I do about a monthly update of my Debian machines. Today I did the usual monthly update and noticed loads of packages uploading from the “security” branch. I’ve had the impression (just an impression) that more and more packages are being updated from security over the past many months. Trixie has been out for a while now and I would have thought that less and less updates should be coming from security. Has anyone had this sensation and if so has anyone linked this to AI finding more holes in OSS that would have normally been found by human scrutiny? Has there been any official research into this? And if this is true, does it mean that we have been running insecure software all along? Or is there is there a risk that AI start filing patches that actually make it less secure because software maintainers are not being rigorous in verifying who is submitting the patch? AI must be changing the paradigm of software development more than any other area of our lives and I can’t still work out if in a better way or not.

  • ISO@lemmy.zip
    link
    fedilink
    arrow-up
    6
    arrow-down
    1
    ·
    4 hours ago

    Let me do the humble action of quoting myself 🙂 from 5 months ago:

    There has been murmurings, mainly from non-technical people, about how “AI” will render advancements in safer type systems nearly useless, because the magic (mushroom) AI will just find all the issues in code written in older languages. What they don’t realize is that the effect will be reversed. Many established projects that come with a high reputation, and a veneer of maturity, indestructibility, and meticulousness, will simply, and perhaps unfairly, lose that perception under the continuous barrage of potentially high impact bugs and vulnerabilities surfaced by these tools, with not enough human bandwidth to keep up with them, and with new code susceptible to the same problems repeating over and over. This will effectively lead to an even harder push for adopting technologies that prevent a good chunk of these bugs from ever happening at any point, not the other way around.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    ·
    7 hours ago

    We have been running insecure software since software was invented. AI has just accelerated finding what may be bugs. Wanacry/eternal blue existed before AI, Confliker existed before AI, SQLslamer, heartbleed, log4j all existed before AI.

  • TrollAccount69@lemmy.ml
    link
    fedilink
    arrow-up
    20
    ·
    6 hours ago

    There are two factors at play here:

    Ai is fast at finding and patching bugs. It’s just true. A lot of the bugs aren’t super high priority but can be daisy chained along with another and another and another exploit to eventually have serious consequences.

    Ai makes it much easier to recognize components of an exploit chain. What would just be a temporary hang for a tester or qa person is immediately recognized as a oob read, deserialization error or any number of other little bitty things that can make up one component of an exploit chain.

    So yes, we have been using insecure software this whole time.

  • Shimitar@downonthestreet.eu
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    7 hours ago

    Yes, simply put software is so complex, so many layers, that without a little critter working it’s ass off to find any possible stupid bug it was just too complex to find

    • trilobite@lemmy.mlOP
      link
      fedilink
      arrow-up
      3
      ·
      7 hours ago

      What really caught my attention was that in the update of today, the rsync package maintainer had to announce that he/she was jumping to version 3.5 because of “33 CVEs” … how can a software like rsync that has been around for so long have 33 CVEs shipped in just one update. I’m not a software developer but that sounds like a lot of CVEs?

      • slazer2au@lemmy.world
        link
        fedilink
        English
        arrow-up
        16
        ·
        7 hours ago

        Not all cve are actual problems. Some can be this function sets an int while that function reads it as a float so it can cause an issue on some obscure corner case that 99.999% of people will not run into.

      • Shimitar@downonthestreet.eu
        link
        fedilink
        English
        arrow-up
        9
        ·
        7 hours ago

        Yes very possible.

        Are they all serious issues? Almost certainly not.

        Should those be fixed anyway? Well, why not? After all if the software is not abandoned, there is no need not to fix those.

    • PattyMcB@lemmy.world
      link
      fedilink
      arrow-up
      2
      arrow-down
      1
      ·
      6 hours ago

      I think you meant “no”

      The “insecurities” were there before AI. AI is just flagging every little thing now.