logoalt Hacker News

Buttons840yesterday at 5:31 AM0 repliesview on HN

I've said before that I think red team security researchers should be able to investigate the security of government and corporate systems without needing permission.

Currently companies say "you cannot investigate the security of our systems without our permission, because it is our system and we are responsible--also, if there's a data breach, we aren't responsible." See how that works? As a society we seem fine with this.

We are sacrificing national security for the convenience of companies.

So... to answer your question:

Probably, again, we will sacrifice national security, and even our national competitiveness in this important new AI industry--we will sacrifice it all for the convenience of companies and so they can make a few bucks.

It's more important than ever that the good guys actively monitor government and corporate systems for security flaws. These open-weight models are going to be in the hands of the bad guys; the hackers are coming whether the company is ready or not. Ideally a good hacker will find and disclose the vulnerabilities before a bad hacker pwns half the nation's personal data for the 3rd time this month--or worse.

This will require that we stop bullying security researchers. Things like the State Governor personally pushing for felony charges because somebody pressed "view source" on an HTML page shouldn't happen.