行业

AI安全漏洞修复创纪录,软件安全状况持续改善

I think this take on AI and security is correct. Less doom. More AI optimism is possible wrt jobs se...

精选理由

微软AI发现近千漏洞,证明AI正在解决而非加剧安全问题,软件安全状况正持续改善。

微软本月修复了974个安全漏洞,几乎全部由AI系统发现。这些漏洞数量创历史新高,但并非AI安全危机的信号。软件代码行数有限,漏洞数量也是有限的,AI正在快速清除长期存在的安全隐患。未来几年,形式化验证技术将进一步提升软件安全性。

图片来源 · Richard Socher
原文 · Richard Socher

I think this take on AI and security is correct. Less doom. More AI optimism is possible wrt jobs se...

I think this take on AI and security is correct. Less doom. More AI optimism is possible wrt jobs security etc. Wrote about this AI safety paradox here: socher.org/thoughts/ai-sa… Perry E. Metzger @perrymetzger Yesterday, Microsoft's monthly Patch Tuesday had fixes for 974 security vulnerabilities, almost all of them found by AI systems. That's a ridiculously large number, a new record by far in fact. Does this mean we're seeing some sort of AI security apocalypse? No, quite the opposite. It means that we're finally clearing out the vast number of security holes that have been lurking all this time in our software. The Doomer view is that this will continue without end, and that if you keep getting smarter AI systems they will *always* find new bugs. That's simply untrue; it implies that all software has an *infinite* number of security holes, but a program with a finite number of lines of code simply cannot have an infinite number of vulnerabilities. What we actually have is a large but limited pool of problems, and the AI systems are rapidly finding them. Eventually, and eventually isn't that far off, the well is going to start drying up. It will get harder and harder to find new security holes. Over the next few years, we will also start doing formal verification of software, that is, mathematically proving that the software lacks bugs of certain sorts. (AIs turn out to be very good at formally proving things.) So, what's happening is *good*. We are rapidly finding bugs that have been lurking for years and sometimes decades, and we're removing them, and newly built software will get AI examination and will be much less likely to have security vulnerabilities in the first place. The situation is getting better, not worse, and it's getting better rapidly. We have been in a continuous computer security crisis since the Morris Worm in 1988. We are finally starting to climb out of it, thanks to AI. This is not a tragedy at all. 🔗 View Quoted Tweet 💬 4 🔄 2 ❤️ 9 👀 1613 📊 4 ⚡