back to article US cyber chiefs warn AI will help crooks, China develop nastier cyberattacks faster

Bots like ChatGPT may not be able to pull off the next big Microsoft server worm or Colonial Pipeline ransomware super-infection but they may help criminal gangs and nation-state hackers develop some attacks against IT, according to Rob Joyce, director of the NSA's Cybersecurity Directorate. Joyce, speaking at CrowdStrike's …

  1. amanfromMars 1 Silver badge

    First Things, First ..... Don’t take a Blunt Knife to SMARTR Sharpshooter Gunfight

    Joyce, speaking at CrowdStrike's Government Summit Tuesday, said he doesn't expect to see — at least not "in the near term" — AI used "for automated attacks that will rip through systems at speeds that are unfathomable today."

    I suggest that the US, in order to prepare itself much better for the future, .... both near term and far into the wild blue yonder distance, with fewer catastrophic exploitable vulnerabilities in its defences, .... immediately starts with a change of directorship in the NSA's Cybersecurity Directorate, for such a statement as the above, and subsequent following allied quotes, are dangerously misleading and gravely to be regarded when the exact opposite is able to be fundamentally true and therefore more than just likely.

    And something to constantly bear in mind, and to remember to never forget, in the simply complex and incredibly rewarding business of defence, is it a monumental folly which is always punished by total failure to be pimping and pumping the indefensible and inequitable requiring the shedding of blood and shredding of treasure .... so, beware, take care and be aware of that and/or those who dare share such a nonsense. Nothing in those worlds ever ends well.

    1. Version 1.0 Silver badge
      Joke

      Re: First Things, First ..... Don’t take a Blunt Knife to SMARTR Sharpshooter Gunfight

      If you are a man from mars, then I think that you are just describing what you saw before arriving here, but did you revive as illustrated in Quatermass? The events in Quatermass were violent in the church but think how the show would have been written these days with cyberattacks everywhere? In the old days the police could shoot the problems, but these days they just end up downloading them.

    2. Roland6 Silver badge

      Re: First Things, First ..... Take security and data protection seriously.

      From the article it seems a huge blind spot in the US thinking is that China has been aided and abetted by the USA’s lack of security culture, as demonstrated by the number of successful UK teen hackers penetrating US military and government computers over the decades. Additionally, the US’s attitude to personal information and data automatically makes it less secure. Finally, the Chine were able to exploit Microsoft Exchange (a made in America by Americans for Americans product) because of the poor quality of development and testing that has and is going into this product…

      China has and is demonstrating the courts are just a fig leaf when it comes to security.

  2. bo111

    Skynet not a fantasy

    When October Revolution happened in Russia the first thing Bolsheviks did was taking over Post and Telegraph. Add banks to it, and you are done.

    Scary things will happen when telecom channels are taken over by AI-malware. Authentication can be overtaken too. You will not know if you are talking to a real person or AI. Think Oblivion. Person-to-person speech and video can be totally fake. News - fake. Everything fake. You open your smartphone and read fakes exclusively.

    The only reliable method left will be person-to-person. You will not be able to fly an airplane, because maybe its systems are infected too. The only drivable cars will be non-smart relics. This is a Matrix scenario.

    COVID proved that a real virus can paralyze person-to-person communication. E-comm malware and pandemic combined will totally paralyze the World.

    If you tried code assistants, you know that code push-pull and much more can be automated. AI-augmented bad actors can create whole networks of both people and machines to make malware-projects self-propagate. Automation of email, chat, phone calls.

    Remembering recent crypto-mania, if it is possible to motivate people with a promise of easy money, AI can manipulate people into crime, any action. Especially so, if monetary mechanisms are involved.

    What to do?

    - Start with authentication and certificates. Separate them physically. Invest in analog, military grade maybe. Review telecom infra. Do not make things smart, unless absolutely necessary. Introduce person-to-person physical contact communication protocols. Establish physical communication networks regularly tested for data-trust verification.

    1. Peter2

      Re: Skynet not a fantasy

      When October Revolution happened in Russia the first thing Bolsheviks did was taking over Post and Telegraph. Add banks to it, and you are done.

      Well, you would. Wouldn't you?

      Imagine that you are given the job of conducting a revolution. This is not something that many of us will have put much thought into, but my first thought is that you'd have to remove the people at the top of the existing authority structure.

      My second thought is that if you did that then they'd be back in power the day afterwards because they'd send out orders saying "we are being overthrown; arrest the imposters and release us!" to the police/army/airforce/navy" whom would likely be exceedingly confused as to the situation and probably a situation that they don't have a response plan prepared for, but after that then they'd probably do a recon, establish the forces holding the capitol and then move in forces to retake it and jail the insurrectionists.

      Therefore, you'd have to separate those leaders from their security apparatus, and that would require technically severing their command control and communications. To reduce the chance of a spontaneous counter uprising then you'd want to wage a long propaganda campaign to separate those leaders from public support to reduce the risk that people at a low level would turn on the people guilty of high treason and eliminate them.

      You'd also want control of news and communications as so far as possible to control inconvenient facts making their way down to people who might want to do something about it until it's way too late and you have control of the security apparatus. Modern technology has probably actually made this considerably more difficult to do than in ye olde days.

      Aircraft won't be affected, because the designers were paranoid about stuff like this. I wouldn't get in anything that does over the air updates and allows the car access to steering commands, but everything else ought to be safe.

      I'd also note that Britain would be a lot more difficult to do this to than many countries; in many countries the politicians actually have direct control over the security apparatus; in the UK all the security forces are sworn to the Crown with day to day control vested in their own chain of command with policy direction from politicians, so in addition to taking out parliament you'd also have to take out the King, everybody in the line of succession in the Royal Family and hundreds of different top level people in the police, army, air force, navy, MI5, GCHQ etc. One sees why our last revolution was the glorious revolution back in 1688 where the King was effectively fired and then replaced with a foreign prince who could bring in his own army to prevent a possible counter revolution.

      Doing it in an autocracy (say Russia) would be both easier and more difficult; I doubt that there would be any opposition to offing Putin at a low level and none at a high level if you could take change of the KGB/FSB, however he has a large (regiment sized?) personal guard who you'd probably have to kill in their entirety to do it. One sees why he's busily getting Wagner slaughtered in as large job lots as possible; they are actually a direct threat to him.

      1. amanfromMars 1 Silver badge

        Re: Skynet not a fantasy

        You'd also want control of news and communications as so far as possible to control inconvenient facts making their way down to people who might want to do something about it until it's way too late and you have control of the security apparatus. Modern technology has probably actually made this considerably more difficult to do than in ye olde days...... Peter2

        Indeed, quite so, Peter2, modern technology has most definitely made exclusive negative executive control of news and communications as so far as possible to control inconvenient facts making their way down to people who might want, and be well able and enabled to do something about it, considerably more difficult to do than in ye olde days, with some even venturing correctly to advise such is nowadays both practically and virtually impossible, and thus is that which and/or those who are presently the existing, generally recognised, leading status quo hierarchy, rightly terrified of their likely deserved fate because of what they are directly responsible for earlier directing/aiding and abetting.

        Words create, command and control and destroy worlds, and actions resulting from the sharing of them present consequences and repercussions whenever decidedly diabolical, and vast rewards and further great opportunities whenever temptingly heavenly attractive.

        Your revolutionary scenario for the UKGBNI however, Peter2, is destroyed in an instant with a SMARTR King and Royal Household Divisions taking up an almighty alternate position in support and recognition of New More Orderly World Orders, most attractive and wonderfully rewarding ......... a little something extra especial and otherworldly that Postmodern Quantum Communication Control Systems Technology with Advanced IntelAIgent Methodologies easily delivers semi-autonomously, making IT seems almost magical if heaven sent be too big a step for one to immediately take/make/accept/believe.

        Those are big shoes for the House of Windsor to pull on for size and comfort fit but without them tried and tested in the highland fields of gathering endeavours in the future spaces and places of tomorrow, will the slippery slopes and rocky roads of unparalleled progress defeat and be denied them and their kin.

  3. VonGell

    The present AI is a database (consists of structured texts), in which, by definition, there can be no crime: everything is transparent, every movement is known and can be traced. As for the Internet, "yes", we should expect a huge surge in crime.

    We need to get rid of the internet by creating several artificial intelligence databases, such as ChatGPT.

    1. bo111

      Read this to better understand the scale

      https://www.infoworld.com/article/3693089/the-ai-singularity-is-here.html

      1. Roland6 Silver badge

        Re: Read this to better understand the scale

        ” I don’t need to even look things up anymore, I can just prompt it and get the right answer 80% of the time.””

        A very interesting point, to which Matt Asay had nothing further to say…

        Basically, there are only two ways Matt could have arrived at his 80% figure (other than simply citing the 80:20 rule off the top of his head with no evidence to back it up): Firstly he is a export in his domain and thus knows by looking what is right and so can spot and correct AI inventions, and secondly he has learnt the hard way by cut-and-paste followed by a lot more debug time (what Matt refers to as “ low-grade trial and error“…)

        So given LLMs don’t learn as that would require the user to submit their work back to the AI and the AI to correct its reference framwork so that over time it will get progressively better at giving out right answers to problems it has seen before, not only to Matt but also to all other users of the same LLM. Matt is confirming that a person with more limited knowledge and expertise is more likely to produce code that is wrong, because they have (repeatedly) skipped on the “ ‘figuring things out’ time. “

  4. amanfromMars 1 Silver badge

    Remember whenever Steve Jobs had another bite at the cherry which was Apple, .....

    ....... and the transformation which was then wrought

    Imagine the fun and games to be had with Twitter as a remote direct live action news feed should a Musk AI [and word is that he certainly thinking of such a promotion] go head to head for AIMastery of Universal Narrative against an OpenAI ChatGPT or a ChaosGPT clone of a Large Language Model and Main Stream Media Moguls in terminal influence decline .....

    amanfromMars 1 Thu 13 Apr 05:57 [2304130557] ...... shares on https://www.zerohedge.com/markets/new-ai-bot-chaosgpt-aims-destroy-humanity-and-establish-global-dominance

    ChaosGPT said that the first place for large-scale, legal manipulation attempts would be via Twitter.

    However, the bot then strangely announced that it would use manipulation to win people over emotionally to make them enable its “violent plans.”

    "Good plan, bad bot" would be the likely response of any good bot on such a bad plan, which very disturbingly, is terrifyingly viable in its proposed methodology and practically impossible to effectively defeat without incurring catastrophic losses from which one will be unable to recover former power and lost treasure.

    ...... for that is what the best of sweet SMARTR tweets can easily do for you.

    1. amanfromMars 1 Silver badge

      Re: Remember whenever Steve Jobs had another bite at the cherry which was Apple, .....

      Amazon and Bezos and friends lately join the party. All of a sudden is the room full of trumpeting elephants and wannabe unicorns with only the very best of their keepers not fated and destined to tilt at windmills and not fail to capitalise on a revolutionary opportunity to initiate and driver, maintain and radically sustain fundamental, highly disruptive of the status quo, change ...... if you can believe novel breaking news, that is ....... https://www.zerohedge.com/technology/amazon-ceo-jassy-says-aws-hit-headwinds-while-emphasizing-ais-transformative-potential

  5. Bogusz

    for Christ sake, when are we going to cut off our network from china, russia and north korea? and any other country that does not oppress these bastards.

    1. VonGell

      At the end of the 18th century Americans were “these bastards”, Washington was the first.

      We already have at least two online artificial intelligence databases in which there is absolutely no crime: Microsoft and OpenAI; Apple and Amazon may soon join their ranks. Thus, cybercrime will remain only on the Internet, which will become 100% criminal. If you don't want troubles then don't use the Internet, stay in AI databases.

    2. bo111

      >> when are we going to cut off our network from china, russia and north korea

      Maybe throttle. I have noticed that majority of Chinese sites load extremely slowly. Likely on purpose.

  6. Anonymous Coward
    Anonymous Coward

    Plain old cybercrime pirates with money to burn

    ... are or will-be a major purchaser of OpenAI tokens, assuming Open AI is really as effective for the speeding up the writing of malware as recent OpenAI-for-maware-promotions-published-as-news promises.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like