Article on the new wave of AI-generated bug reports, and how patches are quickly turned into exploits with automation assistance.

There are really plenty of them, including in commercial software - Firefox has for April twenty times more security bugs reported than normal.

I can’t tell how dramatic this is really. Maybe this is being cooked a tad hotter than it is eaten. Some reports on AI capabilities are basically clever marketing - or even outright misleading.

What is clear is that distros will need to fix more bugs, and it will take some time until most uncovered bugs are fixed.

Users will need to update more frequently.

Frugal configurations might become even more attractive.

Who is in for a bad time are probably vendors and users of “connected” devices which were never designed to be updated. Every Smart TV, Amazon Echo, “Smart” home device, or “Smart” toothbrush will likely become open to black hats or enemies of peace and democracy which invade your home network. Including medical stuff…

Some devices should probablybe put in a Farady cage - say anything that would be able to start a fire.

  • cmnybo@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    5
    ·
    4 hours ago

    Any IoT type devices should be on their own network where internet access is by whitelist only. They should only have access to what they need to function and nothing more. Ideally, they should all be used with self hosted services so internet access is not needed.