logoalt Hacker News

gck1yesterday at 11:29 PM1 replyview on HN

> In cybersecurity, a level playing field favors the attacker

Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs.

And I don't know what Trusted Access programs give to defenders, because as a defender who has credentials, connections, but no deep pockets and no high ranking passport, it only gave me silence. I fail to see how this is better than total access.

I don't think the world where defense is given to those that "deserve" it is the world that we all want to live in. Which brings me back to the starting point - attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already.


Replies

ajyoonyesterday at 11:36 PM

> Yes, but didn't it always? Hence why my position is that this will get us back to relatively where we were pre-LLMs.

Trusted access programs are asymmetrical, and so at least for the time being they give critical parts of the stack an advantage. Total access would not be a return to the status quo; attackers can easily make thousands of agents crawl the web for soft targets well before defenses can be shored up. There are millions of targets out there who won't use AI to improve their defenses for years, if ever, due to institutional slowness (like hospitals).

> attackers are almost completely unaffected. If I masquarade as an attacker, I get way more capabilities already.

What do you mean by this? If guardrails are an obstacle to your defense, they are just as much an obstacle to attackers. I completely understand and agree that trusted access programs are not perfect and leave a lot of people and institutions out. This means trusted access programs should be improved, not that we should throw the baby out with the bath water.

show 1 reply