←back to thread

1160 points vxvxvx | 1 comments | | HN request time: 0s | source

Earlier thread: Disrupting the first reported AI-orchestrated cyber espionage campaign - https://news.ycombinator.com/item?id=45918638 - Nov 2025 (281 comments)
Show context
Dumblydorr ◴[] No.45944576[source]
What would AGI actually mean for security? Does it heavily favor attackers or defenders? Even LLM, it may not help much in defense but it could teach attackers a lot right? What if employees gave the LLM info during their use that attackers could then get re-fed and study?
replies(5): >>45944728 #>>45944777 #>>45944885 #>>45944905 #>>45945127 #
ACCount37 ◴[] No.45944885[source]
AGI favors attackers initially. Because while it can be used defensively, to preemptively scan for vulns, harden exposed software for cheaper and monitor the networks for intrusion at all times, how many companies are going to start doing that fast enough to counter the cutting edge AGI-enabled attackers probing every piece of their infra for vulns at scale?

It's like a very very big fat stack of zero days leaking to the public. Sure, they'll all get fixed eventually, and everyone will update, eventually. But until that happens, the usual suspects are going to have a field day.

It may come to favor defense in the long term. But it's AGI. If that tech lands, the "long term" may not exist.

replies(1): >>45945224 #
PunchyHamster ◴[] No.45945224[source]
Defending is much, much harder than attacking for humans, I'd extrapolate that to AI/AGIs.

Defender needs to get everything right, attacker needs to get one thing right.

replies(2): >>45945536 #>>45947450 #
1. ACCount37 ◴[] No.45945536[source]
But security advancements scale.

On average, today's systems are much more secure than those from year 2005. Because the known vulns from those days got patched, and methodologies improved enough that they weren't replaced by newer vulns 1:1.

This is what allows defenders to keep up with the attackers long term. My concern is that AGI is the kind of thing that may result in no "long term".