@luc I added a calendar reminder!
evan@cosocial.ca
Indlæg
-
Will the number of CVEs in 2031 be higher or lower than 2026? -
Will the number of CVEs in 2031 be higher or lower than 2026?I added a calendar event to remind myself to check.
-
Will the number of CVEs in 2031 be higher or lower than 2026?Anyway, my answer is: slightly lower. The backlog drains, scanning becomes an essential part of releasing software, so this huge rise flattens out and drops a bit.
-
Will the number of CVEs in 2031 be higher or lower than 2026?There are other factors at play, though. The fact that there are so many CVEs mean that people have needed to make filtered or curated lists. It's possible that over time those other reporting systems become more independent, eclipse the use of CVEs, and consequently people stop reporting CVEs as much. I don't think that process happens in the next 5 years, though.
-
Will the number of CVEs in 2031 be higher or lower than 2026?As I write this, I realize that we have already had a big change in how we make software, namely, the models themselves. I don't know how tractable an open-weight model like Gemma is to static analysis, especially for security issues. So, maybe we'll see more happening there.
-
Will the number of CVEs in 2031 be higher or lower than 2026?I think unless there is a big change in how we make and use software, the answer is no. Code complexity isn't an infinite resource; there is only so much interaction between components, lines of code, and external interfaces that can be tied together into an attack. As long as we make human readable, human sized code, there's a limit to how many security issues scanners can find.
-
Will the number of CVEs in 2031 be higher or lower than 2026?So, what about scanners getting better? We've just seen a big step up in reports mostly attributed to Fable. Won't better models find more and trickier bugs?
-
Will the number of CVEs in 2031 be higher or lower than 2026?I think this process will negate the problem with AI generated code. AI and human written code are both scannable.
-
Will the number of CVEs in 2031 be higher or lower than 2026?Doing AI security scans is automatable; I think it will become common to run in CI before releases or even on each Git commit.
As long as the same models are available to everyone, the blue team will have mostly the same tools as the red team.
-
Will the number of CVEs in 2031 be higher or lower than 2026?So, here's what I think: a rich vein of errors in legacy code is currently being mined by AI scanners. I think in 5 years that rich vein will be tapped out, and won't be as big of a factor.
-
Will the number of CVEs in 2031 be higher or lower than 2026?There are three reasons commonly cited:
- AI scanners are finding a lot of security issues
- AI code generators are making more mistakes
- New processes have made it easier to report issues -
Will the number of CVEs in 2031 be higher or lower than 2026?The number per year has been overwhelming for a while; they have shot up ~2-3x over the last year or so.
-
Will the number of CVEs in 2031 be higher or lower than 2026?CVEs are public reports of security issues, more or less.
https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures
-
Will the number of CVEs in 2031 be higher or lower than 2026?Thanks to everyone who responded. Here are my thoughts.
-
The AI Gigafactories call is now open.@HennaVirkkunen it's good to see Europe investing in digital sovereignty.
-
Will the number of CVEs in 2031 be higher or lower than 2026?Will the number of CVEs in 2031 be higher or lower than 2026?
-
What does "the Fediverse" mean?My work at #SWF and W3C is about making this network open to everyone, and encouraging implementers. I'm going to continue doing this.
Anyway, my answer: network.
-
What does "the Fediverse" mean?I don't like the tendency of some people to brigade projects or people they think are a threat to the culture. It's an ugly process. I was disappointed to see some of the replies to the #SiliconBeest post on Reddit, here:
-
What does "the Fediverse" mean?I understand people's concerns with protecting the culture, and I'm fine with people using the tools at hand to protect it -- like blocklists and defederation. If you think some software or some community is bad for the culture, you should use the tools available to protect it.
-
What does "the Fediverse" mean?I use "Fediverse" for both a network and a culture. I also use "ActivityPub network" or "Open social web" for the network itself. I think it's very important to make the network as open, permissionless, and connected as possible. Everyone on the planet has a right to be on that network.