I refuse to bow to our AI overlords

speckx2 pts0 comments

I refuse to bow to our AI overlords - by cR0w - The Info Op

The Info Op

SubscribeSign in

I refuse to bow to our AI overlords<br>If chatty sentient sand broke your threat model, it was already broken

cR0w<br>Jan 13, 2023

10

Share

There’s been a lot of commentary by security nerds about how ChatGPT et alia ( GPT chat services ) are cause for concern and raising the threat level for everyone. I disagree and believe this reactionary pattern of assuming that any new technological capabilities should raise defense conditions is rooted in ignorance, arrogance, or predation. Same old INFOSEC, just a different day.

Subscribe

For the sake of level-setting, here are some generic concepts I am assuming. Obviously the real-world is grey and everyone models things differently, but I think these are basic enough that discussion can be generated without getting bogged down in pedantics and semantics.<br>The primary elements that constitute a threat are:<br>Reason or motive

Opportunity

Capability or means

The primary elements that constitute risk posed by a particular threat are:<br>Likelihood of occurrence of the threat event

Severity of impact caused by the threat event

As one of the threat elements increases, so does one or both of the risk elements.

As either risk element increases, so does the risk level posed by the particular threat.

Let’s start with motive. Unless your organization is directly related to the development, operation, procurement, or acquisition of a particular GPT chat service, I have yet to hear any reasonable explanation of how a particular threat actor’s motive to perform some threat event against a given organization will increase due to the availability of GPT chat services. If an organization is involved in the development, operation, procurement, or acquisition of a particular GPT chat service, the increased motive is increased in a way that is no different than any organization involved with a new technology of value.<br>Next we have opportunity. I don’t see how GPT chat services increase the opportunities for threat actors any more than capable OSINT can. If a threat actor is looking for opportunities to attack a particular organization, those opportunities exist, with or without the availability of GPT chat services. The ability to discover and capitalize on those opportunities comes down to the threat actors’ capabilities.<br>Capability or means seems to be where the majority of punditry revolves around. GPT chat services are not increasing adversarial capabilities any more than Google, Shodan, Stack Overflow, or the CTI industry’s favorite boogeyman: *spooky voice* dark net forums. As @thegrugq@infosec.exchange said on 09 January 2023,<br>“CheckPoint are saying some dumb shit about how ChatGPT will super charge cyber criminals who suck at coding. (See linked post: https://infosec.exchange/@dannyjpalmer/109659661412633830)<br>This isn’t a legitimate concern because most of the day to day operations of cyber criminals is drudgery that can’t be handled just by asking chatGPT.<br>They have to register domains and maintain infrastructure. They need to update websites with new content and test that software which barely works continues to barely work on a slightly different platform. They need to monitor their infrastructure for health, and check what is happening in the news to make sure their campaign isn’t in an article about “top 5 most embarrassing phishing phails”<br>Actually getting malware and using it is a small part of the shit work that goes into being a bottom feeder cyber criminal.<br>( https://infosec.exchange/@thegrugq/109660008815605752 )

That post^W toot really sums it up well. Any potential improvements to poorly written malware that GPT chat services can provide, can already be provided by simply asking other people on the Internet for help. Or outsourcing. Or acquiring. Or using existing similar services like GitHub Copilot. This is where my accusation of ignorance comes in. A lot of people with the word “Security” in their title don’t understand what it takes to operate and maintain highly-capable adversarial organizations. That’s expected. But the idea that GPT chat services will level up potential threat actors any better than YouTube videos with questionable music doesn’t seem rooted in reality.<br>There is one caveat to this that I will begrudgingly allow. I have heard people say that GPT chat services lowered the barrier to entry for threat actors to SMBs who have historically considered themselves non-targets to state-adjacent threat actors. There seems to still be a belief that they should be concerned with high-capability TTPs and that that their traditionally low-capability adversaries will now be unstoppable. The truth is that we are still a long way from getting the basics of security right, especially in the SMB world. They should first focus on the fundamentals before concerning themselves with the cool kid hacks. That said, all organizations of all sizes should have had their eyes...

threat chat services particular organization actors

Related Articles