Article 78BTD Security through obscurity is dead, and AI delivered the fatal blow

Security through obscurity is dead, and AI delivered the fatal blow

by
from www.theregister.com - Articles on (#78BTD)
Story ImageThe term "security through obscurity" describes an old idea that networks and systems will remain secure so long as their architecture, along with any vulnerabilities or other weaknesses, remains secret or hidden. It was never a sound strategy for protecting sensitive assets and systems, but many organizations leaned on it due to lack of resources or complacency. Now it's obsolete. Don't believe us? Here's proof. Software vendors and independent researchers alike are now using AI agents to find bugs - some very obscure and decades old - across products and open source code, leading to record-breaking numbers of security disclosures and patches, and a massive backlog for project maintainers. You see open source platforms that have been visible to the tech community for a decade, these libraries that are run in 80 percent of web servers out there, people have stress-tested those for 10 years, and the community believed that they were really secure," Brett Leatherman, assistant director of the FBI's Cyber Division, told The Register. The latest models were able to break those and say, yeah, there's significant vulnerabilities in here.'" Whether or not security through obscurity is dead isn't even an opinion question," Trend Micro's Zero Day Initiative chief bug hunter Dustin Childs told The Register, the day after Microsoft's record-breaking Patch Tuesday addressed 974 CVEs. When you look at all of the components patched by Adobe and Microsoft yesterday, you see components no one has talked about in years," Childs said. Telnet client - is this even still used in any secure environment? Windows RNDIS - the USB-networking protocol Microsoft has been trying to deprecate for years. NFS Portmapper - 1980s Unix tech. And Link Layer Topology Discovery - the Vista-era network-map protocol nobody's thought about since Vista - just to name a few." Meanwhile, attackers are also using AI to reverse-engineer fixes and find exploits within hours. In one recent case, at least four espionage crews, most suspected of links to China, slammed shut the patch-gap" window for open source Chromium, using an exploit kit developed shortly after the maintainers released an upstream patch - but before the downstream stable release was pushed to users. What this means for OT security During interviews at Black Hat in August, both former US National Cyber Director Chris Inglis and John Hultquist, chief analyst at Google Threat Intelligence Group, told us that they worry about what this means for critical operational technologies and industrial control systems (ICS). These are the systems that ensure the lights turn on when people flip a switch, gas flows out of pumps, and safe drinking water pours from faucets - all critical services that people use daily, and assume will continue working reliably. The OT systems themselves often use obscure protocols and proprietary hardware and software, which historically made them black boxes, even to IT specialists and hackers. AI upended this assumption. It means that criminals don't need to be OT experts to carry out destructive cyberattacks on critical networks and facilities. They just have to ask an agent to learn everything about these systems and do the dirty work for them. A couple of weeks after Black Hat, five US agencies said that attackers used AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series programmable logic controllers (PLCs) at water, manufacturing, energy, and other critical facilities. This is not a theoretical risk - it is an active threat," the feds warned. AI is excellent at technical troubleshooting, at knowing obscure systems and helping you make your way through it, and this makes me very concerned about industrial control systems," Hultquist told The Register in an interview last week. They've been largely secured because the expertise was in a handful of people's heads, and that's not going to last forever," he said. AI can be a useful guide for attackers studying not just the application layer, but also the operating system, and even down into the firmware, Hultquist added. That's going to have implications for a lot of different areas of security, but definitely for industrial control systems." However, while this undoubtedly means more work for sysadmins and defenders, burying this outdated idea of security through obscurity isn't necessarily a bad thing. 'Never a winning strategy' I've always been of the mind that security through obscurity was never a winning strategy," Katie Moussouris, founder and CEO of bug bounty consultancy Luta Security and the fairy godmother of bug bounties, told The Register. But that's because I've been a hacker for so long. The argument always fails in the face of someone who decides to turn their gaze towards your organization. If there is something to find, they will find it." Plus, she added, AI makes hacking a whole lot easier. People might not have familiarity with the particular tech stack that you're running, but that is no longer a barrier because AI has ingested everything, and an AI is going to help them enumerate weak spots, even if they themselves are not familiar with the particular tech stack that they are pointing an AI towards," Moussouris said. However, finding bugs and other weaknesses has never been the big security problem, she added. It's triaging and prioritization and actually getting things fixed." This, Moussouris said, has also been her biggest issue with the way that organizations implement bug bounty programs. AI is shining that bright light on the wrong end of the security picture, and unfortunately, AI hasn't caught up on the defensive side," Moussouris said. We're not there with AI automated patching, remediation - anything of the sort." A couple of recent studies back this up, both finding that AI-generated patches fail more than half of the time. 1Password's research team took six CVEs disclosed since March, and produced 6,080 patches using two frontier models: OpenAI's ChatGPT-5.5 and Anthropic's Opus 4.8. The average success rate for generating a patch that fully resolved the vulnerability (without materially changing application behavior) was just 26.0 percent," wrote Director of Security Research Keith Hoodlet, adding that even patches that did fix the flaw also mucked up the application's behavior 20 percent of the time. This included things like changing allow list" logic to deny list" logic. Conversely, LLM-generated patches did not resolve the vulnerability, added a new vulnerability, or both, an average 53.9% of the time," Hoodlet said. Another study by app security shop Veracode found that, across more than 100 models and 80 coding tasks, the average security pass rate for AI-generated code was just 56 percent. If people are telling you that you need to accelerate on the fixing side, and the defense side - that's just not cutting it," Moussouris said. Orgs that are looking at this as we're going to throw more resources at finding and fixing bugs, and they're not investing in taking a look at their process failures that led to so many bugs - those organizations are going to die on the treadmill," she added. They will literally have a heart attack and die. Like there's no VO2 max that will make you fast enough to deal with all those bugs, and giving up is not the answer." The answer, she says, is taking a more dynamic approach, assessing where your organization can find patterns that lead to a process improvement instead of patching vuln after vuln. A lot of organizations don't even know how to measure their progress, so they are counting bugs and speed of fixing, which is one way to measure. We had this many criticals, and then we fixed them super fast, and we had this many high, this many medium," Moussouris said. The number of flaws fixed is important, but it doesn't show the entire picture, she added. This involves looking at types of vulnerabilities, too. Like: We've got a lot of injection flaws. That's something we could solve with better, safer templates earlier in our CI/CD pipeline. This is something that we can prevent at scale, as opposed to fixing these like really easy to find and fix vulnerabilities really really fast." (R)
External Content
Source RSS or Atom Feed
Feed Location http://www.theregister.co.uk/headlines.atom
Feed Title www.theregister.com - Articles
Feed Link https://www.theregister.com/
Reply 0 comments