LLM’s May Have Finally Spelled The Doom Of Security Through Obscurity

LLM’s May Have Finally Spelled The Doom Of Security Through Obscurity

‘AI’ Can Occasionally Do Something Useful, And Painful For Some

Security through obscurity has been a thorn in the side of security professionals everywhere; some programmers believe that the code they used or even the programming language itself is so rarely used and often so ancient that no one could ever guess what vulnerabilities lie in their programs.  This is partly laziness, but unfortunately it is also due to two other reasons, the first of which is the person who wrote the code can’t be contacted and no one else knows how to edit it or update it successfully.  The other reason is far more terrifying and common; that code runs something which can’t have down time.

It is that last instance that is the biggest nightmare.  A lot of our infrastructure, from drinking water to electricity and including the ancient telecoms equipment which our communications still relies on regardless if those companies will admit it or not depend on ancient code.  These systems can’t go down for long without major repercussions and there is no dev environment where you could test out new code to control these systems.

That means that the discussion over at El Reg is both good and bad.  It is good because thanks to LLMs we are seeing things being recently patched which shouldn’t even be used anymore.  There were updates to Windows RNDIS and NFS Portmapper in the past month, neither of which should have been used in a decade or more but are still out there.

It gets worse when you look at the really obscure things which have been running so long no one even remembers what they do or how they do it.  The last Black Hat conference included a presentation on how researchers were able to use AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities.

That is, as they say, a very bad thing.

Source link

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *