Hackers: We wont let artificial intelligence get the better of us – ComputerWeekly.com
Artificial intelligence (AI) doesnt stand a chance of being able to replicate the human creativity needed to become an ethical hacker, but it will disrupt how hackers conduct penetration testing and work on bug bounty programmes, and is already increasing the value of hacking to organisations that are prepared to engage with the hacking community rather than dismiss it outright.
This is according to the hackers who contributed to the latest edition of Inside the mind of a hacker (ITMOAH), an annual report from crowdsourced penetration testing firm Bugcrowd, which sets out to offer an in-depth look at how hackers think and function, and why they do the things they do. This year unsurprisingly leans into AI in a big way.
When it came to the existential questions around whether or not AI could outperform the average hacker or render them irrelevant, 21% of respondents said AI was already outperforming them, and a third said it will be able to do so given another five years or so.
The vast majority, 78%, said AI would disrupt how they work on penetration testing or bug bounty programmes some time between now and 2028, with 40% saying it has already changed the way people hack, and 91% of hackers saying generative AI either has already, or will in future, increase the value of their work.
Outperforming a human doing repetitive, sometimes monotonous, work such as data analysis is one thing, but hacking as a vocation also encourages creativity of thought, and it is here that the community seems to feel humans will continue to have an edge, with 72% saying they did not think AI will ever be able to replicate these qualities.
Ive done a fair amount with AI, and as impressive as it is, I dont think it will be replacing humans for quite some time, if ever, said one respondent, a 20-year cyber security veteran who hacks on the Bugcrowd platform using the handle Nerdwell.
AI is very good at what it does pattern recognition and applying well-known solutions to well-known problems, he said. Humans are biologically designed to seek out novelty and curiosity. Our brains are literally wired to be creative and find novel solutions to novel problems.
Another Bugcrowd hacker, who goes by the handle OrwaGodfather, added: AI is great, but it will not replace me. There are some bugs and issues, just like any other technology.
It can have an effect on my place in hacking, though. For example, automation has huge potential to help hackers, said OrwaGodfather, who started hacking in 2020 and when away from his keyboard works as a professional chef.
It can make things easier and save time, he said. If I find a bug when performing a pen test and I dont want to spend 30 minutes writing a report, I can start by using AI to write descriptions for me. AI makes hacking faster.
Whatever their gut feelings may be, Bugcrowds hackers are scrambling aboard the AI train, with 85% saying they had played around with generative AI technology, and 64% already incorporating it into their security workflows in some way a further 30% said they planned to do this in the future.
Hackers who have adopted or who plan to adopt generative AI are most inclined to use Open AIs ChatGPT (a Bugcrowd customer) cited by 98% of respondents with Googles Bard and Microsofts Bing Chat AI at 40%.
Those that have taken the plunge are using generative AI technology in a wide variety of ways, with the most commonly used functions being text summarisation or generation, code generation, search enhancement, chatbots, image generation, data design, collection or summarisation, and machine learning.
Within security research workflows specifically, hackers said they found generative AI most useful to automate tasks, analyse data, and identify and validate vulnerabilities. Less widely used applications included conducting reconnaissance, categorising threats, detecting anomalies, prioritising risk and building training models.
Many hackers who are not native English speakers or not fluent in English are also using services such as ChatGPT to translate or write reports and bug submissions, and fuel more collaboration across national borders.
Over the past decade, Bugcrowds annual report has also served a secondary purpose, that of helping to humanise the hacking community and disrupt negative and unhelpful stereotypes of what a hacker actually is.
This is particularly important given that, in spite of years of pushback and attempts to educate, many people who should know better readily and intentionally conflate the term hacker with the term cyber criminal.
Weve taken on the responsibility of helping the market understand what a hacker actually is, Casey Ellis, Bugcrowd founder, chief technology officer and report co-author told Computer Weekly at the recent Infosecurity Europe cyber trade fair.
I think when we started, everyone assumed it was a bad thing, he said. Some 10 years on, were now at a point where people understand that hacking is actually a skill set. Like most skill sets, its dual-use. Its like lockpicking. If youve got that skill, you can become a locksmith, or a burglar. Theres nothing wrong with lockpicking its how youre actually using it. Hacking is the same.
The 2023 ITMOAH report shows how some fundamental shifts in hacker culture and demographics look set to shake up the cyber security landscape in the coming years.
For the first time, the report reveals, the majority of active hackers, between 55% and 60%, are now members of the Generation Z cohort currently in their teens and early 20s, while between 33% and 36% are Millennials aged from their late 20s to early 40s.
And despite hackings cultural roots in the 1980s, only 2% are members of Generation X, those born between the mid-1960s and approximately 1980, the youngest of whom are now about 45 years old.
So, are the stereotypes of teenage hackers actually proving accurate, and more pertinently, are the kids all right? Were seeing a pretty rapid acceleration of participation from people that are under 18, said Ellis. Its still a very small population, only 6%, but its up from 3% year-on-year, which is a big shift.
He said this trend will become increasingly relevant because todays teenagers think about technology in a fundamentally different way to those born even a few short years earlier.
Ive got a 15-year-old daughter and the way she interacts with technology is completely different to me, said Ellis. Her introduction to technology was all about the interface mine was all about the plumbing. We just think about the internet in a fundamentally different way.
Now, I know stuff that shell never know because I grew up with the nuts and bolts, but shell think about the interface in a way that I probably never will because Im so consumed with the nuts and bolts.
You talk about Millennials as digital natives, but Gen Z and younger are actually digital natives, he said. Theyre able to wander through that environment in an intuitive way that we cant really understand. I can try to empathise with that, and I can get most of the way there, but I recognise the fact Ill never fully understand because its not my experience.
This generation is also proving adept at challenging the mores and assumptions of their elders that have often been built into technology, and Ellis said this gives them an advantage in figuring out what is coming next, and where future vulnerabilities may lie.
The other part of this trend is that todays teens are more politically and socially motivated, and more diverse, in ways that older people are not. This factor is already changing the cyber landscape and will certainly continue to do so.
Take Lapsus$, the teenage-run cyber extortion collective that attacked the systems of ride-sharing service Uber in 2022 for no particular reason other than they didnt care for Ubers ethics.
One of the big things that Ive been saying since Lapssus$ is that as defenders, were not ready for a chaotic act, said Ellis. Weve been thinking about cyber criminals, nation states, threat actors as having a symmetric motivation.
A nation state wants to advance the nation, cyber criminals want money. Theyre predictable. And there is symmetry in what theyre doing. Folks that come in with more of an activism bent, you dont really know what they want. And in the case of Lapsus$, its like we just want to make a mess because those guys suck. How do you defend against that? We havent really been thinking in that way since Lulzsec, which was probably the last example of a group that did that.
Of course, the teens on Bugcrowds platform are not attacking organisations in the same sense as Lapssus$ did, but in its story there is a lesson for the hacking community, and the defenders, and clearly the potential to channel activity that might otherwise be expended on malicious acts into legitimate security work is immense.
The full report, which can be downloaded to read in full from Bugcrowd, contains a wealth of additional insight into hacker demographics the gender gap is increasing, likely due to the extra pressure the Covid-19 pandemic put on many women motivations to hack, what hackers think ordinary security teams need to do better, and more besides.
Read the rest here:
Hackers: We wont let artificial intelligence get the better of us - ComputerWeekly.com
- Perspectives in Artificial Intelligence: Creating jobs, not replacing them - Marquette Today - November 23rd, 2024 [November 23rd, 2024]
- Top 3 Artificial Intelligence (AI) Coins of the Third Week of November 2024 - BeInCrypto - November 23rd, 2024 [November 23rd, 2024]
- ZICC: Internet Experts Pay Attention To The Development Of Artificial Intelligence - Barchart - November 23rd, 2024 [November 23rd, 2024]
- How To Elevate Irrigation With Artificial Intelligence - The Scoop - - November 23rd, 2024 [November 23rd, 2024]
- 32.4% of Warren Buffett's $292 Billion Portfolio Is Invested in 4 Artificial Intelligence (AI) Stocks - Yahoo Finance - November 23rd, 2024 [November 23rd, 2024]
- ZICC: Internet Experts Pay Attention to the Development of Artificial Intelligence - Yahoo Finance - November 23rd, 2024 [November 23rd, 2024]
- Billionaire Israel Englander Is Selling Nvidia and Buying These Other Artificial Intelligence (AI) Stocks Instead - The Motley Fool - November 23rd, 2024 [November 23rd, 2024]
- Here Are My Top Artificial Intelligence (AI) Stocks to Buy Right Now (Hint: Not Nvidia) - The Motley Fool - November 23rd, 2024 [November 23rd, 2024]
- [Webinar] The Shifting E-Discovery Landscape From Artificial Intelligence to Antitrust, What the Trends Indicate About How to Prepare for 2025 -... - November 23rd, 2024 [November 23rd, 2024]
- ZICC: Internet Experts Pay Attention to the Development of Artificial Intelligence - WV News - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence and the Future of Work - American Enterprise Institute - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence News for the Week of November 22; Updates from IBM, Microsoft, NVIDIA & More - Solutions Review - November 23rd, 2024 [November 23rd, 2024]
- $159 Billion Artificial Intelligence in Robotics Global - GlobeNewswire - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence Can Improve Access to Justice, But the Legal Profession Has a Role to Play - The Federalist Society - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence for IT Operations Platform Market Transforming IT Efficiency with Next-Gen AI Solutions - openPR - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence of Things Market Merging AI and IoT for Intelligent Automation - openPR - November 23rd, 2024 [November 23rd, 2024]
- Prediction: This Artificial Intelligence (AI) Stock Is Going to Soar Higher After Nov. 26 - The Motley Fool - November 23rd, 2024 [November 23rd, 2024]
- The very real constraints on artificial intelligence in 2025 - The Economist - November 23rd, 2024 [November 23rd, 2024]
- How Artificial Intelligence (AI) Influence on Nuclear Energy Industry is Providing Lucrative Opportunity - GlobeNewswire - November 23rd, 2024 [November 23rd, 2024]
- COVAR to explore ethical use of artificial intelligence (AI) and machine autonomy in military applications - Military & Aerospace Electronics - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence (AI) Could Become a Game Changer for This Company. Should You Buy Its Stock Right Now? - The Motley Fool - November 23rd, 2024 [November 23rd, 2024]
- AI Fatigue: Why the Buzz Around Artificial Intelligence Feels Like A Broken Record - Tech Business News - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence Has Entered the Nuclear Industry and Its Early Benefits Are Just the Tip of the Iceberg - POWER magazine - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence (AI) Is Set to Drive Sizzling Growth in This Market: Here's 1 Stock That Could Win Big From This Emerging Opportunity - The... - November 23rd, 2024 [November 23rd, 2024]
- Founder of artificial intelligence company used by schools in Los Angeles, NYC, Atlanta is arrested - ABC News - November 23rd, 2024 [November 23rd, 2024]
- Artificial Intelligence (AI) Could Become a Game Changer for This Company. Should You Buy Its Stock Right Now? - Yahoo! Voices - November 23rd, 2024 [November 23rd, 2024]
- The Microsoft vision of artificial intelligence in Latin America - BNamericas English - November 23rd, 2024 [November 23rd, 2024]
- Billionaires Are Buying This 1 Top Artificial Intelligence (AI) Stock. Should You Follow Suit? - The Motley Fool - November 21st, 2024 [November 21st, 2024]
- Computers unleashed economic growth. Will artificial intelligence? - The Economist - November 21st, 2024 [November 21st, 2024]
- Leveraging artificial intelligence to tackle climate change - Brookings Institution - November 21st, 2024 [November 21st, 2024]
- Understanding Artificial Intelligence in Tax and Customs Administration - International Monetary Fund - November 21st, 2024 [November 21st, 2024]
- SAU Professor Expands Knowledge of how to Build more inclusive Artificial Intelligence Community - Saint Augustine's University - November 21st, 2024 [November 21st, 2024]
- Using artificial intelligence to personalize infection treatment and address antimicrobial resistance - Medical Xpress - November 21st, 2024 [November 21st, 2024]
- Omdia Features Chetu in Its "On the Radar" Report, Highlighting Its Innovative Artificial Intelligence Solutions - Business Wire - November 21st, 2024 [November 21st, 2024]
- Jeff Dunham Artificial Intelligence tour at the Giant Center: Where to buy tickets - PennLive - November 21st, 2024 [November 21st, 2024]
- Webinar on Artificial Intelligence (AI) in Vaccine Research & Development - World Health Organization - November 21st, 2024 [November 21st, 2024]
- Aclara Secures Funding from Corfo's Innovation High-Tech Program for Artificial Intelligence Project - AccessWire - November 21st, 2024 [November 21st, 2024]
- Artificial Intelligence Is Putting Ever-Increasing Demands on Our Resources - NUVO Magazine - November 21st, 2024 [November 21st, 2024]
- Ajax IndoorCam: wireless IP camera with built-in artificial intelligence and security functions - gagadget.com - November 21st, 2024 [November 21st, 2024]
- Why the Next Big Artificial Intelligence (AI) Play Could be in the Nuclear Power Industry - GlobeNewswire - November 21st, 2024 [November 21st, 2024]
- Even mom-and-pops are investing in artificial intelligence - Restaurant Business Online - November 21st, 2024 [November 21st, 2024]
- Addressing The Future of Artificial Intelligence in Union Operations, on State of Affairs - ROI-NJ.com - November 21st, 2024 [November 21st, 2024]
- Virtus Artificial Intelligence & Technology Opportunities Fund Announces Distributions and Discloses Sources of Distribution Section 19(a) Notice... - November 21st, 2024 [November 21st, 2024]
- Artificial intelligence in UK financial services - 2024 - Bank of England - November 21st, 2024 [November 21st, 2024]
- A Once-in-a-Decade Investment Opportunity: 1 Little-Known Vanguard Index Fund to Buy for the Artificial Intelligence (AI) Boom - The Motley Fool - November 21st, 2024 [November 21st, 2024]
- Got $3,000? 3 Artificial Intelligence (AI) Stocks to Buy and Hold for the Long Term - Yahoo Finance - November 21st, 2024 [November 21st, 2024]
- Leveraging Biological Principles and Artificial Intelligence to Transform Customer Interactions - USA TODAY - November 21st, 2024 [November 21st, 2024]
- Artificial Intelligence To Reverse Mass Insect Extinction - WION - November 21st, 2024 [November 21st, 2024]
- Join us for an exclusive panel event on artificial intelligence - The Independent - November 21st, 2024 [November 21st, 2024]
- How artificial intelligence helped country music icon Randy Travis get back his renowned singing voice - MSN - November 21st, 2024 [November 21st, 2024]
- The Silent Predator: Protecting Children in the Age of Generative Artificial Intelligence - JURIST - November 21st, 2024 [November 21st, 2024]
- Is It Finally Time to Buy This Beaten-Down Artificial Intelligence (AI) Stock? - The Motley Fool - November 21st, 2024 [November 21st, 2024]
- War and Peace in the Age of Artificial Intelligence - Foreign Affairs Magazine - November 19th, 2024 [November 19th, 2024]
- These Artificial Intelligence (AI) Stocks Have Soared Since Trump Won the Election, but Should You Buy? - Yahoo Finance - November 19th, 2024 [November 19th, 2024]
- 'Genesis' looks at the future of artificial intelligence - MSNBC - November 19th, 2024 [November 19th, 2024]
- The Artificial Intelligence (AI) Boom Isn't Over. 3 AI Stocks to Buy Right Now. - The Motley Fool - November 19th, 2024 [November 19th, 2024]
- 1 Soaring Artificial Intelligence (AI) Stock to Buy and Hold for 10 Years (Hint: It's Not Nvidia) - Yahoo Finance - November 19th, 2024 [November 19th, 2024]
- Got $3,000? 3 Artificial Intelligence (AI) Stocks to Buy and Hold for the Long Term - Yahoo! Voices - November 19th, 2024 [November 19th, 2024]
- Artificial intelligence, international security, and the risk of war - Brookings Institution - November 19th, 2024 [November 19th, 2024]
- The role of artificial intelligence in cyber resilience - Security Magazine - November 19th, 2024 [November 19th, 2024]
- Artificial Intelligence and the health workforce - OECD - November 19th, 2024 [November 19th, 2024]
- Artificial intelligence is in your future - Huntsville Item - November 19th, 2024 [November 19th, 2024]
- Nvidia Just Invested in This Small Artificial Intelligence Company -- Should You Be Next? - The Motley Fool - November 19th, 2024 [November 19th, 2024]
- Billionaire Stanley Druckenmiller Just Sold All of His Nvidia Shares and Bought This Rapidly Growing Artificial Intelligence Stock-Split Stock -... - November 19th, 2024 [November 19th, 2024]
- Nvidia Just Invested in This Small Artificial Intelligence Company -- Should You Be Next? - Nasdaq - November 19th, 2024 [November 19th, 2024]
- Billionaire Philippe Laffont Sold 80% of Coatue's Stake in Nvidia and Is Piling Into This Historically Cheap Artificial Intelligence (AI) Stock... - November 19th, 2024 [November 19th, 2024]
- These Artificial Intelligence (AI) Stocks Have Soared Since Trump Won the Election, but Should You Buy? - The Motley Fool - November 19th, 2024 [November 19th, 2024]
- Artificial Intelligence and Relationships: 1 in 4 Young Adults Believe AI Partners Could Replace Real-life Romance - Institute for Family Studies - November 19th, 2024 [November 19th, 2024]
- AI-Fi, the Heart of Decentralised Finance and Artificial Intelligence - Finance Magnates - November 19th, 2024 [November 19th, 2024]
- Got $3,000? 3 Artificial Intelligence (AI) Stocks to Buy and Hold for the Long Term - sharewise.com - November 19th, 2024 [November 19th, 2024]
- Artificial intelligence (AI) and cryptocurrency: Revolutionizing the future of finance and technology - Dataconomy - November 19th, 2024 [November 19th, 2024]
- Assessing potential future artificial intelligence risks, benefits and policy imperatives - OECD - November 19th, 2024 [November 19th, 2024]
- Artificial intelligence can be used to predict river discharge and warn of potential flooding, new Concordia study shows - Concordia University News - November 19th, 2024 [November 19th, 2024]
- UFC enters into groundbreaking Artificial Intelligence (AI) partnership with IBM: Here's everything you need to know - Sportskeeda - November 19th, 2024 [November 19th, 2024]
- Navigating the Future: The Telecom Artificial Intelligence Software, Hardware, and Services Market Outlook - openPR - November 19th, 2024 [November 19th, 2024]
- 2 Artificial Intelligence (AI) Stocks to Buy on the Dip - Yahoo! Voices - November 19th, 2024 [November 19th, 2024]
- This Magnificent Artificial Intelligence (AI) Stock Has Crushed Nvidia in the Past Year. Can It Continue to Skyrocket in 2025? - The Motley Fool - November 19th, 2024 [November 19th, 2024]
- The Impact of Artificial Intelligence on the 2024 Election - Government Technology - November 16th, 2024 [November 16th, 2024]
- AI researcher Gary Marcus: The future of artificial intelligence is darker with Trump in the White House - EL PAS USA - November 16th, 2024 [November 16th, 2024]
- Artificial Intelligence Conference Examines Impacts on Health care, Research, Education - UAMS News - November 16th, 2024 [November 16th, 2024]