← Back to context

Comment by elmer2

13 hours ago

Something that might come out of all of this is that companies that previously slow rolled security fixes will now be forced to fix them quickly, because the speed of AI and the liability of being insecure.

USA has that digital misuse law that makes it a crime to use software in unintended ways. So claude or codex finding bugs in their software is actually illegal... I am not sure if really no one tried this yet or if they did and I just missed the news.

Yea, when their cyber insurance policies start biting them because AI found a bug months ago and it was never fixed I figure we'll start seeing a change.

With that said there are numerous companies that are very concerned about the situation. They know AI is finding bugs in their software at an accelerated rate, one they are having difficult times keeping up with because they want human understanding and review of the fixes to avoid introducing new bugs.

  • Did CrowdStrike actually suffer? That was a huge outage and their stock is today at an all time high. Seems like no one actually cares. Neither the companies providing the software, the companies purchasing the software, nor the markets.

    To me, this is the craziest part about all of it. Why doesn't anyone seem to care?

    • Because the purpose of Crowdstrike is not to prevent exploits or make computing safer, its purpose is to allow corporate CTOs to tick a checkbox.

    • Why would they suffer? They showcased that they were big enough to disrupt the global economy. Why _wouldn't_ you invest in something so big and powerful?

      This is the same as when junkies specifically seek batches of drugs on which others overdosed.

      1 reply →

Depends on the jurisdiction. Where I live, companies are not liable for insecure software, if sold to a private person for example. Enter huge botnets of crappy home routers. Hopefully this is going to change.

The better outcome would be for everyone to slow roll everything rather than speeding up the rate of bug propagation.