Security researchers: patching bugs won't survive AI-driven vuln research, redesign needed
max_paperclips · x · 2026-10-05
Responding to Guillermo Rauch's take that security will become verification engineering plus capital allocation for software companies, researcher matrosov pushes further: memory safety is a symptom, not the cause—recent Linux kernel disclosures trace back to design decisions and trade-offs. Throwing more tokens at the attack surface won't help; nothing today is ready for AI-driven vulnerability research at scale. He argues for AI-assisted redesign, architecture validation, formal methods, and rejecting attack surface at the design phase—hardware included.
More from Safety
- Dean Ball on the vulnerable world hypothesis: cognitive AI will unlock cheap ultra-destructive weapons — deanwball · 2026-10-05
- halvarflake: broken incentives since 2000 have ground down 2-3 generations of security engineers — halvarflake · 2026-10-05
- OpenAI reveals 'novel' encryption bypass used in distillation attack, ties parts to MoonShot — jedisct1 · 2026-10-05
- New "systems are thinking" guardrail message hints at OpenAI human review — Darpinian · 2026-10-05
- US government and tech execs sign voluntary pledge to call AI "super intelligence" — YvesMulkers · 2026-10-05
- GitHub still doesn't accept post-quantum SSH keys, cryptologist points out — jedisct1 · 2026-10-05