Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Will the number of CVEs in 2031 be higher or lower than 2026?

Will the number of CVEs in 2031 be higher or lower than 2026?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
evanpollpollpredictionscveinfosec
23 Indlæg 8 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • evan@cosocial.caE evan@cosocial.ca

    So, here's what I think: a rich vein of errors in legacy code is currently being mined by AI scanners. I think in 5 years that rich vein will be tapped out, and won't be as big of a factor.

    evan@cosocial.caE This user is from outside of this forum
    evan@cosocial.caE This user is from outside of this forum
    evan@cosocial.ca
    wrote sidst redigeret af
    #14

    Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.

    As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.

    evan@cosocial.caE spraoi@tooting.chS 2 Replies Last reply
    0
    • evan@cosocial.caE evan@cosocial.ca

      Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.

      As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.

      evan@cosocial.caE This user is from outside of this forum
      evan@cosocial.caE This user is from outside of this forum
      evan@cosocial.ca
      wrote sidst redigeret af
      #15

      I think this process will negate the problem with AI generated code. AI and human written code are both scannable.

      evan@cosocial.caE 1 Reply Last reply
      0
      • evan@cosocial.caE evan@cosocial.ca

        I think this process will negate the problem with AI generated code. AI and human written code are both scannable.

        evan@cosocial.caE This user is from outside of this forum
        evan@cosocial.caE This user is from outside of this forum
        evan@cosocial.ca
        wrote sidst redigeret af
        #16

        So, what about scanners getting better? We've just seen a big step up in reports mostly attributed to Fable. Won't better models find more and trickier bugs?

        evan@cosocial.caE 1 Reply Last reply
        0
        • evan@cosocial.caE evan@cosocial.ca

          So, what about scanners getting better? We've just seen a big step up in reports mostly attributed to Fable. Won't better models find more and trickier bugs?

          evan@cosocial.caE This user is from outside of this forum
          evan@cosocial.caE This user is from outside of this forum
          evan@cosocial.ca
          wrote sidst redigeret af
          #17

          I think unless there is a big change in how we make and use software, the answer is no. Code complexity isn't an infinite resource; there is only so much interaction between components, lines of code, and external interfaces that can be tied together into an attack. As long as we make human readable, human sized code, there's a limit to how many security issues scanners can find.

          evan@cosocial.caE 1 Reply Last reply
          0
          • evan@cosocial.caE evan@cosocial.ca

            I think unless there is a big change in how we make and use software, the answer is no. Code complexity isn't an infinite resource; there is only so much interaction between components, lines of code, and external interfaces that can be tied together into an attack. As long as we make human readable, human sized code, there's a limit to how many security issues scanners can find.

            evan@cosocial.caE This user is from outside of this forum
            evan@cosocial.caE This user is from outside of this forum
            evan@cosocial.ca
            wrote sidst redigeret af
            #18

            As I write this, I realize that we have already had a big change in how we make software, namely, the models themselves. I don't know how tractable an open-weight model like Gemma is to static analysis, especially for security issues. So, maybe we'll see more happening there.

            evan@cosocial.caE 1 Reply Last reply
            0
            • evan@cosocial.caE evan@cosocial.ca

              As I write this, I realize that we have already had a big change in how we make software, namely, the models themselves. I don't know how tractable an open-weight model like Gemma is to static analysis, especially for security issues. So, maybe we'll see more happening there.

              evan@cosocial.caE This user is from outside of this forum
              evan@cosocial.caE This user is from outside of this forum
              evan@cosocial.ca
              wrote sidst redigeret af
              #19

              There are other factors at play, though. The fact that there are so many CVEs mean that people have needed to make filtered or curated lists. It's possible that over time those other reporting systems become more independent, eclipse the use of CVEs, and consequently people stop reporting CVEs as much. I don't think that process happens in the next 5 years, though.

              evan@cosocial.caE 1 Reply Last reply
              0
              • evan@cosocial.caE evan@cosocial.ca

                There are other factors at play, though. The fact that there are so many CVEs mean that people have needed to make filtered or curated lists. It's possible that over time those other reporting systems become more independent, eclipse the use of CVEs, and consequently people stop reporting CVEs as much. I don't think that process happens in the next 5 years, though.

                evan@cosocial.caE This user is from outside of this forum
                evan@cosocial.caE This user is from outside of this forum
                evan@cosocial.ca
                wrote sidst redigeret af
                #20

                Anyway, my answer is: slightly lower. The backlog drains, scanning becomes an essential part of releasing software, so this huge rise flattens out and drops a bit.

                evan@cosocial.caE 1 Reply Last reply
                0
                • evan@cosocial.caE evan@cosocial.ca

                  Anyway, my answer is: slightly lower. The backlog drains, scanning becomes an essential part of releasing software, so this huge rise flattens out and drops a bit.

                  evan@cosocial.caE This user is from outside of this forum
                  evan@cosocial.caE This user is from outside of this forum
                  evan@cosocial.ca
                  wrote sidst redigeret af
                  #21

                  I added a calendar event to remind myself to check.

                  1 Reply Last reply
                  0
                  • luc@chaos.socialL luc@chaos.social

                    @evan will you tag us in 2031 to see if we got it right?

                    evan@cosocial.caE This user is from outside of this forum
                    evan@cosocial.caE This user is from outside of this forum
                    evan@cosocial.ca
                    wrote sidst redigeret af
                    #22

                    @luc I added a calendar reminder!

                    1 Reply Last reply
                    0
                    • evan@cosocial.caE evan@cosocial.ca

                      Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.

                      As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.

                      spraoi@tooting.chS This user is from outside of this forum
                      spraoi@tooting.chS This user is from outside of this forum
                      spraoi@tooting.ch
                      wrote sidst redigeret af
                      #23

                      @evan

                      AI security scans are also vulnerable to prompt injection. Portswigger have some cool labs based on a vulnerable AI scanner.

                      1 Reply Last reply
                      0
                      Svar
                      • Svar som emne
                      Login for at svare
                      • Ældste til nyeste
                      • Nyeste til ældste
                      • Most Votes


                      • Log ind

                      • Har du ikke en konto? Tilmeld

                      • Login or register to search.
                      Powered by NodeBB Contributors
                      Graciously hosted by data.coop
                      • First post
                        Last post
                      0
                      • Hjem
                      • Seneste
                      • Etiketter
                      • Populære
                      • Verden
                      • Bruger
                      • Grupper