The Exchanges

Every argument clarity score on this site is built from rows on this page. Each question and answer was assessed with names hidden, the host's own answers included, on four things from 1 to 5: directness (does it answer the question asked), coherence (do the ideas follow), precision (concrete details and clear references), compression (says a lot per word). The weighted mix (30/30/25/15) is the exchange score. A person's published score averages their exchange scores on raw tape only, at least 8 of them, shrunk toward the cohort mean. Full method →

Yinon Costica no published score: only 6 usable exchanges on raw tape, and a fair score needs 8+ · coarse estimate ≈4.0/5 from 6 raw tape exchanges record → ← everyone

Every exchange below was scored with names hidden, four dimensions each from 1 to 5. An exchange's score is 0.30·directness + 0.30·coherence + 0.25·precision + 0.15·compression. The published score averages the raw tape exchange scores and shrinks small samples toward the cohort mean, so five great answers can't beat twenty good ones. Produced feed rows count only toward coarse estimates, never toward a full score.

clear all ✕
6exchanges match
6on raw tape
0redirected or not addressed
Answered raw tape D 5 · C 5 · P 5 · Cm 4 4.85

Q which is that it's a very promising technology, but companies trying to put, because if bad guys are companies, they're businesses, companies trying to put it into action have seen mixed results. And so actually what I'm getting from you is same thing happens happening with the bad actors. But then the question is, if these models get much more intelligent, uh, does that open us up to bigger risks?

A I believe there are areas that Yes. If they become increasingly better, let's take vulnerability research as an example. Vulnerability research is one area. Let's explain what's a vulnerability. Okay. Vulnerability by definition is the ability to move from one trust level to another trust level in a way that is not permitted. For instance, if I can run remote code, then I'm moving from the outside to the inside, and this is the worst that can happen because I'm literally running code from remotely, external, In your internal environment, right? So that's a vulnerability. A vulnerability can be un, like, um, unauthenticated access, so authentication bypass. I'm logging in and I have this trick that I'm giving False password, and I'm still able to log in, ok? That's authentication bypass. I was able to walk into an, like, a higher trust without the permission to do so. So that's a vulnerability. The ability to research and find vulnerabilities, this is kind of the bottleneck of the security space, ok? Because vulnerabilities are what allow threat actors to move from, you know, lower trust to higher trust environments, and The ability to automate research by, ah, ah, you know, AI of vulnerabilities can open up maybe a race where you can find many vulnerabilities and unable to patch them at the same pace. There are solutions today that are already leveraging AI to detect vulnerabil…

AI assessment note: “I believe there are areas that Yes. If they become increasingly better”

Answered raw tape D 5 · C 4 · P 4 · Cm 4 4.30

Q Ok, and now let's circle back to the question I asked in the beginning, because you know we've been building up to it, which is how vulnerable is AI written code?

A So, AI written code is interesting because one, yes, it is, it may be more vulnerable because we haven't instructed it To, to be secured. We need to, as we use AI to build applications, we need to also instru same way that we instructed in what we want the application to do. We need to instruct it in the way we want it to be secured, right? Apply list privileges, remove data, if not in use. So there are all of these, you know, best practices in securities that we apply today. If we have a human developing it and we review it, But with AI, we need to now specify the same manner, and as an example, we have released, the research team have released, it's, it's a rule set that you can feed into AI generate, generator, like code generator through AI, and this rule set will guide AI to build a secure code more than if you didn't, and this is just one aspect, but the more interesting thing around securing code That is generated by AI is what happens if you actually need to fix it? And who is the owner of this code? Now there is a very interesting question that arises because if I'm the developer of the code and now there is a vulnerability or someone reported a security issue, I wrote the code. I know it by heart, and, uh, I have someone reviewed it, but let's say I vibe code my entire application, and it's funny because on the first blog, uh, like post introducing vibe code, uh, the,…

AI assessment note: “yes, it is, it may be more vulnerable because we haven't instructed it”

Answered raw tape D 5 · C 4 · P 3 · Cm 4 4.05

Q They're vibing it, and the AI is, is, um, doing the rest. Are we already seeing Cybersecurity problems, uh, within companies who's, who have had developers that have just vibe coded or AI coded applications?

A Yeah, there are, uh, actually there are very, uh, known examples of someone, uh, some people that have posted the, the vibe code and application, and then it got ticked hours after or days after, and now they don't know how to recover because they didn't have the skill. So The way I'm looking at it is that vibing code is a great way to accelerate, but it doesn't remove you from the responsibility of actually knowing your code, being able to address issues within the code, and guide AI farther into the, you know, maintenance process as we go and use the application and mature the application. So this is, I think, a maturity thing that we need to go and to do. And another aspect is when we think about How would an agent architecture work? Because you're talking only on, ah, one role, which is the developer. But if we're fast forwarding, ah, like agentic concepts, ah, into the future, so why wouldn't you have a security reviewer that is also an agent? So you commit code, you're developing your code, and next you should have, like, a security review to your code, but also performed by an agent. That is minded for security with all the security best practices guidelines that we have provided it. And someone should maybe look at the architecture and someone should look at data privacy. And you can think about, and again, it doesn't exist today yet, but as we fast forward, AI doesn't …

AI assessment note: “Yeah, there are, uh, actually there are very, uh, known examples”

Answered raw tape D 4 · C 4 · P 4 · Cm 3 3.85

Q at cybersecurity part of the conversation because all these tools are in the hands of the bad guys now for all these reasons. But yet, Where, you know, in, in reality, the actual ability of them to get through is not higher. Is it, I mean, is your answer just because companies are doing a better job securing their infrastructure? Because if so, then it's really not a big problem.

A I think that we are in the process, when, when I think about our, like, the last decade, right? This process of automation, it's not new to us, right? Automation has taken place before AI, long before AI, and will take place after AI, long before. We are always in a journey to continue and automate what threat actors a decade ago have done on the keyboard, you know, manually. And when we look at cloud attacks, for instance, the ability to automate What happens as soon as I walk into an account as a threat actor? What do I do? Well, I can automate quite a bit, and we have seen this level of automation. We have seen this level of automation, for instance, with ransomware. We have seen automation happening over the course of the last decade, but in response within security, we have basically developed the capabilities to respond to this automation. AI is another layer that allows us to automate more right now. Okay, I'm not talking, because we're not seeing the crazy new threats yet, we are right now at the phase where we're seeing accelerated automation of the known threats, known risks, and this is a journey security has been into in the past decade, and it's only one step up.

AI assessment note: “within security, we have basically developed the capabilities to respond to this automation.”

Partly raw tape D 3 · C 4 · P 4 · Cm 4 3.70

Q know, we've called them threat actors. I call them bad actors. Basically bad guys looking to do damage or looking to hack into, to, uh, computer programs. They have all these tools at their disposal as well. So are we already seeing them putting those tools to use in an attempt to hack into software? And has that increased the sophistication and the level of hacking that we're seeing already?

A So there are several ways in which threat actors can use AI, ok? And the first thing is just hacking into an application, AI application, right? And if you think about how do I hack into an application and why it's appealing, there is what's called, like, the trifecta of, let's say, risk factors in AI. One, it's exposed. Second, it has access to private data. Third, you have, um, untrusted content, like the query, you know, Chat queries that you send to it, the prompt that are, that is also exposed to the threat actors. So one, you have the layer of directly aiming at the AI application and trying to extract via the prompt sensitive data. So that's one. The second thing that you can do, you can automate and iterate more on what is already known. And I think this is one thing that we look at AI. It's really good in automating repetitive tests. So instead of Trying one type of attack or one type of vulnerability. I can automate and iterate through an AI like built, like purpose built application to try and test many more options, right? And then you have the third layer that am I able to discover new type of threats using AI? Am I able to do vulnerability research to find new vulnerabilities because I've trained AI to do something very specific in that case. So These are the three levels that we can look at, and I think that the interesting thing is, and let's try to tackle it on…

AI assessment note: “So there are several ways in which threat actors can use AI”

Answered raw tape D 4 · C 4 · P 3 · Cm 3 3.60

Q Um, If this happens, hypothetically, ah, is it a magnitude greater risk if, let's say, humanoid robots, which might be in people's houses, or embedded in society, or autonomous cars, which we know are, like, all over the roads now, if there's a vulnerability there, is that, like, a level up from just the typical software hack?

A You know, there are, there are things that happened in the history of cyber that were very surprising. For instance, what would happen if I break into your, you know, I don't know, oven. It has an IP. I'm breaking into your, you know, remote cameras. What will happen? Just I'm getting installing something there. So, Historically, there was a DDoS attack that actually utilized all of these IOTs in order to target one specific, let's say, target, and they brought it down because we're talking about millions and millions of devices that are flooding a certain area. But who thought that this will be the use of these IOTs, right? It's a very creative use by the threat actors, right? And I think that the way we think about the risks Threat actors are very creative in how they utilize this source of stuff, and it's not always in, you know, the direct way, okay, we're gonna hack autonomous cars to run into people and, uh, robots to go into people's house and do stuff, but I think that this can cause significant outages, for instance, right? We can use it. It can cause, uh, significant, um, dysfunctional, uh, let's say, Society is right if we rely on it too much, or we don't have the proper ways to secure against it. So I do think that as things evolve, we do need to, ah, always think about how this can be used not only in the direct way, but also in part of other campaigns that Can tak…

AI assessment note: “I think that this can cause significant outages... significant, um, dysfunctional, uh, let's say, Society”

page 1
Made with StarZero

Turn any episode into a week of clips.

This entire site, over 300 episodes transcribed, diarized, checked and made playable, runs on the StarZero media pipeline. Drop in your own episode and the podcast clipper finds the moments worth sharing, cuts them, captions them, and reframes them for every feed.