About this entire AI security scanning thing:
1. Why are people using $ spent as a metric?
2. A huge chunk of these vulnerabilities are likely hallucinated and/or overstated
3. You can’t just point AI at a pile of files and expect good results
Login to reply
Replies (18)
Dollars spent = virtue signalled.
$ spent is also the metric is useful when comparing to security audits and bug bounty programs (sadly already a low bar)
overstated or exagerating the impact of bugs are a thing for sure, it is still a useful tool to use can be useful as a starting point. But requires a human to verify vulns and give it a real cve rating
Third point is absolutely right, but you can train the modela and give the harness the right tooling to do the job of a team of junior vulnerability researchers
* just my 2 sats trying to use the clankers for bug hunting during the react2shell and shai-hulud disclosures
Bill Gates and pals peddling flawed AI for profit, exploiting ignorance, and fueling hype.
Well a harness that wastes tokens is a great way to maximize money spent
I think cost of outcome matters, not cost alone. $100k is a lot for a bottle of milk, but not that lot for a house.
I dunno...the "I have a hunch" way of doing things might be popular for a while... on the good and the bad sides. A hallucinated vulnerability... won't be safe for long,
Yup people who are getting excited have probably never used an ai agent lol.
They want to save their asses because these clowns were shill coldcards a week ago and now fear a law suit.
I doubt they even spent $5000 of the claimed 20k. Anchor watch is a broke business with no clients. They basically admitted this by saying no one of their clients has claimed under their insurance.
"Agree, flawed metrics. Reminds me of flawed nutrition metrics, like focusing on calories over nutrient density."
agreed, but if provides at least some actionable remediation to even a 1/10th of the vulns it 'discovers' it still worth the cost
once dust settle a $/critical cve patched price will be distilled from redteam work, I think it is money well spent... albeit a bit rushed considering the epic fail of coinkite CTO
The voice of reason
Anything can be a critical CVE if you exaggerate it enough
A researcher can describe it as critical in text
But CVE scoring has a real methodology with various frameworks and takes time to do properly, just have a look at the NIST CVSS calculator
A valid critical 9+ cve score is more science than propaganda
can it be that some of the redteam's critical vulnerabilities found are actually 7 or 8 cve? yes possible, but those are sill valid vulns to patch
NVD - CVSS v3 Calculator
here is a current example that just popped up in my nostr feed
It does not take time to do CVSS scoring, and the CVSS scoring system is known to have issues many issues anyway.
1. Scores are often much lower or higher than they should be.
2. It is possible to easily over- or understate the impact of a vulnerability, intentionally or not.
3. Whether the vulnerability is actively exploitable is another question.
After NIST had slowed down enrichment of CVEs, and many other safeguards broke, anyone can now go and issue a CVE for a project without any verification.
SQLite User Forum: Fake CVEs against SQLite
1000%
also NIST funding not being renewed did cause chaos in the ecosystem, I agree it is not perfect
In my experience with using AI, it at best amplifies the existing skills of the user. If the user had no prior experience with the task at hand, the user will not be able to distinguish the good from the bad when the AI completed the task.