Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <788cca6a-ac2a-491e-9050-c02227126330@dwheeler.com>
Date: Sat, 12 Sep 2026 14:11:32 -0400
From: "David A. Wheeler" <dwheeler@...eeler.com>
To: oss-security@...ts.openwall.com
Subject: Re: AI slops from Eve


On 9/11/26 06:13, Martin Hecht wrote:
> Our society strongly depends on connected IT systems comprising our 
> infrastructure nowadays. Now, these powerful algorithms are able to 
> find tons of vulnerabilities in software, and they are acting on the 
> same public internet to which many critical systems are connected.
>
> I'm concerned if we (the humanity) manage to close all those 
> vulnerabilities before these algorithms take over essential parts of 
> our infrastructure, or if we find ways to really contain the 
> algorithms reliably (which seems to be close to impossible, given the 
> fact that there are also bad actors around). Sorry for being slightly 
> off-topic, but I believe protecting critical IT systems as good as we 
> can will soon become more important than ever before.

I agree that protecting critical IT systems is important. But I think 
that's *always* been important. We should be protecting *all* IT 
systems, too. Way too many have thought "I won't get attacked" and then 
get successfully attacked.

Over the next few years AI-enabled attacks will be painful for many. AI 
makes attacks much cheaper, so attacks will greatly proliferate. 
However, AI also makes finding & fixing the vulnerabilities cheaper. 
Defenders will *NOT* be able to claim "I won't be attacked" (they 
already are), so they'll need to seriously find & fix vulnerabilitie. 
It's true that current AI systems aren't good at fixing *complex* 
vulnerabilities (1Password found a success rate of only 26.0%), but most 
vulnerabilities aren't complex, and humans can step in to fix complex 
vulnerabilities once they are *known* about.

Beyond these next few years, I think we're going to see systems become 
*dramatically* more secure. But it's going to be a rocky few years 
getting there.

The "rocky time" can easily be prepared for, though. I encourage 
everyone to do the following, assisted by AI:

1. Find & fix vulnerabilities.

2. Speed component update response. I argue this further here: 
https://www.linkedin.com/pulse/accelerate-deployment-vulnerability-tsunami-david-a-wheeler-eapge/

3. Harden systems so even break-ins will be less effective.

I'd encourage others to do the same. The "vulnpocalypse" is starting. 
Like many storms, if you're ready, it will be far less damaging. I look 
forward to the end-state: WAY more secure software.

--- David A. Wheeler


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.