Cybersecurity, as I see it, is a rare field where offensive tools (as distinct from offensive artifacts) are good to have public and open sourced. Strong examples are Kali, Burp, Mimikatz.
The reasons include budget asymmetry between strong attackers and the average defenders, the requirement of using offensive tools to find improper defenses, and more.
It’s evident today, but based on my opinion, that recent trends show that having defenders and white-hat hackers having access to the best tooling will make the overall security of a lot of technological infrastructure more, not less, protected.
I see reasons why it’s good to have cybersecurity AI. But, I don’t see reason to particularly try to differentially accelerate it.
By default, I think AI capabilities are basically bad. There are good properties of having more capabilities of some types, but, in order to pass the high bar of “it’s good to accelerate AI capabilities”, they need to not just be useful, but, more useful to have sooner relative to other type of capabilities.
I think giving the world more time to adapt to the current level of AI cyber capabilities seems better than rushing to the next level.
Why is this good?
Cybersecurity, as I see it, is a rare field where offensive tools (as distinct from offensive artifacts) are good to have public and open sourced. Strong examples are Kali, Burp, Mimikatz.
The reasons include budget asymmetry between strong attackers and the average defenders, the requirement of using offensive tools to find improper defenses, and more.
It’s evident today, but based on my opinion, that recent trends show that having defenders and white-hat hackers having access to the best tooling will make the overall security of a lot of technological infrastructure more, not less, protected.
I see reasons why it’s good to have cybersecurity AI. But, I don’t see reason to particularly try to differentially accelerate it.
By default, I think AI capabilities are basically bad. There are good properties of having more capabilities of some types, but, in order to pass the high bar of “it’s good to accelerate AI capabilities”, they need to not just be useful, but, more useful to have sooner relative to other type of capabilities.
I think giving the world more time to adapt to the current level of AI cyber capabilities seems better than rushing to the next level.