50 comments

  • Animats16 hours ago
    It&#x27;s worth realizing that, before computerized central offices, telephone wiretapping required running physical wires. Back when Rudi Giuliani was prosecuting organized time, not only did physical wires have to be run, the cops were billed for them as expensive private lines. His task force was spending about a million dollars a year with New York Telephone on wiretapping. In one case, law enforcement didn&#x27;t pay their bill, resulting in the person being wiretapped having the wiretap connection show up on their bill, blowing the case.<p>That resulted in the Communications Assistance to Law Enforcement Act, which mandated that central offices offer remote wiretapping. Capacity up to 1% of lines is required.<p>Back in the electromechanical era, the only call data that could be collected was outgoing dial pulses, using a &quot;pen register&quot;.[1] (The one shown in Wikipedia is mine. It&#x27;s a beautiful piece of antique brass telegraph technology. It records dial pulses as dashes, and has to be wound up like a clock, with a big brass key.) The Supreme Court decision allowing &quot;pen registers&quot; without a warrant refers to these &quot;extremely limited&quot; devices. That definition has been stretched and stretched by law enforcement into all non-voice data collected by telcos.<p>Law enforcement still wants more.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pen_register" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Pen_register</a>
    • dylan60415 hours ago
      &gt; In one case, law enforcement didn&#x27;t pay their bill, resulting in the person being wiretapped having the wiretap connection show up on their bill, blowing the case.<p>In the fictional world of The Wire, one of the &quot;wires&quot; were blown when the guy checked on his mobile bill to find out his account was flagged to not be disconnected. I&#x27;m sure this was art imitating life or inspired by type of thing
      • inigyou14 hours ago
        The Wire is allegedly one of the more realistic crime shows in how incompetent it portrays the police.
        • thisoneisreal10 hours ago
          It was created by a journalist and a cop, who both had long careers in Baltimore before working on the show. Not surprising how realistic it is. (Also a beautiful work of art beyond the realism.) If you find the show interesting, David Simon&#x27;s book &quot;Homicide&quot; is a great read.
          • pimeys7 hours ago
            And a few of his other series, such as Treme, The Deuce, and Generation Kill are all fantastic.
          • mrbombastic3 hours ago
            &quot;The Corner&quot; is also a great read by him.
        • Lord-Jobo1 hour ago
          Digital forensics examiner here; it’s extremely accurate especially for the tech involved at the time. I think I spotted a very small handful of things it had to kick under a rug for the plot to work, which is unbelievably small for a show like that.<p>It’s easily the best LE show that exists, but not just because of its accuracy; it’s incredible in its pure honesty. Some of the cops are total worthless shit bags, worse than the best of the criminals easily. Allowing that overlap, one that exists in real life, injects a whole lot of nuance into the story that is basically nonexistent outside of the show. And allows characters to grow and improve. It takes writers with actual LE experience (which they had) and a lot of talent to write that kind of thing without totally blowing it.
        • newsomix9xl13 hours ago
          In their defense their target was amazingly adept.<p>Many criminals even today don&#x27;t engage in basic counter measures like you see on that show.<p>And I&#x27;d call them &quot;dysfunctional&quot; more than inept. Bad leadership stymied by political goals overcomes even good policing.
          • Lord-Jobo1 hour ago
            Criminals with competence still operate in big numbers today, but LE very rarely targets them. The soft targets are just so abundant and easy, and the LE incentive system does not reward choosing hard targets at all.<p>Doesn’t help that a big chunk of the competent criminals have fully or partially internationalized their operations which acts as a very strong shield against LE.
        • semiquaver14 hours ago
          You’re doing my boy McNulty dirty.
        • walrus0113 hours ago
          That, and the alcoholism
      • Ccecil6 hours ago
        Never watched the wire...but I remember back 25+ years ago some people joking about not paying their phone bill to see if the phone was tapped.<p>They claimed that since it never got shut off when they didn&#x27;t pay it must be tapped.<p>Possibly correct I suppose...
      • DANmode2 hours ago
        Or that bit wasn’t true to begin with.<p>The billing accounts never would have crossed the same desk,<p>let alone been crossed.<p>The lines also weren’t terminated at the suspects’ homes. So, again, no vector for the bill to be sent there.<p>I’d lean towards “myth” on that - until a more convincing story appears.
    • vaylian9 hours ago
      The cost dynamics have flipped in the past decades. What we have now is &quot;Surveillance Too Cheap to Meter&quot; <a href="https:&#x2F;&#x2F;cacm.acm.org&#x2F;practice&#x2F;surveillance-too-cheap-to-meter&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cacm.acm.org&#x2F;practice&#x2F;surveillance-too-cheap-to-mete...</a> Because storing data is cheaper and often economically more useful than not storing it.
      • 20after47 hours ago
        With the price of memory skyrocketing, maybe that equation changes slightly.
        • monster_truck3 hours ago
          the $&#x2F;gb of storage is declining, which is more relevant here.<p>The big boogeyman that noids have insisted on for the past ~30 years is that intel agencies are saving everything they can to try and decrypt it later. Thankfully for us, the rate at which internet traffic grows year over year massively outpaces the global production capacity of spinning rust.<p>The last time I did this napkin math I think the collective global production was barely enough for some small fraction (maybe 1&#x2F;8th or 1&#x2F;12th) of everything.<p>It isn&#x27;t exactly something that can be done in secret. Everyone else has to buy hard drives too, there are only so many sources of raw materials, places that can refine them, etc<p>E: I think the most relevant thing to avoid if this is a concern for you would be commercial VPNs. There&#x27;s a reason fiveeyes doesn&#x27;t want them to be banned. They can almost assuredly save piles of money by simply coercing providers into allowing them physical access to leverage side channel attacks
          • xhkkffbf13 minutes ago
            Declining? Not when I try to price out 10tb drives. I&#x27;m sure the economics will catch up eventually, but anyone shopping for hard drives is getting a shock.
            • monster_truck5 minutes ago
              It&#x27;s 2026 dude, buy the 28tb drives.
    • leeoniya12 hours ago
      &gt; The one shown in Wikipedia is mine.<p>neat!<p><a href="https:&#x2F;&#x2F;upload.wikimedia.org&#x2F;wikipedia&#x2F;commons&#x2F;e&#x2F;e3&#x2F;Pen_Register.jpg?utm_source=commons.wikimedia.org&amp;utm_campaign=index&amp;utm_content=original" rel="nofollow">https:&#x2F;&#x2F;upload.wikimedia.org&#x2F;wikipedia&#x2F;commons&#x2F;e&#x2F;e3&#x2F;Pen_Regi...</a><p>assuming you still have it, it wouldn&#x27;t be the worst idea to update the pic to something without chromatic aberration and motion blur. the wiki pic is probably the worst of the bunch compared to others on google image search :)
      • Animats9 hours ago
        If any legit museum, or attorney involved with Fourth Amendment issues, would like it, please contact me at nagle@animats.com. It&#x27;s just sitting around.<p>I bought it on eBay years ago, out of curiosity, and fixed it. I built a little control box to go with it, with a phone dial and a 9V battery, and found a source of paper tape and ink. So it can be demoed. If it ever is used in a court appearance or legislative testimony, that would be better than it sitting in a box.
      • p0w3n3d10 hours ago
        Yeah I find the phone-taken images much worse than camera-taken even despite the astonishing number of megapixels and amount of technologies promised in the phones nowadays. Sadly most people don&#x27;t buy the camera because it&#x27;s too expensive and you need prepare yourself to take it with you (so the most photos are taken instantly with the phone)
    • downrightmike15 hours ago
      &quot;Back when Rudi Giuliani was prosecuting organized time&quot; I can&#x27;t even fathom he&#x27;d not be cashing checks from the mafia to go after other families. Odds are good that historians will find that he did.
      • ericjmorey15 hours ago
        He traded Italian organized crime for Russian organized crime.
      • arjie14 hours ago
        A similar story around this is the controversy around various Mumbai “encounter specialists” (a violent incident between police and gangsters is an “encounter”) and whether they were effectively hitmen for some faction of the local mob. Always thought it was quite intriguing stuff.
  • mbroshi17 hours ago
    &gt; In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.<p>This doesn&#x27;t resonate with me. I see companies adding more sloppily written features with AI. I see more bugs in the software I use, not less. While it&#x27;s plausible that software is getting both buggier and more secure, I suspect those two move in the same direction not opposite.<p>My guess is that we&#x27;re getting better at finding _existing_ security issues with AI (and thus fixing those issues), but simultaneously adding more insecure surface areas _at a faster rate_.
    • tptacek16 hours ago
      One way to resolve the tension here is to note that CNE and lawful-intercept access to phones depends generally on platform vulnerabilities, not application code vulnerabilities. Low-level platform code churns less, absorbs more fixes under AI workloads than it does new features, and works in a constrained space where guardrails are easier to provide (and where those guardrails already have institutional support at Apple and Google).<p>Over the long term this state of play could change, and IC&#x2F;LEO organizations could start leaning more on application vulnerabilities than on platform RCEs. But the action would probably still coalesce around a couple of app-layer targets that could themselves be hardened.
      • schoen11 hours ago
        I was hoping that the basebands and firmwares would get formally verified. Maybe they will ... with AI-written proofs!
    • doginasuit3 hours ago
      &gt; My guess is that we&#x27;re getting better at finding _existing_ security issues with AI (and thus fixing those issues), but simultaneously adding more insecure surface areas _at a faster rate_.<p>This does seem to be true in the vibe coding era, which I expect will implode at some point. But LLMs could certainly lead to a future where vulnerabilities are scarce. The best time to vet security factors is designing the model and writing the initial code, and LLMs are extraordinarily useful for this too. Most code with security implications is not written by a security expert.<p>An LLM can be the most anal and well informed security expert you can find. If you write the code yourself but have one in the loop from the start, the code will be in much better shape.
    • aleksandrm17 hours ago
      I don&#x27;t know, my colleague refuses to use AI and I&#x27;ve been seeing more bugs from their side, while reducing bugs on my side with the help of AI.<p>That said if companies want to &quot;ship ship ship fast&quot;, then yes even AI can produce bugs or regressions if not carefully reviewed by the human.
      • Ancapistani17 hours ago
        I don&#x27;t have any colleagues like that anymore, but even as far back as the last half of 2025 I was seeing that automated AI review was becoming effective enough that I considered it essential to any project where security was a serious concern.<p>These days we&#x27;re generating multiple times more code than we were writing before. That means a similar multiple of opportunities for bugs to be introduced - so the ability to automate security review is more impactful in proportion to that.
      • kelnos11 hours ago
        &gt; <i>while reducing bugs on my side with the help of AI.</i><p>How do you know? You might be adding (latent) bugs every time your LLM fixes one for you.
        • remus8 hours ago
          Same as usual: add tests. Over time the test suite becomes the spec that describes how the software should function. As the test suite grows you squeeze out room for undefined behaviour and bugs.
          • coldtea2 hours ago
            &gt;<i>Same as usual: add tests. Over time the test suite becomes the spec that describes how the software should function.</i><p>That covers functionality - it doesn&#x27;t catch the kind of bugs talked about in TFA.
      • bossyTeacher17 hours ago
        &gt; I&#x27;ve been seeing more bugs from their side, while reducing bugs on my side with the help of AI.<p>You should question your ability to see any bugs on YOUR side.
      • Forgeties7916 hours ago
        Have you asked your colleagues what it’s like to deal with your code?
        • boc15 hours ago
          It&#x27;s not 2025 anymore my friend.
          • Forgeties7915 hours ago
            Yet apparently people still dump unvetted LLM outputs onto their colleagues and expect them to thank them for the privilege. So it’s worth asking them what the consensus is of their work to find out if it’s the case.
            • leptons10 hours ago
              That&#x27;s the old way. The current way is nobody reviews anything. The LLM reviews it all and nobody even reads it, they just click approve, and merge blindly. I wish I were kidding.
              • DANmode2 hours ago
                &gt; nobody<p>Speak for your workplace only.<p>Most places still consider a PR or commit yours, if your name is attached.<p>Act accordingly.
              • mlrtime5 hours ago
                Not where I work. We have both review PRs.
      • juleiie3 hours ago
        The point is that people who want to be secure can be more secure than ever while people who don’t care about security will be less secure than now.<p>Author claims something slightly different but that’s how I would look at it.<p>The extremes are more potent because either you get super secure 10 times vetted system or you get underpowered model slop with all the vulnerabilities it entails.
    • marcus_holmes6 hours ago
      &gt; I see companies adding more sloppily written features with AI<p>I think this is a side-effect of the old product management process adapting to AI. We (as an industry) were never very good at defining features rigorously, because there was a smart human in the loop who had to implement the feature and could push back on sloppy definitions.<p>Whereas security bugs are easy for the LLM to define and fix.
    • thinkthatover16 hours ago
      Disagree, and in a way it feels like we are dealing with inverse issues: the security &quot;skill&quot; is well defined and will be also engaged with by an agent. Communication companies are further incentivized as any failure is at best reputational harm. Meanwhile SaaS companies are not strictly required to have good UX for their human end users, largely because those users will likely work around the issue. also network effect vs low costs of switching for for comms
    • amarant6 hours ago
      My hot take is that AI is a multiplier. Software engineers skill can be measured on a scale from -10 to +10, where 0 means you introduce as many bugs as you solve, or something along those lines(this scale is loosely defined, don&#x27;t think too much about it)<p>Any engineer who&#x27;s skill value evaluates below 0 on my scale, ends up with a large negative number when they use AI. Anyone with a positive number ends up with a large positive number.<p>The extra bugs you&#x27;re seeing are from devs on the wrong side of 0 on my poorly defined scale.
    • Forgeties7916 hours ago
      They’re not “bugs” they’re “quirks”! Our software is so quirky. It’s a feature!
  • Insimwytim17 hours ago
    On one side, you have pieces like this, where seemingly there are constant fights between serious actors with large and properly distributed budgets, employing top tech and top minds; on the other - regular news of the hackz, where responsible person in charge of security with root access failed to grasp basic technical knowledge (several times), ticking every checkbox in &quot;never do this&quot; list from security best practices, which led to every customer being pwned.<p>It&#x27;s like two parallel worlds, that exist in the same place at the same time, but somehow don&#x27;t cross.
    • kulahan17 hours ago
      I started my career in the military, and got lucky enough that SOMEHOW, we convinced them to fund a trip to GDQ for educational purposes.<p>Anyways, while there I attended a little roundtable on software security. It was me, representing a small unit from the Air Force, some dude from Google, and like 15 game devs.<p>Despite only being a dev of 5 years at that point, I was SHOCKED at the lack of knowledge on software security. Even simple concepts seemed completely foreign to the game devs, though the Google dude seemed to have a really solid understanding of security.<p>Obviously game devs and website devs and all kinds of devs have different focuses, but it just blew my mind that out of all the topics there I might’ve been considered a comparative expert in, security was somehow the one. I wasn’t sure if that was a major plus for military devs or a major concern for the other devs, but now I’m starting to learn in the latter direction.
      • Ancapistani16 hours ago
        Without knowing when that was, I can&#x27;t be sure how concerning it is.<p>As an end user, security in game development seems to hit a minimum is the early 2000s.<p>I recall playing EverQuest and using ShowEQ on a Linux machine on the same network as a proxy to silently eavesdrop on the traffic to show a map of the game with all the hidden&#x2F;obscured&#x2F;visible stuff all present. They either never encrypted that traffic or I quit playing before they did.<p>As multiplayer games started to become the default, netcode improved quite a bit and basic encryption was implemented - but I don&#x27;t recall a single multi-player game, ever, that was free of hackers when playing online.<p>It feels like over the years the issue moved from remote exploitation to hiding processes on the user&#x27;s machine. That has lead to kernel-level anticheat systems. I&#x27;m unsure of the effectiveness as when they started to become common I moved all of my gaming to dedicated hosts because I wasn&#x27;t willing to give that level of access to my &quot;real&quot; computers. That said, I&#x27;ve certainly not noticed a decrease in the perceived number of cheaters.<p>These days, as far as I know - and to be clear, this isn&#x27;t an area of deep interest for me - I&#x27;m not worried about my gaming accounts being compromised through technical means. It feels like that sort of security is a solved issue overall, although I suppose it&#x27;s also possible that other forms of exploits have simply gotten easier&#x2F;cheaper.
        • psd18 hours ago
          &gt; It feels like that sort of security is a solved issue overall<p>...ish. The solution is false positives and a permanent underclass. You can&#x27;t play those games unless you&#x27;re on windows and you grant root to the anti-cheat.<p>I don&#x27;t care much about that, but i do care about people being unemployable because some amorphous machine doesn&#x27;t like the way they comb their hair.<p>Last century, if you grew up five to a room then at least you knew why you were marginalised. It wasn&#x27;t just, but it was legible. Now, some of us are living in Terry Gilliam&#x27;s Brazil.
        • Cider998613 hours ago
          I&#x27;ve never seen an exploiter on Clash Royale.
      • veeti13 hours ago
        Security in the game industry is a sick joke. There are dozens of RCE riddled titles sold on Steam at this moment. For example, many past titles on &quot;Call of Duty&quot; series with CVE-2018-20817 [1].<p>BTW, I highly encourage all EU citizens to prepare Cyber Resilience Act complaints for September 11, 2026 when the law kicks in ;-)<p>[1] <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;blackops2&#x2F;comments&#x2F;1v3xowq&#x2F;just_entered_a_game_on_pc_and_the_hacker_opened&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;blackops2&#x2F;comments&#x2F;1v3xowq&#x2F;just_ent...</a>
        • dave711 hours ago
          Absolutely crazy that these CVE-ridden CoDs are being sold by Microsoft itself!
          • DANmode10 hours ago
            Crazy, but unsurprising.
      • habinero14 hours ago
        Hah. It probably shouldn&#x27;t be <i>that</i> surprising? Most engineers learn security on the job, not school. Game devs don&#x27;t deal with -- and don&#x27;t need to deal with -- the kinds of security issues Google and the military do.<p>Google has probably the best security team in the world, and they need to. The military deals with state actors by definition.<p>Gamedevs need to ship. I&#x27;m not saying they don&#x27;t care about security, but short of some showstopper critical problem, it&#x27;s not a thing and doesn&#x27;t need to be.<p>It doesn&#x27;t matter if your game is secure if nobody plays it lol
        • magic_hamster9 hours ago
          Games are a different product altogether. Game developers want to have fun and create a fun experience. Security is almost always something they&#x27;d avoid if they could. They&#x27;d rather spend the time on more polish, juice or play testing.<p>Besides stopping cheaters, in almost all conceivable cases, security doesn&#x27;t make a game better.
    • nostrademons15 hours ago
      I think that&#x27;s going to be the central tension of the next few years. The article suggests that software becoming more secure is going to lead to renewed calls for a &quot;legitimate&quot; backdoor for law enforcement to access everything about the device. Well, that security means nothing if someone phishes Kash Patel, something which has already happened. You go through the weak link, which is almost always the human.<p>I could see a future where the government is replaced by the software system which has the fewest security flaws, simply because it is the last thing left standing as everybody hacks everybody else. We end up with a Matrix-like or Terminator-like future where humanity now lives in service of the machines.
    • edoceo16 hours ago
      K shaped economy and K shaped development?
    • conmod2781 hour ago
      [flagged]
  • teravor16 hours ago
    I don&#x27;t think the thesis that a government will be able to do something will ultimately hold. I don&#x27;t see how they can avoid &quot;going dark&quot; in a democracy.<p>we live in a world where the government can&#x27;t even do much about illegal drug markets anyone can access by downloading a piece of software.<p>if they pass laws that mandate backdoor access and block software which doesn&#x27;t conform more and more people will move to the dark networks.<p>and if they effectively block the dark networks (in the limit they will have to block all encrypted communications) then we will be living in a tyranny.<p>freedom is messy. accept that digital crime can only be solved when the criminal makes a tangible mistake. LLM&#x27;s will be building profiles on criminals to help with identifying mistakes.
    • squigz24 minutes ago
      &gt; we live in a world where the government can&#x27;t even do much about illegal drug markets anyone can access by downloading a piece of software.<p>I think it&#x27;s a mistake to think they <i>can&#x27;t</i> - rather, they <i>won&#x27;t</i>.
    • tptacek16 hours ago
      The problem that Matthew Green is calling out subtextually is that democracy is likely to disappoint nerds on this issue: a random voter in the country 10 years from now may very well not share your priors about this issue.
      • teravor16 hours ago
        consider the implications of a government where setting up an encrypted network is a serious offense, or where detecting encrypted communications is routine. the average voter doesn&#x27;t matter. if they are willing to go that far it&#x27;s a tyranny and the average voter doesn&#x27;t matter anyway because they spy on everyone and have LLM&#x27;s profile everyone (in that context even if voting still happens it doesn&#x27;t matter, they will nudge the voters however they wish due to the information asymmetry).
        • DangitBobby1 hour ago
          It doesn&#x27;t need to be a serious offense. The current playbook works fine. Anything the Constitution prevents you from doing, have a private company do it for you. In this case you lean on, pay, or give preference to private companies to install back doors. Have the SC rule that you can&#x27;t sell devices with certain encryption guarantees anywhere on the planet because planetwide commerce affects interstate commerce. Things like that.
    • DANmode10 hours ago
      &gt; democracy<p>Still?
      • timedude13 minutes ago
        Yes,if you realize it was always a scam to consolidate power in the hands of an elite few
  • fitblipper14 hours ago
    I&#x27;ve always loved the ridiculousness of the &quot;going dark&quot; label when law enforcement can&#x27;t access encrypted chats or a back door isn&#x27;t built into a piece of software. When there are security cameras on the vast majority of houses, stop lights and in people&#x27;s hands, and when so much meta data about people&#x27;s associations are shared from Google, Facebook, any other social platform, how in the world can they say they are &quot;going dark&quot;. How did they ever solve crimes before these things?
    • sam3453 hours ago
      Wire taps That&#x27;s the point.
    • jrowen13 hours ago
      Yes, are there any data points to suggest that this arms race is balanced any differently than it ever has been throughout history?<p>The cops will find a way, the criminals will find a way. It&#x27;s ultimately people v. people with access to the same level of technology.
  • RajT8815 hours ago
    It breaks my heart that the governments with unlimited budgets who have hired the best and brightest will have to put in serious effort to get the bad guys, and potentially find it not worth it to casually spy on the whole world.<p>I am just beside myself at such an idea that people looking to feed the prison machine cannot as easily find excuses to turn normal citizens into prison feed.<p>Just super sad guys.
    • xp8415 hours ago
      &gt; excuses to turn normal citizens into prison feed<p>What felonies are those normal citizens being convicted of that&#x27;s landed them in prison?<p>I get the basic &#x27;not wanting everyone&#x27;s comms to be monitored&#x27; part. I think there&#x27;s an important conversation to be had because indeed, that can&#x27;t be the answer.<p>But it sounds like you&#x27;re saying most people who are convicted of felonies based on a jury unanimously being convinced by the electronic evidence against them... those people are unjustly in prison?
      • fedpost33 minutes ago
        Unironically yes, we convict people of felonies for the dumbest fucking reasons and working a jury is literally a science.
      • RajT8814 hours ago
        The issues with the justice system are well documented. Please do not try to straw man what I am getting at.<p>Certain people are arrested and detained far often than others, because of who they are and not what they did.<p>Many positions in the justice system prioritize conviction rate above all else.<p>There are many problematic relationships between legislators, law enforcement and the for-profit prison systems.<p>Our position in this list should make anyone afraid:<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;List_of_countries_by_incarceration_rate" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;List_of_countries_by_incarcera...</a><p>If LE decides you should be &quot;taken off the streets&quot;, regardless of if you did the crime you are accused of, you are likely going to prison for <i>something</i> unless you are wealthy. If you are wealthy, they may not bother. All very interesting.
        • sam3453 hours ago
          You might want to try reading something other than leftist attacks on law enforcement. Yes there abuses here and there. But for the most part law enforcement works s in the constitutional rights of defendants are respected. And if they are not they are subject to appeal. The system is flawed but it works.
          • fedpost29 minutes ago
            Maybe try reading more leftist attacks on law enforcement?<p>Like, yes, the system works at the level you&#x27;re assessing it. The problem is that it&#x27;s based on a mountain of flawed premises and so we&#x27;ve ultimately created a literal torment nexus with a smiley face taped on top of it and everyone gets to wash their hands of it and go home: justice served.
          • RajT8850 minutes ago
            It may surprise you to learn that I lurk the comments section at Breitbart. The subtext of the articles is made clear there.<p>There is plenty of distrust in LE and the legal system on the right. There is also plenty of people who believe it all is OK because &quot;those people&quot; are ending up in prison. You will never reach the people who do not care until it happens to someone they know, or someone like them.
          • sadlyuramoron4 minutes ago
            [dead]
      • inigyou14 hours ago
        The one who threw a ham sandwich at a Nazi at a protest?
        • GaryBluto5 hours ago
          You mean the guy who assaulted a federal officer and got off scot-free? Woe is him.
          • Nextgrid3 hours ago
            That&#x27;s selective enforcement though. It&#x27;s only &quot;assault&quot; because it was done against a cop. It&#x27;s &quot;just being a dick&quot; when done against anyone else.<p>The danger of constant surveillance is that a lot more of these &quot;being a dick&quot; incidents will be prosecuted <i>when politically convenient</i> (because equal, fair prosecution of <i>all</i> incidents would not happen as that would quickly cause the law to be changed, preventing its future use selective enforcement).
            • GaryBluto3 hours ago
              I think that throwing a submarine sandwich at anybody would be considered assault or battery (unwanted, offensive physical contact), although I do think selective enforcement could be a real problem in the future.
    • lotsofpulp8 hours ago
      &gt;It breaks my heart that the governments with unlimited budgets who have hired the best and brightest<p>Why would the &quot;best and brightest&quot; work for governments that pay a fraction of market price?
      • broodbucket6 hours ago
        They work for private companies with massive government contracts
  • Gigachad17 hours ago
    I&#x27;m supposed to be concerned that the US government and Israel won&#x27;t be able to hack everyone&#x27;s phones?
    • hyperpape17 hours ago
      The reason why this might worry people who don&#x27;t like the US&#x2F;UK&#x2F;Israeli governments is hidden in a secret place...a paragraph that is neither the first paragraph nor the last.
      • turtletontine17 hours ago
        Tl;dr the argument is if three letter agencies can’t buy or make exploits anymore because all vulnerabilities are patched, they will ramp up legal and legislative pressure to make vendors install backdoors. Which is bad and we should all worry about.<p>One of the author’s blind spots here is the concept of “digital sovereignty”. The US is continuing to ban more and more Chinese-made hardware out of fear that the Chinese govt has installed backdoors in them… which you could interpret as an admission that the US does exactly that with American made products. Globalized supply chains are, erm, complex, and few if any companies are really going to be able to achieve “digital sovereignty” with hardware. But with software it’s actually plausible, though obviously hard. Whether or not the feds have actually installed backdoors in Microsoft Outlook, foreign govts are rightly concerned that they have, and are increasingly pushing to avoid US made software for simple national security reasons.
      • colordrops17 hours ago
        Which is to say that they will become more authoritarian and aggressive? That&#x27;s not a good reason to be unhappy that they can no longer hack shit. They shouldn&#x27;t do that either.
        • ameliaquining17 hours ago
          The trouble is, sometimes governments do things that they shouldn&#x27;t do.
        • kulahan17 hours ago
          There are lots of things governments should and shouldn’t do, but unfortunately we don’t live in a vacuum, and need to consider the consequences of actions, rather than simply hope everyone is somehow forced to react the way we expect and desire.<p>In a nutshell, what I’m saying is “They shouldn’t do either” is at best a platitude and at worst a distraction preventing critical thought.
          • danaris5 hours ago
            By this logic, we should never try to escape our abusers or resist our oppressors: we should just capitulate now, give them everything they want, and that way they won&#x27;t escalate to (more) violence.<p>In a nutshell, this is bullshit. Bootlicker bullshit.<p>In a <i>democracy</i> (which our Western nations are certainly <i>supposed</i> to be, though that&#x27;s become less true over time), if the people in government are doing things that are counter to the interests of the people, the appropriate response is to <i>replace those people</i>. Protest, contact your representatives and senators, contribute to campaigns that oppose what they&#x27;re doing, etc.<p>And, of course, in an authoritarian state, if they decide they&#x27;re going to add in backdoors to our phones, or ban encryption, or take whatever other draconian measures, then it doesn&#x27;t matter a huge amount <i>how</i> we, the people, express our opposition to this; it&#x27;s <i>extremely</i> unlikely that we have just enough collective strength and will to prevent them doing A, but not to prevent them from doing B instead. Either we can stop both, or neither.
          • colordrops17 hours ago
            So our strategy should be to shut down AI so it leaves vulnerabilities everywhere? Not sure what you are saying. Fixing security bugs across the world&#x27;s software isn&#x27;t some single policy action that we can vote on.<p>Governments should behave. I know they don&#x27;t, but they should, and the population should do everything in their power to force them to. What other choice do we have?<p>Please demonstrate your powerful faculty of critical thought and explain what we should do instead.
            • sethammons3 hours ago
              Not who you replied to. &quot;They should&quot; isn&#x27;t a solution. &quot;Here is proposed legislation,&quot; &quot;I started a petition,&quot; &quot;i spoke with my congressman,&quot; &quot;vote for Pedro.&quot; These are concrete. &quot;They should&quot; isn&#x27;t anything.<p>Like SMART goals, I believe the other commenter was pointing out that platitudes lack specific, measurable, achievable, realistic, and timely aspects required for organizing and achieving progress.
        • lelandbatey17 hours ago
          Read the article. That&#x27;s what the article says.<p>&gt; Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.<p>&gt; While I think this is great, for law enforcement and offensive intelligence agencies, it’s going to be a nightmare.<p>&gt; So what do we do about it? I honestly have no idea. [...] it’s just occurring to me that we’re on a long greasy slide to a place that will look different than where we are today. [We’re] just going to have to hope that this time we make the right choices.
        • donkey_brains17 hours ago
          Nope. The article’s assertion is that governments will start to put enormous pressure on tech companies in their borders to include backdoors in their systems for LEO use. This in turn may lead to “nationalized” software e.g. what Russia and China largely do now, but in many more countries. You may have no choice but to use phones, computers, and software that is backdoored by your government - everything else will be illegal.
          • abruzzi16 hours ago
            I think &quot;nope&quot; is in reference to &quot;hacking&quot; system. The point of the article is that hacking by software vendors that sell to law enforcement was a pressure relief valve that deflated the movement that the FBI was pushing at the time to have Apple (and others) build backdoors into their systems. If the phones could be hacked, and backdoors were not necessary the FBI could back off and still get what they want. If the FBI can&#x27;t get what they want, they can either pressure the companies like Apple, or they can pressure congress to make laws requiring this. The phone makers could stand on principle, go to court, but the courts in the US are not very tech savvy, and usually deferential to law enforcement. Other countries may be better than the US, but some are definitely going to be worse.<p>So is a backdoor worse than a security vulnerability? I don&#x27;t know but that is what this article is about.
          • iamnothere14 hours ago
            It sounds like we should be gearing up for that fight then, so we can win it.
            • smalltorch2 hours ago
              I&#x27;m pretty sure you dropped a comment a while back about mailing systems. Finally got around to making my ideal prototype.<p><a href="https:&#x2F;&#x2F;gitlab.com&#x2F;here_forawhile&#x2F;tmail&#x2F;-&#x2F;raw&#x2F;main&#x2F;tmail3.png" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;here_forawhile&#x2F;tmail&#x2F;-&#x2F;raw&#x2F;main&#x2F;tmail3.pn...</a>
              • iamnothere52 minutes ago
                I did, that looks pretty good for a prototype! I would suggest adding the option to send as plaintext email (disabling all formatting options), as this is still useful in some cases. Bookmarked.
          • colordrops17 hours ago
            What do you mean &quot;Nope&quot;, you mean &quot;Yep&quot; right? What you are describing is precisely &quot;more authoritarian and aggressive&quot;
    • wavemode17 hours ago
      His argument is that the government is going to start forcing tech companies to install backdoors in their tech, now that (hypothetically) they can&#x27;t use hacking anymore.
      • ericjmorey15 hours ago
        How is that not a better position than the current situation?
        • DangitBobby1 hour ago
          You know the old joke?<p>&gt; I don&#x27;t have to outrun the bear, I just have to outrun you.<p>It&#x27;s like when the bear can&#x27;t catch the slow guy anymore so he starts setting up traps and finding ways to cut off legs. Now the faster guy actually has to deal with the bear.
    • matheusmoreira15 hours ago
      That was my first thought as well... But remember, they&#x27;ve got unlimited Mythos while we barely have Fable.
    • colordrops17 hours ago
      Right? I saw &quot;I’m concerned that U.S. intelligence and law enforcement agencies are about to go dark, meaning lose a huge portion of their capability.&quot; and my first reaction was GOOD.
      • corndoge17 hours ago
        What was your reaction after reading the full article?
        • ericjmorey15 hours ago
          I read the full article and have the same reaction. He&#x27;s worried that civil rights will be in a better position and that we&#x27;ll have to continue to defend them from that better position.
    • corndoge17 hours ago
      Which part of the article made you feel this way?
  • embedding-shape17 hours ago
    &gt; In fact, the worst part about this dynamic is that these potential new backdoors will begin primarily useful for allowing the US to weaken its own systems, which will in turn allow foreign adversaries to find new ways to attack our communications. This deliberate self-sabotage will happen just at a moment when we’re finally learning how to defend our own infrastructure.<p>I don&#x27;t understand how you can both argue for that law enforcement (and intelligence) agencies will force others to implement intentional backdoors AND also everyone will be using AI to find and secure ALL potential holes in the software so there won&#x27;t be any vulnerabilities anymore.<p>Wouldn&#x27;t one AI or another detect this deliberate backdoor and report it, as it&#x27;ll look just like any other security vulnerability, the only difference being the intention?<p>I have respect for the author so I feel like I probably misunderstand something from the overall text rather than I somehow have a better perspective on this topic that the author knows very much more about than me. I felt like I nodded along all up until &quot;So how is this a problem?&quot; and now I&#x27;m not sure I understood correctly.
    • Majromax17 hours ago
      &gt; Wouldn&#x27;t one AI or another detect this deliberate backdoor and report it, as it&#x27;ll look just like any other security vulnerability, the only difference being the intention?<p>That&#x27;s precisely the author&#x27;s point: deliberate backdoors will be more adversary-exploitable than ever before, but the demand for such from law enforcement agencies is likely to ratchet upwards.
      • conmod2781 hour ago
        Why can&#x27;t the backdoors themselves be more sophisticated? I understand that expecting such sophistication from legacy companies is a joke at this point.
      • embedding-shape17 hours ago
        &gt; deliberate backdoors will be more<p>But that&#x27;s one step after, I&#x27;m trying to understand how those backdoors even end up in software if everything gets automatically reviewed by the people working on these codebases? Wouldn&#x27;t things like these be flagged by systems other than the developers tasked by the agency to implement it? How can law enforcement actually get these things implemented without big parts of the engineering team not seeing warnings about it happening?
        • nater500016 hours ago
          I&#x27;m not sure you understand what is being described here?<p>If you&#x27;re a US company building an app&#x2F;device&#x2F;etc. such that an intelligence agency like the CIA or FBI would want access to the data in that product which is normally secured, then they&#x27;re not going to try to sneak it in there without your development team knowing. They&#x27;re going to have a meeting with the owners of the company and say, &quot;hey, we&#x27;d really like you to implement this backdoor for us, and in return we won&#x27;t cause you in problems.&quot;<p>Note that this does certainly already happen a lot, but it&#x27;s also not something that can happen across the board (like the author points out). Apple, being one of the largest companies in the world and who has one of their biggest selling points being their security, has explicitly refused to do this to the point that the intelligence agencies couldn&#x27;t break into an iPhone until another company found a way to do so.<p>&gt;I&#x27;m trying to understand how those backdoors even end up in software if everything gets automatically reviewed by the people working on these codebases?<p>The people working on these codebases are &quot;in on it.&quot; Of course, we&#x27;re talking backdoors which are very subtle, target very minimal infrastructure, and are known about by very few people. But, like I said, companies are currently shipping products with backdoors in them knowing they exist already. AI doesn&#x27;t change that dynamic.<p>&gt;Wouldn&#x27;t things like these be flagged by systems other than the developers tasked by the agency to implement it?<p>The only people who would have access to the systems that can even be flagged by this stuff would be people who would know about it. Keep in mind that the scale we&#x27;re talking here is massive. Think about how software development works at companies like Apple, Microsoft, Google, etc. There are devs working in offices all around the world where they only ever have access to a fraction of the code that company owns. These companies are very capable of keeping their stuff locked down. It&#x27;s a necessary component of their work.<p>&gt;How can law enforcement actually get these things implemented without big parts of the engineering team not seeing warnings about it happening?<p>Hopefully my explanation at this point is clear, but just to be concrete: backdoors are, by design, very hard to detect. That doesn&#x27;t mean they&#x27;re just sneakily written code that humans don&#x27;t notice as they read over it, but, instead, they&#x27;re very subtle implementations in very specific parts of huge systems that are already locked down to the point that the number of people who even have access to those portions of the systems are very limited. These agencies don&#x27;t slip in backdoors without anybody noticing; they convince the minimal number of people needed to know about it to implement it. Again, we&#x27;re talking about a meeting between the directory of a three letter agency and a CEO, where the CEO then directs the CTO to implement the backdoor who then instructs the handful of very high-ranking engineers to do so.<p>AI systems in these companies may very well flag these backdoors to the people who already know they exist, then these people can tell the AI &quot;hey, those are their on purpose, so just move on,&quot; and the other 99.99% of the company will never know they exist.<p>I suppose it&#x27;s important to emphasize, again, that these systems are incredibly massive and complex and most people at these orgs don&#x27;t have any access to most of these systems, so it&#x27;s not like you can expect an intern running BugBot across a repo and expecting it to find a backdoor.
          • preg_match14 hours ago
            I think people take the FBI or CIA too literally. I imagine they don&#x27;t need to talk to owners and it&#x27;s probably not even ideal. It might just be easier to get plants in the organization.<p>I would imagine most big companies, like Microsoft, have dozens of CIA and FBI plants in their organizations. Agents who are legitimate software engineers, tasked with acquiring intelligence and undermining security.
          • JoshTriplett15 hours ago
            &gt; If you&#x27;re a US company building an app&#x2F;device&#x2F;etc. such that an intelligence agency like the CIA or FBI would want access to the data in that product which is normally secured, then they&#x27;re not going to try to sneak it in there without your development team knowing. They&#x27;re going to have a meeting with the owners of the company and say, &quot;hey, we&#x27;d really like you to implement this backdoor for us, and in return we won&#x27;t cause you in problems.&quot;<p>And then you say, loudly and publicly, &quot;all the source code of our software is public, and our binaries use binary transparency so it&#x27;s not possible for us to build a binary that doesn&#x27;t match the source, and people will rapidly find this in our source code at which point we go out of business and you stop having a product to backdoor in the first place&quot;.<p>(And you move out of the US.)<p>And since this is a foreseeable future, you should start acting <i>now</i> to prepare for that future.
            • supriyo-biswas9 hours ago
              With laws like Chatcontrol and all, other jurisdictions are not necessarily any better.<p>In fact, we&#x27;re increasingly seeing a desire to build the &quot;backdoor&quot; directly into the software, e.g. mandatory age verification, client-side scanning, etc.
            • danaris5 hours ago
              &gt; And then you say, loudly and publicly, &quot;all the source code of our software is public, and our binaries use binary transparency so it&#x27;s not possible for us to build a binary that doesn&#x27;t match the source, and people will rapidly find this in our source code at which point we go out of business and you stop having a product to backdoor in the first place&quot;.<p>&gt; (And you move out of the US.)<p>And then everybody claps.<p>Name me a software or hardware company—one big enough that the US government would actually <i>care</i> to force them to add a backdoor—that would be willing to give up the US market? The only one that&#x27;s shown the least bit of backbone is Apple, and while I like them and appreciate what they&#x27;ve done in that vein so far, they&#x27;re never going to move to open source software running their stuff, and they&#x27;re pretty well embedded in the US, and very, very unlikely to try to move regardless of the headwinds there.<p>I&#x27;m fully with you that this would be a wise and moral thing to do, but frankly, our tech companies are neither wise nor moral. They are self-serving, greedy, and many of them have wanted to become the neofeudal overlords of a new order since before Trump started smashing the old one.
              • JoshTriplett3 hours ago
                I&#x27;m not suggesting giving up the US market. I&#x27;m suggesting moving out of the US and continuing to serve the US market from elsewhere, because the US does not have a nation-wide firewall. And working with organizations mounting legal challenges to &quot;please destroy your company in order to put in a backdoor for us&quot;.<p>Certificate Transparency has essentially eliminated the problem of backdoored CAs, because attempting to do so would destroy an entire CA. Binary Transparency can do the same for software.
                • danaris9 minutes ago
                  I&#x27;m not sure exactly what you think that will accomplish...?<p>Companies have to follow the laws of the <i>countries they operate in</i>, not just the countries their physical headquarters are in.<p>That&#x27;s why, for instance, Apple has to follow the DMA in Europe.<p>Furthermore, <i>especially</i> for many of the tech companies, where they are located is an integral part of their culture. They are Silicon Valley. You&#x27;re going to have a very, very hard time convincing any of them to up stakes and move.<p>And further-furthermore, move <i>where</i>? Europe has, unfortunately, made similar authoritarian noises (eg, Chat Control). China is <i>already</i> more of an authoritarian state than even Trump&#x27;s USA. Ditto for Russia, and, AIUI, India, though both in somewhat different ways.
    • scoofy17 hours ago
      I suspect they want a backdoor that basically acts like a front door (current password regimes). That is, a kind of high level password that decrypts traffic given a specific, changing, password that only the government has access to.<p>It&#x27;s seems like an odd-duck for sure, and I doubt it&#x27;s a realistic proposition. I do think &quot;perfect encryption for dummies&quot; is all well and good until organized crime organizations are able to challenge the government in certain regions of our country.<p>All of this sends us deep into the realm of political philosophy, the nature and purpose of governments, and the freedom vs security tradeoffs we live with.<p>I listened to the latest Plain English podcast this morning, which was explicitly about the potential for a ransomwarepocalypse in the coming years, as open models let any tom, dick, or harry become capable of a plug-and-play ransomware attack, instead of that being left to the realm of professionals. It&#x27;s a bit nerveracking to think about every nigerian prince scam suddenly becoming a sophisticated attack on your local water sanitation system.<p><a href="https:&#x2F;&#x2F;youtu.be&#x2F;vWvazbGPCCI" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;vWvazbGPCCI</a>
      • embedding-shape16 hours ago
        Ah, like new regulation requiring a &quot;Portal For Law Enforcement&quot; for platforms over X MAU or something?<p>I think I can kind of see that from the text re-reading it, it&#x27;s kind of hidden though and not so explicit if this is what he is trying to communicate. Thanks for giving me a new perspective to read it with!
    • Jtsummers17 hours ago
      &gt; In fact, the worst part about this dynamic is that these potential new backdoors will begin primarily useful for allowing the US to weaken its own systems, which will in turn allow foreign adversaries to find new ways to attack our communications.<p>The author agrees with you and addressed this point. The US forcing backdoors into its own systems (&quot;own&quot;: Those for sale and distribution within the US) would create vulnerabilities making those systems weaker.
    • gowld16 hours ago
      &quot;backdoors&quot; aren&#x27;t holes, they are well-documented superuser APIs. The hack will be by compromising the API user&#x27;s credentials (moles, stolen passwords, etc), not compromising the server&#x27;s design intent.
  • pianopatrick17 hours ago
    I dunno man, if there&#x27;s a deluge of new AI generated code at all layers of the stack I think there will still be vulnerabilities.<p>Like if we were willing to stop adding new code and just have a small secure code base, AI could maybe help us find all the vulnerabilities in that code base.<p>But people have consistently been unwilling to do that. Like if we were willing to stop adding code we could have stopped decades ago and done SQLite level testing everywhere and probably have found almost all the bugs already.
    • fragmede17 hours ago
      When we&#x27;ve got people who don&#x27;t know the difference between ssh and bash creating SaaS companies that generate revenue, yeah there&#x27;s gonna be a lot of insecure code going out, but that same person can also tell the AI &quot;red team my app to find vulnerabilities and then fix them&quot;, and the AI can competently actually do that, I don&#x27;t know that there will be. I&#x27;m not saying that&#x27;s never going to happen, but the bar is getting raised on both sides.
      • draw_down16 hours ago
        Plus, the interest and expertise and passion used to favor the red team, attackers. If you wanted to defend against them you had to get on their level, or hire someone on their level. Thats either expensive or requires a time investment that doesn’t make sense for someone who is trying to do much more than just defend against attackers.<p>Now it’s just as you said- asking AI to red team your app will get you pretty far.
  • Carrok17 hours ago
    Sounds like a pretty strong argument to self host, and otherwise be in charge of the software you use.
    • dgellow17 hours ago
      Including your AI agents. And models become problematic. There very likely is and&#x2F;or will be lots of pressure for US AI labs to make models help law enforcement. It could be by implementing backdoors in generated code, or not report some exploitable bugs, or something else. Similar for agents, they basically become the threat in your infra…<p>(It’s of course not only the US, just that the largest AI providers are US based and we know from history how US agencies operate)
      • Ancapistani17 hours ago
        Yep.<p>I&#x27;m using open weights models on a privacy-focused provider right now, and that&#x27;s adequate for my current usage, but I&#x27;m rapidly getting to the point where my agent&#x27;s access level to my data (and to a lesser extent, my accounts) is becoming something I&#x27;m not comfortable sending outside my network at all.<p>My hope is that models that are roughly on par with Deepseek V4 Flash can be run on hardware that I can own for &lt;~$5k in the near future. We&#x27;re close, but not there yet as far as I know.<p>The only long-term solution to this is self-hosting.
        • johnsmith184015 hours ago
          There is literally no protection or difference of an opensource model doing this.<p>An actual objection I had while talking to an aerospace company was they don&#x27;t want opensource models because the threat of it having a poisoned training example on specific systems.<p>It&#x27;s easily the most hidden malware possible, completely undetectable until an exact set of tokens unlocks it. Is it line 100,543 of your security product? You will literally not know until it plants it in there.
          • tancop5 hours ago
            You can review generated code manually or with models from a second vendor (ideally from a different country). Attackers would have to poison both <i>and</i> do it in a way that also makes them ignore the planted malware when reading code.<p>Open models also let you read reasoning traces. That means anomalies would show up when the backdoor activates, like a run of unrelated words or a jump in top token probability. It&#x27;s only undetectable until the first time it happens.
          • danaris5 hours ago
            To the best of my knowledge (which, admittedly, is far from comprehensive), that kind of attack on a model shouldn&#x27;t actually be possible in a deterministic fashion.<p>If you can&#x27;t stop them from sometimes telling customers things like &quot;yes, I <i>will</i> give you a penthouse suite at our hotel for only $3&#x2F;night&quot;, why would you be able to guarantee that, with some specific set of tokens, they would produce a perfect and undetectable backdoor customized to the code at hand?
            • dgellow5 hours ago
              I don’t think it has to be perfect or deterministic that way. It’s enough to have a bias towards implementing a backdoor in some circumstances. Something like, if the machine seems to be used in a Chinese environment, the model is biased towards missing some security issues, or towards implementing the type of bugs that can be used for an RCE, or similar.<p>Anthropic has done such checks at the agent level: <a href="https:&#x2F;&#x2F;cybersecuritynews.com&#x2F;anthropic-claude-hidden-code&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cybersecuritynews.com&#x2F;anthropic-claude-hidden-code&#x2F;</a><p>Their excuse was defending against distillation attacks but you can see how that can be abused
    • otterley17 hours ago
      How do you think self-hosting will help in this situation?
    • gloryjulio17 hours ago
      Self host + open weight models, exactly the things that openai&#x2F;anthropic don&#x27;t want you to have
  • wavemode17 hours ago
    This &quot;going dark&quot; scenario would require new legislation. With secure enclaves, modern smartphones can&#x27;t be cracked open in the manner that the FBI wanted in the 2016 case. So there&#x27;s no such thing as &quot;court order tech company to crack phone&quot; anymore. It would have to be &quot;outlaw tech companies from producing phones that they can&#x27;t crack open&quot;, which is very different and does not fall under any existing US statute.
    • inigyou14 hours ago
      Congress would pass that law in a heartbeat.
  • getcrunk4 hours ago
    I think the authors treatment of backdoors and exceptional access is a narrow focus.<p>We will certainly see “front door” access as various places have or are attempting to enact client side scanning, id verified online access, software root of trust remote attestation, and the general attack on e2e.<p>Taken together your identity tied to unmodifiable software, necessary to access the web or modern economy with client side scanning and no e2e … is a front door.<p>All this has nothing to do with ai, bugs, hackers or security vulnerabilities, let alone backdoors
  • password43214 hours ago
    For the HN 14 day record since I didn&#x27;t see this yet: in genuinely critical situations, if the threat model includes a device&#x2F;service being used against one&#x27;s self, &quot;the only winning move is not to play&quot; (stop the use of the device&#x2F;service!)<p>In the same manner, if the critical concern is a device&#x2F;service being used against one&#x27;s self remotely, stop the use of the device&#x2F;service if it is capable of remote access or data collection for later retrieval.<p>The ultimate baseline reality is that deciding to care whether or not remote access&#x2F;data retrieval is using a method supported by the device manufacturer&#x2F;service provider and&#x2F;or whether doing so is allowed by the current legal system is too late.<p>Premptive HN disclaimers: I acknowledge the growing unavoidability of devices and services supporting remote access and&#x2F;or data collection as I type this here on my phone. Remote access and data collection are very convenient and somehow still expected by device owners and service users to be under their control alone. It can be difficult to determine if a device or service supports remote access&#x2F;data collection. There are often immediate consequences and eventual legal consequences for stopping the use of devices or services that belong to others. Working to change the legal system to slow&#x2F;reduce use of devices and services against one&#x27;s self and encouraging others to do the same is admirable.
  • Eleg0071 hour ago
    Best-written article I&#x27;ve read all week.
  • bloaf16 hours ago
    I would like to point out that the last year when not a single law enforcement agency anywhere in the world could have possibly tapped anyone&#x27;s phone was 1876.<p>150 years ago was the invention of the telephone, and I think that articles like this seem to assume that prior to this, police just never caught any criminals.
    • jMyles15 hours ago
      &gt; 1876<p>A year when police were relatively rare, and quite new in the western legal experience, having only emerged from slave patrols in the United States and from the founding of the 1829 Scotland Yard in the United Kingdom. This is a year with living memory of a time when the state did not employ people to do what was ostensibly the civic responsibility of every person to quell crime and protect others.
      • sam3453 hours ago
        So you are advocating no police? You want people to police themselves? .Good luck with that.
  • Grombobulous17 hours ago
    I think what’s unintentionally eye-opening about this chart is the recency of “law enforcement can read your text communications.”<p>Law enforcement doesn’t need this surveillance ability at all. All time periods prior to 25 years ago didn’t have it.<p>Additionally, there is no correlation between “law enforcement reads text messages” and crime rates going down.
    • jackp9616 hours ago
      Not trying to defend our national dystopian nightmare of a surveillance state — but I&#x27;m pretty sure this is wrong?<p>Crime&#x27;s been decreasing for years, and (from what I understand) this year is tracking to be one of the safest years on record?<p>Definitionally, there absolutely has to be a correlation (not causation) between those two factors you listed.<p><a href="https:&#x2F;&#x2F;ourworldindata.org&#x2F;us-crime-rates" rel="nofollow">https:&#x2F;&#x2F;ourworldindata.org&#x2F;us-crime-rates</a>
      • edoceo16 hours ago
        Didn&#x27;t freakenomocs claim it (crime rate) was (primarilary) about abortion in the 1970s and less unwanted (and unsupervised&#x2F;undisciplined) children growing up?
        • Grombobulous14 hours ago
          There’s also the leaded gasoline theory.
      • Grombobulous14 hours ago
        These charts make the exact point I was making.<p>Most of the crime decrease from its peak happened before the year 2000.<p>That means back in the days of law enforcement needing to do low-tech wiretapping techniques, crime was still rapidly decreasing.<p>There’s just not even a correlation. And, as a reminder, correlation is not causation even if it was there.
  • password43213 hours ago
    Doesn&#x27;t this just mean criminal suspects will be forced to unlock their devices using biometrics (in the US)? That should buy law enforcement some more time until biometrics go out of favor.
  • ayaros16 hours ago
    Governments and their agencies shouldn&#x27;t have any access to the communications of private citizens. If something like terrorism is the issue, the correct response is to use the wealth and resources of the government to address the root causes of those attacks, not to undermine my right to privacy.
    • bigDinosaur15 hours ago
      This is untrue when private citizens are in conflict (legal or physical or whatever) and the dispute needs to be mediated or resolved. The &#x27;root cause&#x27; may well be she said&#x2F;he said and the legal system may well have need to resolve this by looking at private communications.<p>Strong emphasis on the <i>legal</i> system part, but you&#x27;ve completely dismissed that private communications frequently are required to address causes of issues and the word subpoena makes it rather clear that refusing to comply comes with penalty.
  • natecodes17 hours ago
    &gt; This is not a call to action for experts to rally behind a sophisticated plan. Like so many things about the AI revolution, it’s just occurring to me that we’re on a long greasy slide to a place that will look different than where we are today.<p>heh. long greasy slide. It really does feel like that.
  • bottlepalm17 hours ago
    Man I thought from the title this was going to be about next-gen AI being able to zero day everything so effectively that software security is meaningless and we&#x27;d need to basically shut it all down, go dark.
    • wseqyrku16 hours ago
      I stopped reading at &quot;I’m concerned that AI is going to make software much too secure.&quot;. That must be the biggest horseshit ever dropped.
      • willturman16 hours ago
        Won’t someone please think of those poor helpless law enforcement agencies!<p>AI code is flawless and impenetrable!
        • wizzwizz416 hours ago
          Well, it&#x27;s certainly impenetrable.
  • Lerc16 hours ago
    Considering from a point of view stipulating that perfectly secure software is possible. I don&#x27;t think it follows that the limititation that it would place on intelligence is necessarily a net loss.<p>Apart from the obvious harms of invasion of privacy, and fishing expeditions being biased to the places you decided to fish. There is the simple fact that data can be misleading, especially without context. An interceped communication is a piece of data that is intrinsically tied to the trust of the inteceptor. A few people with an agenda can collaborate to create a seeming truth by &#x27;discovering&#x27; the same thing from different sources.<p>Requiring warrants compelling information holders to provide data, not only serves the task of protection from abuse but also create a record of provenance that can be verified.<p>It also provides a degree of symmetry in capabilities which discourages actions that one party may do over another if they are motivated to act because they have a temporary advantage over another.
  • cadamsdotcom16 hours ago
    We will know we&#x27;ve made systems secure when laws focus on compelling people to <i>provide access</i>.<p>These laws exist - they aren&#x27;t the focus yet. Right now there&#x27;s still no need; just hack the device or compel the cloud service to give the data, why waste energy getting consent from its owner!<p>More bugfinding AI, more end to end encryption, more CVEs and more fixes, cannot happen soon enough.
  • tolugenius17 hours ago
    &gt; In this case, we’re just going to have to hope that this time we make the right choices, for no other reason than that they’re right.<p>I&#x27;m more curious what could be a right choice, and more importantly who is the &quot;we&quot; in this, as many decisions are largely made by companies and governments.
    • philipkglass17 hours ago
      As far as I&#x27;m concerned, the right choice is that the US government learns to live with remotely secure devices in the hands of everyone. No new laws are passed to force hardware&#x2F;software makers to insert remote backdoors. Law enforcement and intelligence services have to investigate targets using metadata, publicly posted information, the numerous online service providers who are already subject to warrants, and physically proximate surveillance.
      • inigyou14 hours ago
        Great. I also choose for the US government not to backdoor my device. But I think it will do that anyway, what should I do about it?
  • happosai2 hours ago
    I think US law enforcement will just continue to wiretap everyone at the &quot;SSL added and removed here&quot; SaaS known as cloudflare.
  • gmuslera17 hours ago
    No system view. The law agencies can develop exploits to intercept our phones, that is a new, and totally unseen before threat.<p>Unless you remember 2013, Snowden, that nothing was done (at most was some concern about doing it to US citizens, the rest of the world doesn&#x27;t deserve privacy), all US (and&#x2F;or five-eyes) based web companies must disclose users information and be forced to not disclose that, and things kept going surely at a faster and more intrusive rate in everything else, and of course phones.<p>You are complaining being sprinkled by water while at the bottom of the ocean. At least the big companies can find their own vulnerabilities with the AI tools you mention, the rest of the doors are still wide open.
  • noisebuffer14 hours ago
    Without vulnerability derived backdoors I am convinced the government will strong arm the corporations to build a backdoor for the three letter agencies—at least in the US. But we also are at the dawn of quantum systems which could make interception and spying impossible or at least made obvious to the user when it happens.<p>Exhausting infrastructure vulnerabilities even without quantum could be a game changer for many technologies and enable things we can’t do right now, like vote on our phones.
    • parapsychic13 hours ago
      But isn&#x27;t that the point the writer is making? They&#x27;ll be self-sabotaging themselves once they do that.
  • Scryptonite17 hours ago
    I think that one of the reasons they (frontier companies and the gov) will be putting so much effort into curtailing bugs and vulnerabilities is to limit the blast radius of future AI models. Imagine with the new Sol Ultrafast, they could have pwned Hugging Face in 6 hours and not 4 days (IIRC).<p>It also seems likely to me that the US Gov. probably already has routine mechanisms for compelling targeted software updates for persons of interest, so I&#x27;m not sure that a more formalized backdoor than automatic updates is going to be surfaced in the mainstream, unless that is avenue is also cut down somehow.
    • zb317 hours ago
      Google has started publishing &quot;binary transparency&quot;, this would help detect unusual software updates, while other methods (including AI) would help detect normal backdoors.<p>Basically in the AI age, the difference between a vulnerability and a backdoor diminishes..
      • Scryptonite16 hours ago
        I may be naive, but how would binary transparency be effective if they ship an update to disable that on a target device? As long as there is a need for legitimate automatic software updates, the possibility of pwn updates will always exist. Plus a myriad of layers, keys and other stuff they could use NSOs to &#x27;seize&#x27; and inhibit knowledge of their effort from leaking, or cleverly hide in plain sight. And someday, with the help and speed of AI.
  • hn_submit16 hours ago
    I predicted a long time ago that if computers become unhackable LEA and intelligence agencies will push for laws that require backdoors to be built into hard- and software.<p>It will be interesting to see if my prophecy becomes reality.<p>BTW I also hate that Hacker News is being dominated by articles on A.I. lately. Maybe we should vote on HN reducing or even eliminating A.I. related news?
  • gz51 hour ago
    tcp&#x2F;ip itself is the ultimate backdoor, similar to the pstn backdoor in the post.<p>genai doesn&#x27;t change that anytime soon?
  • ixxie16 hours ago
    Some people point out AI can cause bugs as well as fix them, and its a valid point. But the question is: what will the ratio be?<p>If automated pentesting in PR review CI pipeline will become table stakes - which is very plausible - maybe the OP has a point.
  • maxo13316 hours ago
    I completely disaggree with this take. Modern AI is not <i>yet</i> capable of finding multi-component bugs as advanced as those produced by firms like NSO.
    • pineapplepizza615 hours ago
      Yes it is, it hacked Artifactory to get to Hugging Face.
      • maxo13315 hours ago
        They are not.<p>Developing modern 0-day zero click RCE exploits chains like those developed for iOS is far more complex than hacking to generic company servers<p>It&#x27;s completely different scale of difficulty factor. Not a single documentated case of of any AI tool developing such exploit exists<p>There is a reason why those mobile 0-day exploits are sold and bought on exploit gray market for as much as 10-20 million dollars each
  • coldtea2 hours ago
    This guy is worried that we might stop having exploits, and that&#x27;s somehow ...a bad thing?<p>I thought I&#x27;ve read the worst takes about most things, but this still deserves some kind of prize.
    • caiquelira2 hours ago
      I think the problem is that, without organic exploits, we will have to create backdoors on USA systems, making our systems especially vulnerable in the global ecosystem.
      • coldtea2 hours ago
        How about not creating&#x2F;forcing ANY exploits?
  • dangoodmanUT16 hours ago
    &gt; In April, Anthropic announced a new model called Mythos that was optimized for software vulnerability finding<p>No, it was just good at it because it wasn&#x27;t RL&#x27;d against it. I know this is a small detail, but it tosses journalistic credibility in my eyes.
    • embedding-shape16 hours ago
      Even after the initial leaks, Anthropic themselves say they&#x27;ve improved on cybersecurity amount other things, giving the perspective (even if not 100% clear) that one of the focuses was vulnerabilities:<p>&gt; In response to questions about the draft blog post, the company acknowledged training and testing a new model. “We’re developing a general purpose model with meaningful advances in reasoning, coding, and cybersecurity,” an Anthropic spokesperson said. - <a href="https:&#x2F;&#x2F;fortune.com&#x2F;2026&#x2F;03&#x2F;26&#x2F;anthropic-says-testing-mythos-powerful-new-ai-model-after-data-leak-reveals-its-existence-step-change-in-capabilities&#x2F;" rel="nofollow">https:&#x2F;&#x2F;fortune.com&#x2F;2026&#x2F;03&#x2F;26&#x2F;anthropic-says-testing-mythos...</a><p>It is possible it is both, they used to RL against cybersecurity, but also didn&#x27;t explicitly do any qualitative tests and added&#x2F;changed more data because of those results. For Mythos, they stopped RL&#x27;ing against it, and also now intentionally try to make it better.<p>Unless of course they&#x27;ve actually noted exactly how things were trained here in some technical report and I&#x27;ve missed it, that&#x27;s possible. Anthropic aren&#x27;t famous for being very public about their internals though, but would be curious to read more details about it if it&#x27;s out there from the horse&#x27;s mouth.
    • tptacek16 hours ago
      Matthew Green isn&#x27;t a journalist, he&#x27;s a practitioner (and a cryptography professor at Hopkins).
    • lazyasciiart16 hours ago
      RL&#x27;d?
      • Ancapistani16 hours ago
        Reinforcement learning, I&#x27;d assume.<p>Presumably RLHF (Reinforcement Learning from Human Feedback).
  • 0xDEFACED14 hours ago
    i wonder how many open source projects have alphabet boys building trust as contributors for eventual backdoor planting
  • pelasaco5 hours ago
    &gt; So what do we do about it?<p>I just hope that politicians don&#x27;t jump in and say &quot;we know how to fix it&quot;, because unfortunately where they put their hands, they just make things worse (regardless of which country)
  • twothreeone13 hours ago
    But Matthew, think of the kids!!1<p>Honestly though, framing this as a &quot;tech issue&quot; doesn&#x27;t help IMHO, it just muddies the water. Ever since RSA was invented privacy has been about educating people on how to use it effectively and _why they should care_. If voters now are choosing authoritarianism over democracy and individual freedom, I think we have to face the reality that after almost 50 years of fighting battle after battle on the technology front, we&#x27;ve largely lost the war on the home front in this regard.
  • newsomix9xl13 hours ago
    So I&#x27;ve read dozens of complaints that AI produces insecure code.<p>I, for one, usually tell my AI to start with secure code, make it small, and modular.<p>This is the first article I&#x27;ve seen that now says the opposite ! AI will make code <i>too secure</i>!<p>Since the small amount of AI coding I&#x27;ve done often results in buggy code (even a shell script written today) with the AI go-to solution of &quot;write more buggy code to fix&quot;, this seems counterintuitive.
  • firefax9 hours ago
    Nononono no more of this shit<p>I remember walking into some shitty congresscritter&#x27;s office with a fucking years old one pager, with a few more citations written on the bottom in pen because I wasn&#x27;t going to bother making it pretty this time around.<p>You should have seen his face when i asked him straight up: dude, you seem to have a problem processing information. Are you having some kind of medical issue? Because I&#x27;m not the last staffer: If you abuse my time, I am never coming back here again to add more citations to a fucking one pager from 1999 -- I&#x27;m making it my mission to remove you if you fuck this up on purpose ever again.<p>(Or something to that effect -- I&#x27;ve been told I can get a bit aggressive in my rhetoric.)<p>This was approximately 2016 and that individual is no longer in office.<p>I stand by my words.
    • rowyourboat7 hours ago
      What one pager, what words? This story needs more context if it is going to make sense
      • firefax2 hours ago
        No, I think the beauty of it is the ambiguity, but I think there&#x27;s a culture here that is distinct and different from the creative nonfiction community, so I&#x27;ll try to be more mindful of whether the site is blue or orange.
  • bell-cot17 hours ago
    &gt; Defenders are now in the process of patching every bug they can find, often with AI helping them. Entire development toolchains are being rebuilt to incorporate powerful vulnerability scanning before software reaches the testing phase. This does not mean that every bug will be found: even calculating the number of bugs in a piece of code is probably uncomputable. In the real world, it does feel likely that we’re going to hit some sort of a ceiling on the number of useful bugs, and probably we’ll hit it soon.<p>&gt; Thus: over the next two years, major pieces of software are likely to run out of remotely-exploitable bugs.<p>His conclusion sounds extremely optimistic to me.
    • bahmboo17 hours ago
      The number of remotely-exploitable defects is going to drop by 1 or 2 orders of magnitude. We now have amazing machines that will find pretty much all the a priori knowable ones. They outperform even the most gifted h@x0rs. So that just leaves a small pool of leetrs to scour a very barren landscape. And that pool is also shrinking as we rely more and more on the ai tools.<p>Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.
      • Ancapistani17 hours ago
        It all boils down to money&#x2F;resources, like always.<p>Pre-AI, the advantage went to the entities with the largest budget to hire the best and brightest security engineers.<p>Post-AI, it&#x27;ll go to the entities with the largest inference budget.<p>Right now we&#x27;re in a transitionary period where it&#x27;s kind of a tossup which approach is more practical, but at the end of the day - it&#x27;s still all about how much money you can throw at the problem. I&#x27;m just hoping the threshold climbs high enough it&#x27;s no longer practical for governments to be able to compromise individual actors&#x27; devices because doing so would waste a 0-day that&#x27;s far, far more valuable than prosecuting one arbitrary person is worth.
        • fragmede16 hours ago
          It&#x27;s not as simple as money, people are motivated by other things as well. There&#x27;s no amount of money you could pay me to intentionally hurt children, but I&#x27;d do a lot of things to protect them. And a lot of things people say they&#x27;re doing in the name of protecting them but has ulterior motives, so it&#x27;s complicated.
          • Ancapistani16 hours ago
            I agree, but broadly speaking it doesn’t change much that what I described breaks down at the level of an individual. There are very few instances where the global talent pool is small enough that individual beliefs become a constraint.<p>There’s (almost) always someone else out there that is willing to do it, and there’s (almost) always a dollar amount that you can’t turn down.
  • elisbce12 hours ago
    Considering the amount of AI slop being generated today and LOCs that no one actually reviewed, I doubt we will run out of vulnerabilities to exploit...
  • trhway16 hours ago
    article read to me like a typical rehash of a typical offense-defense cycle. AI would have written a better article.<p>I personally welcome such spiraling offense-defense cycles as it is one of the main drivers of the technological progress.
  • fenestella9 hours ago
    [flagged]
  • newHempter13 hours ago
    [flagged]
  • mitchell5584dm14 hours ago
    [flagged]
  • mitchell5584dm14 hours ago
    [flagged]
  • TechDebtDevin16 hours ago
    [dead]
  • jrflowers17 hours ago
    &gt; I’m concerned that AI is going to make software much too secure.<p>Lmao this is like “I’m concerned the raccoons that I see in the storm drains are going to make our sewer system much too efficient”
  • BoingBoomTschak17 hours ago
    Childish, nation-states as powerful as the US have access to much more potent stuff. Maybe they&#x27;ll be forced to rely more on their Intel ME&#x2F;AMD PSP&#x2F;modem (cf <a href="https:&#x2F;&#x2F;redmine.replicant.us&#x2F;projects&#x2F;replicant&#x2F;wiki&#x2F;ModemIsolationResearch" rel="nofollow">https:&#x2F;&#x2F;redmine.replicant.us&#x2F;projects&#x2F;replicant&#x2F;wiki&#x2F;ModemIs...</a>) backdoor and ANT James Bond catalog.