‘Never-ending’ AI slop strains corporate hacking reward schemes - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
FT商学院

‘Never-ending’ AI slop strains corporate hacking reward schemes

‘Bug bounty’ programmes have seen a jump in spurious AI-generated submissions
00:00

{"text":[[{"start":7.65,"text":"Companies that pay hackers to find flaws in their software are being inundated with low-quality reports generated by AI, forcing some to suspend the programmes altogether. "}],[{"start":18.85,"text":"Businesses that run “bug bounty” schemes have long relied on independent security researchers to spot vulnerabilities. But the rise of AI tools is now overwhelming them with spurious submissions. "}],[{"start":30.950000000000003,"text":"Bugcrowd, whose customers include OpenAI, T-Mobile and Motorola, said the number of reports it received more than quadrupled over a three-week period in March, with most proving to be false. "}],[{"start":43.900000000000006,"text":"Curl, a widely used tool to transfer data across the internet, suspended its paid bug bounty programme in January, citing an “explosion in AI slop reports” and lower-quality submissions. "}],[{"start":55.300000000000004,"text":"Cyber security experts say advances in generative AI are reshaping the economics of bug bounty programmes. While the tools allow experienced researchers to find flaws more quickly, they are also lowering the barrier to entry, triggering a flood of automated or erroneous submissions that companies must sift through."}],[{"start":null,"text":"

The Nextcloud logo displayed on a smartphone screen, with blurred colored lights in the background.
"}],[{"start":75,"text":"The big increase in poor-quality AI reports was “quickly becoming a major problem”, said Ross McKerchar, chief information security officer at cyber security group Sophos. “Bug bounties are going to stay [but] they’re going to have to change,” he said."}],[{"start":89.95,"text":"Bug bounties have grown in popularity since the early 2000s, with schemes offering six-figure payouts for the biggest discoveries. Google’s programme disbursed a total of $17mn last year, up from $7.5mn in 2021. It paid its largest individual reward of $605,000 in 2022 to a user who spotted a vulnerability in its Android mobile operating system."}],[{"start":118.2,"text":"McKerchar said the rise in poor-quality submissions came from both amateurs trying to find bugs for the first time and existing researchers who were “sometimes getting led on by the [AI] agents”. "}],[{"start":130.4,"text":"He added there was a “third cohort” of “experienced AI builders” who had developed automated “end-to-end scanning and submission systems” that were “creating absolute carnage”."}],[{"start":142.35,"text":"Curl’s creator Daniel Stenberg wrote in a blog post that the “never-ending slop” had taken “a serious mental toll to manage and sometimes also a long time to debunk”."}],[{"start":153.6,"text":"Software group Nextcloud suspended its bug bounty programme in April because of the “massive increase of low-quality reports”. It said it hoped to resume the programme once it had found a way to filter submissions effectively."}],[{"start":167.5,"text":"The surge in AI-generated reports comes as Anthropic last month launched Mythos, its new cyber AI model, which it says can find software flaws faster than humans."}],[{"start":178.3,"text":"Companies running bounty bug programmes have started to introduce more stringent background checks to combat the problem, as well as building AI agents to triage submissions. "}],[{"start":188.20000000000002,"text":"HackerOne, whose bug-reporting platform serves Goldman Sachs, Google and the US Department of Defense, said it had “introduced new agentic validation capabilities” this year to “help organisations manage high volumes of findings”, such as those generated by models like Mythos."}],[{"start":205.10000000000002,"text":"The company said submissions had jumped 76 per cent in the year to March. But it said the share of reports flagging legitimate vulnerabilities had remained steady over the past year at 25 per cent."}],[{"start":217.00000000000003,"text":"HackerOne chief executive Kara Sprague said it had in recent weeks seen a rise in “higher quality” reports that had used AI. She added that the rise in AI-generated submissions was “not a strong reason to say we don’t want them” altogether, given that hackers were using the technology to spot more flaws."}],[{"start":235.85000000000002,"text":"Bugcrowd chief Dave Gerry said developments such as Anthropic’s Mythos would assist human bug bounty hunters, not replace them. “AI is going to help with a lot of things but we’re never going to replace that human creativity,” he said."}],[{"start":256.75,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1779001094_2483.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

现代战争的血腥一如往昔

科技的进步并没有减少俄乌战争中的伤亡,武装无人机和AI正把前线变成险恶的杀戮地带,惨烈程度堪比一战。

帕拉贝利斯医药公司于与再生元达成交易次日披露IPO计划,上市热潮升温

成立已有十年且资金雄厚、从格雷格•维尔丁在哈佛实验室孵化出的“不可成药”生物技术公司——帕拉贝利斯医药公司,正寻求成为今年第12家进行首次公开募股的药物研发企业
17小时前

英伟达部署900亿美元助推AI繁荣

黄仁勋正成为依赖其芯片的AI相关公司的最大资助者之一。这些支出涉及逾145家公司,从AI模型开发商、云服务提供商到基础设施供应商不一而足。

Lex专栏:股市投资者信心爆棚,但现金见底

鉴于标普500指数高度依赖以人工智能为驱动的公司,股市出现小问题和大问题的可能性都很大。

FT社评:埃博拉疫情暴露全球应对大流行病准备不足

援助资金减少以及特朗普政府对全球公共卫生理念的敌意,正危及我们所有人。

“四大”急聘AI专业人才,岗位数量盖过传统审计师

全球最大的几家会计师事务所正竞相适应颠覆性的技术变革。
设置字号×
最小
较小
默认
较大
最大
分享×