Discussion about this post

User's avatar
richardstevenhack's avatar

When is the software industry going to start using AI to stop making vulnerabilities in code?

What I'm seeing are band-aids. "Oh, hey, it's all right, the vulnerability will never be executed."

Says who? We've got AIs now that can chain together vulnerabilities across an entire codebase that weren't discovered for the last ten years.

And smart hackers have been doing this for decades, and now have AIs to help them.

Plus studies have shown that AI-generated code is basically crap when it comes to security, not to mention maintainability, generating vulnerabilities at two or three times the level of crappy human programmers.

But both the software industry and the cybersecurity industry have now just thrown up their hands and are hiding behind "path analysis."

And that's not counting all the non-professional "vibe coders" who are cranking out Web and mobile apps with "no-code" utilities.

If the AI "doomsters" are ever going to be proven right, it's in this attitude.

Reminds me of the statement by the greatest philosopher of the 20th Century - Woody Allen - who summed up the human condition in five words: "Nothing works and nobody cares."

Shaun Lowry's avatar

Why not go one step further and add facilities to author VEX reports to include in SBOMs? https://cyclonedx.org/capabilities/vex/

No posts

Ready for more?