about/Metrics

    #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

    spraoi@tooting.chS This user is from outside of this forum
    spraoi@tooting.chS This user is from outside of this forum
    spraoi@tooting.ch
    wrote sidst redigeret af
    #2

    @evan

    I think it will peak in 2027 or 2028.

    1 Reply Last reply
    0
    • evan@cosocial.caE evan@cosocial.ca

      Will the number of CVEs in 2031 be higher or lower than 2026?

      https://www.cve.org/about/Metrics

      #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

      M This user is from outside of this forum
      M This user is from outside of this forum
      monnier@oldbytes.space
      wrote sidst redigeret af
      #3

      @evan It will be a secret because it will have been bought out by GAFAM which will sell streaming access via subscriptions to specific channels

      1 Reply Last reply
      0
      • evan@cosocial.caE evan@cosocial.ca

        Will the number of CVEs in 2031 be higher or lower than 2026?

        https://www.cve.org/about/Metrics

        #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

        johnefrancis@cosocial.caJ This user is from outside of this forum
        johnefrancis@cosocial.caJ This user is from outside of this forum
        johnefrancis@cosocial.ca
        wrote sidst redigeret af
        #4

        @evan it will be a time of great disruption, and change brings CVE's.

        1 Reply Last reply
        0
        • evan@cosocial.caE evan@cosocial.ca

          Will the number of CVEs in 2031 be higher or lower than 2026?

          https://www.cve.org/about/Metrics

          #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

          luc@chaos.socialL This user is from outside of this forum
          luc@chaos.socialL This user is from outside of this forum
          luc@chaos.social
          wrote sidst redigeret af
          #5

          @evan will you tag us in 2031 to see if we got it right?

          evan@cosocial.caE 1 Reply Last reply
          0
          • evan@cosocial.caE evan@cosocial.ca

            Will the number of CVEs in 2031 be higher or lower than 2026?

            https://www.cve.org/about/Metrics

            #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

            jamesmarshall@sfba.socialJ This user is from outside of this forum
            jamesmarshall@sfba.socialJ This user is from outside of this forum
            jamesmarshall@sfba.social
            wrote sidst redigeret af
            #6

            @evan I think the number of vulnerabilities created by "AI" will be greater than the number of vulnerabilities found or fixed by "AI".

            1 Reply Last reply
            0
            • evan@cosocial.caE evan@cosocial.ca

              Will the number of CVEs in 2031 be higher or lower than 2026?

              https://www.cve.org/about/Metrics

              #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

              plumbert@thecanadian.socialP This user is from outside of this forum
              plumbert@thecanadian.socialP This user is from outside of this forum
              plumbert@thecanadian.social
              wrote sidst redigeret af
              #7

              @evan Much lower, perhaps
              0.

              The entire CVE system will be overwhelmed by the amount of slop generated crapware that it will collapse before 2031. In addition, AI companies will sue researchers for publishing what are perceived as "negative statements" about their software, and the resulting fear and loathing will eliminate the last remaining publication of vulnerabilities.

              1 Reply Last reply
              0
              • evan@cosocial.caE evan@cosocial.ca

                Will the number of CVEs in 2031 be higher or lower than 2026?

                https://www.cve.org/about/Metrics

                #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

                evan@cosocial.caE This user is from outside of this forum
                evan@cosocial.caE This user is from outside of this forum
                evan@cosocial.ca
                wrote sidst redigeret af
                #8

                Thanks to everyone who responded. Here are my thoughts.

                evan@cosocial.caE 1 Reply Last reply
                0
                • evan@cosocial.caE evan@cosocial.ca

                  Will the number of CVEs in 2031 be higher or lower than 2026?

                  https://www.cve.org/about/Metrics

                  #EvanPoll #poll #predictions #cve #infosec #disclosure #ai

                  josh@hactivedirectory.comJ This user is from outside of this forum
                  josh@hactivedirectory.comJ This user is from outside of this forum
                  josh@hactivedirectory.com
                  wrote sidst redigeret af
                  #9

                  @evan Faulty question: assumes we will get to 2031.

                  1 Reply Last reply
                  0
                  • evan@cosocial.caE evan@cosocial.ca

                    Thanks to everyone who responded. Here are my thoughts.

                    evan@cosocial.caE This user is from outside of this forum
                    evan@cosocial.caE This user is from outside of this forum
                    evan@cosocial.ca
                    wrote sidst redigeret af
                    #10

                    CVEs are public reports of security issues, more or less.

                    https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures

                    evan@cosocial.caE 1 Reply Last reply
                    0
                    • evan@cosocial.caE evan@cosocial.ca

                      CVEs are public reports of security issues, more or less.

                      https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures

                      evan@cosocial.caE This user is from outside of this forum
                      evan@cosocial.caE This user is from outside of this forum
                      evan@cosocial.ca
                      wrote sidst redigeret af
                      #11

                      The number per year has been overwhelming for a while; they have shot up ~2-3x over the last year or so.

                      https://www.cve.org/about/Metrics

                      evan@cosocial.caE 1 Reply Last reply
                      0
                      • evan@cosocial.caE evan@cosocial.ca

                        The number per year has been overwhelming for a while; they have shot up ~2-3x over the last year or so.

                        https://www.cve.org/about/Metrics

                        evan@cosocial.caE This user is from outside of this forum
                        evan@cosocial.caE This user is from outside of this forum
                        evan@cosocial.ca
                        wrote sidst redigeret af
                        #12

                        There are three reasons commonly cited:

                        - AI scanners are finding a lot of security issues
                        - AI code generators are making more mistakes
                        - New processes have made it easier to report issues

                        evan@cosocial.caE 1 Reply Last reply
                        0
                        • evan@cosocial.caE evan@cosocial.ca

                          There are three reasons commonly cited:

                          - AI scanners are finding a lot of security issues
                          - AI code generators are making more mistakes
                          - New processes have made it easier to report issues

                          evan@cosocial.caE This user is from outside of this forum
                          evan@cosocial.caE This user is from outside of this forum
                          evan@cosocial.ca
                          wrote sidst redigeret af
                          #13

                          So, here's what I think: a rich vein of errors in legacy code is currently being mined by AI scanners. I think in 5 years that rich vein will be tapped out, and won't be as big of a factor.

                          evan@cosocial.caE 1 Reply Last reply
                          0
                          • evan@cosocial.caE evan@cosocial.ca

                            So, here's what I think: a rich vein of errors in legacy code is currently being mined by AI scanners. I think in 5 years that rich vein will be tapped out, and won't be as big of a factor.

                            evan@cosocial.caE This user is from outside of this forum
                            evan@cosocial.caE This user is from outside of this forum
                            evan@cosocial.ca
                            wrote sidst redigeret af
                            #14

                            Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.

                            As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.

                            evan@cosocial.caE spraoi@tooting.chS 2 Replies Last reply
                            0
                            • evan@cosocial.caE evan@cosocial.ca

                              Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.

                              As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.

                              evan@cosocial.caE This user is from outside of this forum
                              evan@cosocial.caE This user is from outside of this forum
                              evan@cosocial.ca
                              wrote sidst redigeret af
                              #15

                              I think this process will negate the problem with AI generated code. AI and human written code are both scannable.

                              evan@cosocial.caE 1 Reply Last reply
                              0
                              • evan@cosocial.caE evan@cosocial.ca

                                I think this process will negate the problem with AI generated code. AI and human written code are both scannable.

                                evan@cosocial.caE This user is from outside of this forum
                                evan@cosocial.caE This user is from outside of this forum
                                evan@cosocial.ca
                                wrote sidst redigeret af
                                #16

                                So, what about scanners getting better? We've just seen a big step up in reports mostly attributed to Fable. Won't better models find more and trickier bugs?

                                evan@cosocial.caE 1 Reply Last reply
                                0
                                • evan@cosocial.caE evan@cosocial.ca

                                  So, what about scanners getting better? We've just seen a big step up in reports mostly attributed to Fable. Won't better models find more and trickier bugs?

                                  evan@cosocial.caE This user is from outside of this forum
                                  evan@cosocial.caE This user is from outside of this forum
                                  evan@cosocial.ca
                                  wrote sidst redigeret af
                                  #17

                                  I think unless there is a big change in how we make and use software, the answer is no. Code complexity isn't an infinite resource; there is only so much interaction between components, lines of code, and external interfaces that can be tied together into an attack. As long as we make human readable, human sized code, there's a limit to how many security issues scanners can find.

                                  evan@cosocial.caE 1 Reply Last reply
                                  0
                                  • evan@cosocial.caE evan@cosocial.ca

                                    I think unless there is a big change in how we make and use software, the answer is no. Code complexity isn't an infinite resource; there is only so much interaction between components, lines of code, and external interfaces that can be tied together into an attack. As long as we make human readable, human sized code, there's a limit to how many security issues scanners can find.

                                    evan@cosocial.caE This user is from outside of this forum
                                    evan@cosocial.caE This user is from outside of this forum
                                    evan@cosocial.ca
                                    wrote sidst redigeret af
                                    #18

                                    As I write this, I realize that we have already had a big change in how we make software, namely, the models themselves. I don't know how tractable an open-weight model like Gemma is to static analysis, especially for security issues. So, maybe we'll see more happening there.

                                    evan@cosocial.caE 1 Reply Last reply
                                    0
                                    • evan@cosocial.caE evan@cosocial.ca

                                      As I write this, I realize that we have already had a big change in how we make software, namely, the models themselves. I don't know how tractable an open-weight model like Gemma is to static analysis, especially for security issues. So, maybe we'll see more happening there.

                                      evan@cosocial.caE This user is from outside of this forum
                                      evan@cosocial.caE This user is from outside of this forum
                                      evan@cosocial.ca
                                      wrote sidst redigeret af
                                      #19

                                      There are other factors at play, though. The fact that there are so many CVEs mean that people have needed to make filtered or curated lists. It's possible that over time those other reporting systems become more independent, eclipse the use of CVEs, and consequently people stop reporting CVEs as much. I don't think that process happens in the next 5 years, though.

                                      evan@cosocial.caE 1 Reply Last reply
                                      0
                                      • evan@cosocial.caE evan@cosocial.ca

                                        There are other factors at play, though. The fact that there are so many CVEs mean that people have needed to make filtered or curated lists. It's possible that over time those other reporting systems become more independent, eclipse the use of CVEs, and consequently people stop reporting CVEs as much. I don't think that process happens in the next 5 years, though.

                                        evan@cosocial.caE This user is from outside of this forum
                                        evan@cosocial.caE This user is from outside of this forum
                                        evan@cosocial.ca
                                        wrote sidst redigeret af
                                        #20

                                        Anyway, my answer is: slightly lower. The backlog drains, scanning becomes an essential part of releasing software, so this huge rise flattens out and drops a bit.

                                        evan@cosocial.caE 1 Reply Last reply
                                        0
                                        • evan@cosocial.caE evan@cosocial.ca

                                          Anyway, my answer is: slightly lower. The backlog drains, scanning becomes an essential part of releasing software, so this huge rise flattens out and drops a bit.

                                          evan@cosocial.caE This user is from outside of this forum
                                          evan@cosocial.caE This user is from outside of this forum
                                          evan@cosocial.ca
                                          wrote sidst redigeret af
                                          #21

                                          I added a calendar event to remind myself to check.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper