Security

Carbon-based vuln hunters will always be better at infosec than AI, insist puny humans

No intelligent pentesting systems were available to comment on this assertion


Puny humans still think they're superior to AI when it comes to infosec – and a significant number still don't venture into meatspace or get enough sunlight.

So reckons a survey carried out on behalf of Bugcrowd, which also made the edifying finding that 64 per cent of independent infosec researchers are on median incomes below $25,000/year – with half being aged 24 or younger.

Bugcrowd, which competes with HackerOne in the "crowdsourced security" bug bounty market, released its "In The Mind of a Hacker" report to shed some light on the sorts of people using its services. While it referred to them throughout as "hackers", it meant both infosec researchers and pentesters who claim bug bounties through its platform – the people whose work helps thwart criminal hackers with bad intentions.

Financial reward was not the number-one motivation of the survey's 3,500 respondents either: just under a third (30 per cent) said "learning" was their main motivation, followed by a quarter who cheerfully admitted they were doing it for the cash. A fifth said they enjoyed the problem-solving element of vuln hunting.

"Hackers will always be one step ahead of AI when it comes to cybersecurity because humans are not confined by the logical limitations of machine intelligence," said Jasmin Landry, top-ranked Bugcrowd hacker. "For example, hackers can adapt four to five low-impact bugs to exploit a single high-impact attack vector that AI would likely miss without the creative flexibility of human decision-making."

Eye-catchingly, or perhaps not, the company's survey found that 87 per cent of humans agreed with Landry. No AI pentesting solutions were asked to respond.

Of the 3,500 people who answered the survey, just under half (48 per cent) reckoned healthcare orgs were most vulnerable to cybercrime during the COVID-19 pandemic. Although some ransomware gangs announced earlier this year they would stop targeting healthcare organisations, other notable names from the underworld declined to join those calls.

Bugcrowd also asked ethical infosec researchers how much sunshine they had access to during the year. A third answered "less than three hours a day", helping reinforce the stereotype that begins with an angry young man hiding inside a hoodie, an image 71 per cent said depicted them. And yes, at present it's almost always men: 94 per cent of respondents said they were male. ®

Send us news
2 Comments

Google Cloud chief is really psyched about this AI thing

We're on a highway to ML

AI spam is winning the battle against search engine quality

'Not all AI content is spam, but I think right now all spam is AI content'

What's up with AI lately? Let's start with soaring costs, public anger, regulations...

'Obtaining genuine consent for training data collection is especially challenging' industry sages say

Psst, hey. It's the NSA. You want some AI security advice?

You can trust us, we're the good guys

Intel CEO suggests AI can help to create a one-person Unicorn

And possibly replace entire business units too

Hailo's latest AI chip shows up integrated NPUs and sips power like fine wine

All your PC needs for 40 TOPS is an M.2 slot

Microsoft puts ex-DeepMind boffin in charge of London AI hub

Follows £2.5 billion pledge to 'upskill' British workers for the new world order

US House mulls forcing AI makers to reveal use of copyrighted training data

Proposed law doesn't include any ban on use of such stuff to build models, mind you

British watchdog has 'real concerns' about the staggering love-in between cloud giants and AI upstarts

Billions in investment? Yeeeah, right – looks more like ensuring only select few developers thrive

AI could crash democracy and cause wars, warns Japan's NTT

Calls for ecosystem in which AIs keep other AIs in check, and lots more regulation

Devaluing content created by AI is lazy and ignores history

The answer is not to hide from ML, but to be honest about it

Tech titans assemble to decide which jobs AI should cut first

But don't worry, if tech takes your job, we'll retrain you