logoalt Hacker News

0xbadcafebeetoday at 3:04 AM0 repliesview on HN

Back on my usual rant: we need software building codes. Among the many different reasons we've needed them for years, is safety. Our world depends on software, and our software should be safe. Security is a part of safety. If your software isn't secure, it isn't safe, as security holes can be used to create unsafe situations. Whether it's medical devices, industrial controls, voting machines, flock cameras, credit records, smartphones, online games, social media, or software packages in a package repository, each of these things can impact the real world if they're not properly secured.

So we need a software building code, and it should mandate security [safety] scans before certain software is made available to the public (any software which can compromise users' sensitive data, or be used to launch further attacks). We mandate safety checks for buildings and products that might harm people; we need the same safety checks for software that might harm people.

AI is how we'll do that. Some people have suggested weakening or holding back AI because they're afraid of what it can do. But that's the opposite of what we should do. We need to make powerful security-scanning software easier to get, so it can be used to secure all software, before launch. Attackers are not relying solely on closed models; they use open weight models, specifically so they can do whatever they want with them. You cannot stop this, it just is what it is. The only way to fight this kind of fire, is with more fire.

The important part is to not launch software before it's been made safe. You wouldn't open an apartment complex for people to live in before it had been made safe. We shouldn't do that with software either. Holding back AI models is just going to make this harder. We need to make more powerful security tools, and mandate they be used to build safer products.