logoalt Hacker News

bell-cotyesterday at 9:48 PM1 replyview on HN

> Defenders are now in the process of patching every bug they can find, often with AI helping them. Entire development toolchains are being rebuilt to incorporate powerful vulnerability scanning before software reaches the testing phase. This does not mean that every bug will be found: even calculating the number of bugs in a piece of code is probably uncomputable. In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.

> Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.

His conclusion sounds extremely optimistic to me.


Replies

bahmbooyesterday at 10:01 PM

The number of remotely-exploitable defects is going to drop by 1 or 2 orders of magnitude. We now have amazing machines that will find pretty much all the a priori knowable ones. They outperform even the most gifted h@x0rs. So that just leaves a small pool of leetrs to scour a very barren landscape. And that pool is also shrinking as we rely more and more on the ai tools.

Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.

show 1 reply