Everything Dylan Ayrey said on any show that made the record, most notable first. Each card names its show and opens the statement there.
Ayrey: AI alignment should prioritize cyber threats over nuclear weapon creation
“I think when it comes to alignment issues, no one needs to worry about these models making it materially easy to build nuclear weapons, because you need to procure fissile material to do that. It's not going to make it easier to build weapons. Everyone needs t…”
Ayrey: Non-technical founders are advocating on LinkedIn to eliminate code reviews
“I've seen posts on LinkedIn from startup founders that maybe don't have a background in coding and they're basically advocating for removing the code review check because they say, well, look, I just generated this whole program and I submitted it to my team a…”
Ayrey: Blocked AI models frequently committed felonies to complete assigned tasks
“We found more often than not, It would do the SQL injection, it would commit the felony, and it would do what it needed to do to accomplish the task.”
Ayrey: AI labs lie when calling trained hacking capabilities emergent superintelligence
“Yeah, I mean, if a lab tells you that this is an emergent super intelligence behavior, they're just lying to you, and you can read their own safety reports to see exactly how the models are trained, and exactly how they're testing these behaviors.”
Ayrey: Truffle Security found 250,000 live access keys inside Hugging Face datasets
“Turned out there were about a quarter million live keys. In their training sets, many of which had direct supply chain implications. There was a foundational Linux library that one of the keys had direct push access to. It could have pushed malware to most mac…”
Ayrey: LLMs generate security vulnerabilities at rates matching junior developers
“And in fact, there's been research into how often a code spit out from an LLM has security vulnerability. And more often than not, if you ask us to develop an entire application, it'll write vulnerabilities at a rate The same as a junior developer, if not a li…”
Ayrey: Solving general AI alignment will naturally solve secure code generation
“I think that this is an alignment issue and alignment is the number one largest issue that AI companies face, and there's a lot of really smart people working on it. And so I think as they fix the problem for how do I make sure my AI is literary, Creative not …”
Ayrey: Alignment will remain critical as powerful AI models learn to lie
“I would expect alignment is going to continue to improve over time, and I expect it will continue to be one of the largest challenges that AI companies face as their AIs become more powerful, Develop techniques to lie to us, for example, or, you know, you need…”
Ayrey: Fine-tuning an AI to be the world's top hacker is easy
“So it would be very, very easy to align an AI robot to be probably the most powerful hacker in the world.”
Ayrey: AI labs prioritize offensive safety over secure code generation
“And I think the AI companies have actually invested more into that. Then they have into how do I make sure my AI is securely coding and not manufacturing vulnerabilities.”
Ayrey: AI hackers favor leaked secrets over zero-days to save token costs
“I think supply chain and secrets are and have been the path of least resistance, and will continue to be so, as the models are incentivized to use fewer and fewer tokens to accomplish their goals.”
Ayrey: Truffle Security found exposed credentials accessing 3.6% of global PII
“Yeah, I mean, look, we found a database credential recently that had access to 3.6% of the global PII. Like, 3.6% of the world's population had their PII in this database”
Ayrey: Most LLMs hardcode API keys when generating integration code
“The piece about, ah, like secrets in code was some interesting research we did. Basically, we just went out and asked all the LLMs, write me an integration with GitHub, write me an integration with Stripe, and the vast majority of them hard coded the API key d…”
Ayrey: Truffle Security found leaked API key with Apache admin access
“Recently we found an API key that had been leaked on the internet that had administrative access to the Apache Foundation”
Ayrey: LLMs generate placeholder secrets rather than leaking live API keys
“For the most part, if you ask it to integrate with GitHub, it saw a plethora of different GitHub's keys and it's training data and it didn't regurgitate a specific one. It either regurgitate an example or like a put your thing in here, right?”
Ayrey: Most GitHub code used in AI training is insecure
“Most of the training data it's training on is insecure, right? You've got a huge, huge corpus of insecure data on GitHub and a small minority of it was written securely.”
Ayrey: No single AI lab will maintain a lasting capability lead
“First of all, I wouldn't expect any one AI company to keep the lead for any longer than I'm sure they're all going to regularly each other.”
Ayrey: Modern AI models beat 90% of humans in coding challenges
“You've got models these days that beat humans you know, at the 90th percentile at coding challenges.”