Steven Sinofsky 与 Aaron Levie 对谈:Agent 集群将冲击企业安全模型
Box 的 Levie 和 Sinofsky 聊了 Agent 集群怎么把企业安全打穿, swarm 像 DoS 攻击这个角度很少见,聊得挺具体。
a16z 播客中,Box CEO Aaron Levie 与 Steven Sinofsky 讨论企业安全依赖一个假设:员工 95% 到 99% 的时间会做正确的事。Sinofsky 指出 Agent 集群不疲倦、不厌倦,会以极短时间尝试所有请求路径,行为上酷似拒绝服务攻击,企业从未设防内部 GitHub、Slack 或财务报销工具会遭遇此类冲击。Levie 认为这意味着权限、身份认证和整个安全栈需要大规模升级。两人还讨论了「We Must Pace the Frontier」监管议题、2028 年的 AI 选举,以及 Noam Brown 提出的热隐写信息泄露设想。
Steven Sinofsky and Aaron Levie on the assumption behind enterprise security: people do the right thing 99% of the time, and agents are about to break it. Steven: "What AI can do is try all of those things in a very short time. It doesn't get tired. It doesn't get bored." "You now have to look at every single API and every single service you're running internally on your network." "Nobody thinks their internal GitHub, internal Slack, or internal finance expense tool is vulnerable to a denial-of-service attack. But swarms literally look like a denial-of-service attack." "Now we need a whole layer internally that is tracking way more about what authentications are being done and what APIs are being done." Aaron: "You kind of got by with information security on the fact that most people will do the right thing 95% to 99% of the time." "All these systems are basically open to whoever wants to access them, or one tap on the shoulder and then you have access." "Agent swarms completely flip that because these are roaming drones, times 10,000. They don't get bored. They will easily mistake a good task for a bad one and vice versa. The data security in our systems is going to have a huge upgrade moment." @stevesi @levie Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z Box CEO Aaron Levie, Steven Sinofsky, and Martin Casado join Erik Torenberg to discuss "We Must Pace the Frontier," the upcoming AI election in 2028, and Jev: They argue that most of today's AI regulation debate is happening before anyone has defined the risks being regulated. Every prior wave, from computer viruses to aviation, built its safety standards after learning how the technology actually failed. Then it gets concrete. Agents don't get tired, run at enormous scale, and probe systems in ways employees never could, which may mean rethinking permissions, authentication, and the security stack itself. They close on why AI innovation may increasingly happen outside the frontier labs, in the software built around the models. 00:50 "We Must Pace the Frontier" 03:50 Do the labs believe their own x-risk talk? 06:49 If it's existential, nationalize it 11:32 "You're asking us to regulate you?" 12:08 2028 as the AI election 18:50 Tech never learned to navigate regulation 25:50 The law that came from one 1983 hack 28:39 Noam Brown's heat exfiltration idea 32:30 Cold War covert channel stories 34:35 Agent swarms look like a DoS attack 41:25 Sinofsky's fear: GDPR for AI 46:20 No jets if the FAA started in 1910 48:38 Jev: decision engines vs. chatbots 53:01 Labs build beings, software needs tools YouTube: youtu.be/TLJNJDf2XGo @levie @stevesi @martin_casado @eriktorenberg Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 4 🔄 3 ❤️ 7 👀 5666 📊 4 ⚡