The problem isn’t AI hacking tools, it’s computer security

I worked in computer security for most of my career. I worked on Unix security, then phone operating system security, then Bluetooth security. It was largely thankless work.

The issue was that no one wanted to work on a secure computer. Every security feature was a small obstacle to the user getting work done. Security features tended to get turned off or worked around. Certainly nobody was willing to pay more to buy a more secure operating system.

The secure Unix system I worked on was pretty secure. It had great security features that made it easy for users to do their work with considerable confidence that neither outsiders nor other users on their computer could hack their way in.

The federal government required that all computers purchased by anyone for any government office be evaluated to the level of security that our system offered. Over a period of years, our system was the only evaluated system available.

Guess how many we sold?

Zero.

Every government office that was buying computers asked for and got an exception to the requirement that they buy a system like ours.

That’s how much people hate security features in their computers. They slow you down. They make it harder for you to get your work done. They make your system different from other systems, so you have to learn new stuff.

It is from that perspective that I’m dismissive of AI hacking tools. Yes, they can hack computer systems, but that’s because people have preferred computer systems that are hackable. It will take a bit of time to go back and redesign and rebuild those systems with security in mind, but not long. How to do computer security is a solved problem. The knowledge is broadly distributed. It’s just a willingness to put up some minor inconveniences that’s been the obstacle to having broadly unhackable computer systems. Maybe with AI hacking tools quickly hacking into every insecure system out there (which is virtually all of them), people will finally be willing to accept the cost and inconvenience of secure systems.

At any rate, it’s no reason to regulate AI. Just a reason to enforce our regular laws.

Philip Brewer @philipbrewer