跳到主内容
@wquguru
精选75Hacker News Best(web_list)行业动态

AI 让软件过度安全,执法黑客时代将终结

执法黑客时代:一切即将陷入黑暗

原文
发到 X

I’m coming down from spending a few days at Usenix Security, right here in my hometown of Baltimore. This means that my days have been taken up with two kinds of conversation: first, explaining to colleagues why Baltimore isn’t actually like The Wire. And second, trying not to talk about AI.

我刚从Usenix Security大会回来,这次大会就在我的家乡巴尔的摩举行。这意味着我的日子被两种对话占据:第一,向同事们解释为什么巴尔的摩实际上不像《火线》里那样;第二,尽量不谈人工智能。

Here I’m going to break that second rule.

在这里,我要打破第二条规则。

I have many worries about what AI means for our field, for various definitions of “field”. But in this post I want to focus on just one thing I’ve started worrying about, and it’s a perverse thing: specifically, I’m concerned that AI is going to make software much too secure.

对于AI对我们领域(无论“领域”如何定义)意味着什么,我有很多担忧。但在这篇文章中,我想专注于我开始担忧的一件事,而且这是一件反常的事:具体来说,我担心AI会让软件变得过于安全。

While that doesn’t sound so bad on the surface, there’s a consequence to this. I mean something very specific: I’m concerned that U.S. intelligence and law enforcement agencies are about to go dark, meaning: that they’re going to suddenly lose a huge portion of their capability. And that this isn’t going to be simply a problem for those agencies, but also for those of us who value computer security and privacy in general.

虽然这表面上听起来并不糟糕,但有一个后果。我的意思非常具体:我担心美国情报和执法机构即将陷入“黑暗”,意思是:他们将突然失去很大一部分能力。而且这不仅仅是这些机构的问题,也是我们这些普遍重视计算机安全和隐私的人的问题。

Going Dark, and the era of law enforcement hacking

“走向黑暗”与执法黑客时代

To explain how we got here, we need to talk about recent history. This actually gives me a real excuse to reference The Wire, just because it’s a perfect snapshot of what electronic surveillance looked like way back in 2002. If you’ve seen the first season, you’ll recall that it’s about cops wiretapping drug dealers who use payphones and burners. The mobile phones in the show are relatively new technology for the time, but from a technological perspective nothing in this scenario would have shocked a cop who jumped forward from, say, 1989.

要解释我们如何走到这一步,我们需要谈谈近代史。这实际上给了我一个真正的借口来引用《火线》,因为它完美地捕捉了2002年电子监控的样子。如果你看过第一季,你会记得它是关于警察窃听使用付费电话和一次性手机的毒贩。剧中的手机在当时是相对较新的技术,但从技术角度来看,这个场景中的任何东西都不会让一个从1989年跳过来的警察感到震惊。

In less than a decade from the premier, everything in those episodes became totally quaint.

在首播后不到十年,那些剧集中的一切都变得完全过时了。

The change began in the late 2000s, thanks to the rise of smartphones and texting. Because smartphones can actually store data as well as conveying it, the contents of those phones quickly became a useful new source of law-enforcement capability. Or they were until 2010, when Apple began encrypting iPhone storage using a key derived from the user’s passcode (Android phones followed shortly thereafter.) The next year, Apple deployed end-to-end encryption in iPhone text messages. By 2014, a tiny texting startup named WhatsApp had gathered 600 million users worldwide. By 2016 those users, now nearly a billion strong, were all using default end-to-end encrypted messaging and calls. These two trends — the move from calls to texts, and texts to encrypted data — happened very rapidly. The chart below gives one view of the transition:

这一变化始于2000年代末,得益于智能手机和短信的兴起。由于智能手机不仅能传输数据,还能存储数据,这些手机的内容很快成为执法能力的一个有用的新来源。或者它们一直如此,直到2010年,苹果开始使用基于用户密码的密钥对iPhone存储进行加密(安卓手机紧随其后)。第二年,苹果在iPhone短信中部署了端到端加密。到2014年,一家名为WhatsApp的小型短信初创公司已拥有全球6亿用户。到2016年,这些用户已接近10亿,都在使用默认的端到端加密消息和通话。这两个趋势——从通话转向短信,以及从短信转向加密数据——发生得非常迅速。下面的图表展示了这一转变:

The FBI and law enforcement agencies were not insensitive to what was happening. In 2014, Director Comey announced an initiative called Going Dark, which would launch a “national conversation” about what providers could do — or be compelled to do — to make these new communications media legible to law enforcement and counterintelligence.

联邦调查局和执法机构并非对正在发生的事情无动于衷。2014年,局长科米宣布了一项名为“走向黑暗”的计划,该计划将发起一场“全国对话”,讨论提供商可以做什么——或被强制做什么——以使这些新的通信媒体对执法和反间谍活动可读。

In 2016, the agency quit talking and took their theory to court. When a terrorist attack left the FBI holding a shooter’s locked iPhone, the agency ordered Apple to give them access. The company refused. What broke the stalemate — and, to some extent, ended “Going Dark” itself — was something that neither the FBI nor Apple expected. An outside company announced that there was no need for Apple’s assistance: they could simply hack the phone.

2016年,该机构不再空谈,而是将他们的理论诉诸法庭。当一次恐怖袭击让联邦调查局掌握了一部枪手的锁定iPhone时,该机构命令苹果公司允许他们访问。苹果公司拒绝了。打破僵局——并在某种程度上结束了“走向黑暗”本身——的是联邦调查局和苹果都未曾预料到的事情。一家外部公司宣布,不需要苹果的协助:他们可以直接黑掉这部手机。

The Apple v. FBI case turned out to be microcosm of the whole Going Dark debate. For the next decade, law enforcement and intelligence agencies continued to ask for “exceptional access” backdoors. But the urgency was gone: both agencies and manufacturers knew that law enforcement could purchase targeted hacking tools like GrayKey (for phone unlocking), or even remote exploitation tools like NSO Group’s Pegasus, assuming they needed them badly enough. Vendors like Apple and Google played a vigorous defense, closing vulnerabilities as soon as they learned about them. But offensive vulnerability hunters consistently managed to keep the edge.

苹果与联邦调查局的案件结果成了整个“走向黑暗”辩论的缩影。在接下来的十年里,执法和情报机构继续要求“特殊访问”后门。但紧迫感已经消失:机构和制造商都知道,执法部门可以购买像GrayKey(用于解锁手机)这样的定向黑客工具,甚至像NSO集团的Pegasus这样的远程利用工具,如果他们确实需要的话。像苹果和谷歌这样的供应商进行了积极防御,一发现漏洞就立即修补。但进攻性的漏洞猎手始终保持着优势。

And now there’s a very good chance that all this is about to be history.

而现在,这一切很有可能即将成为历史。

The era of AI bug hunting is here

人工智能漏洞猎杀的时代已经到来

This April (just four months ago!) Anthropic announced a new model called Mythos that happened to be unusually skilled at software vulnerability finding. The U.S. government temporarily blocked its export, restricting access to U.S. agencies and trusted vendors. While the ban was dramatic and made for good PR, it turned out to be mostly pointless. OpenAI, along with Chinese open-weight model labs like Z.ai and Moonshot, have since demonstrated that vulnerability finding isn’t something that a single lab is likely to hold a monopoly on. The list of serious vulnerabilities that these models have found is getting scarier (or more impressive) by the day.

今年四月(仅仅四个月前!)Anthropic 发布了一款名为 Mythos 的新模型,它碰巧在软件漏洞发现方面异常擅长。美国政府暂时禁止其出口,限制只有美国机构和受信任的供应商可以使用。虽然这一禁令引人注目,并带来了很好的公关效果,但事实证明它基本上毫无意义。OpenAI 以及中国的开源权重模型实验室如 Z.ai 和 Moonshot 已经证明,漏洞发现不太可能被某个实验室垄断。这些模型发现的严重漏洞列表正日益变得可怕(或令人印象深刻)。

At first glance, this might seems like good news for the offensive team, and for hackers in general. But I doubt that’s how this will play out in the long term. Defenders are now in the process of patching every bug they can find — often decades worth of bugs — and the backlog feels huge. But they’re making progress. Entire CI toolchains are being rebuilt to incorporate AI-based vulnerability scanning before software ever reaches the point where a human will touch it. While I doubt this means that every bug will be found (even calculating the number of bugs in a piece of code is probably uncomputable), in the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.

乍一看,这对攻击方和一般黑客来说似乎是好消息。但我怀疑从长远来看情况不会如此。防御方目前正在修补他们能找到的所有漏洞——通常是积累了数十年的漏洞——积压的工作量看起来巨大。但他们正在取得进展。整个 CI 工具链正在被重建,以便在软件到达人类接触之前就集成基于 AI 的漏洞扫描。虽然我怀疑这意味着每个漏洞都会被找到(甚至计算一段代码中的漏洞数量可能是不可计算的),但在现实世界中,我们确实有可能达到某种有用漏洞数量的上限,而且可能很快就会达到。

Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.

因此:在未来两年内,主要软件可能会耗尽可远程利用的漏洞。

Obviously I think this is great. But for law enforcement and offensive intelligence agencies, it’s going to be a nightmare. For the first time since 2010, law enforcement might experience what it looks like to really “go dark”, across a huge category of advanced (well-maintained) devices and pieces of software.

显然我认为这很棒。但对于执法部门和进攻性情报机构来说,这将是一场噩梦。自 2010 年以来,执法部门可能会首次体验到在大量高级(维护良好的)设备和软件类别中真正“陷入黑暗”的感觉。

So how is this a problem?

那么这怎么会成为问题呢?

The debate over “exceptional access” mechanisms never really went away. In some places, like the UK, it even metastasized into something worse. Here in the US it mostly went into hibernation. Some of the slowdown can legitimately be attributed to expert pushback — academics and industry engineers pointing out the risk that backdoors might be abused by the very adversaries that Agencies are supposed to be protecting us against. But I fear that this was less of a principled pause, and more of a market that was just pricing supply.

关于“特殊访问”机制的争论从未真正消失。在一些地方,如英国,它甚至恶化成了更糟的情况。在美国,它大多进入了休眠状态。放缓的部分原因可以合理地归因于专家的反对——学者和行业工程师指出后门可能被机构本应保护我们免受的对手滥用的风险。但我担心这与其说是原则性的暂停,不如说是市场在定价供应。

The destruction of the low-hanging vulnerability fruit will make law enforcement (and intelligence) agencies’ need much more acute. The demand for constructed, intentional backdoors will re-start in earnest. The result will be enormous pressure on industry to re-architect their systems to make their systems amenable to exceptional access. In some cases, governments will ask for these capabilities in the expectation that they’ll be useful for spying on other governments — a strategy that might have been undetectable in the pre-AI era, but that probably will be less productive now. The results are unpredictable. One result might be that non-US governments entirely remove their dependence on US software.

低垂的漏洞果实的毁灭将使执法(和情报)机构的需求变得更加迫切。对构建的、有意的后门的需求将重新认真开始。结果将是巨大的压力,迫使行业重新架构其系统,使其系统适应特殊访问。在某些情况下,政府会要求这些能力,期望它们能用于监视其他政府——这种策略在人工智能时代之前可能无法被察觉,但现在可能效果不佳。结果不可预测。一个结果可能是,非美国政府完全摆脱对美国软件的依赖。

The worst part about this dynamic is that these potential new backdoors will probably only affect the countries that demand them, meaning that they will be primarily useful for allowing the US to weaken its own systems. This will in turn allow foreign adversaries to find new ways to attack our communications. This deliberate self-sabotage will happen just at a moment when we’re finally getting a handle on securing our own infrastructure.

这种动态最糟糕的部分是,这些潜在的新后门可能只会影响要求它们的国家,这意味着它们将主要用于让美国削弱自己的系统。这反过来将使外国对手找到攻击我们通信的新方法。这种故意的自我破坏将发生在我们终于开始掌控自己基础设施安全的时候。

So what do we do about it?

那么我们该怎么办呢?

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近