news.mlab.sh
Back to the feed
threat-intel

Smashing Security podcast #470: This AI security flaw might be impossible to fix

Medium
Summary

This Smashing Security podcast episode focuses on the potential for persistent security vulnerabilities, particularly related to large language models (LLMs) and prompt injection. The discussion highlights the risk of insecure code generated by LLMs and the importance of careful code review, especially when dealing with AI-generated solutions. ESET is sponsoring the episode and promoting Tanya Janca’s new book, "Alice and Bob Learn Secure Coding," which addresses this issue.

The podcast episode centers around the ongoing challenge of ensuring the security of code generated by AI, specifically LLMs. Tanya Janca discusses a Cornell University paper exploring the possibility that prompt injection vulnerabilities could be ‘forever’ – meaning they are difficult, if not impossible, to fully eliminate. The conversation pivots to the importance of vigilance when using LLMs for code generation, emphasizing the need for thorough review and testing to prevent insecure code from being deployed. The episode also touches on broader security concerns, referencing instances of data breaches involving password vaults and highlighting the potential for subtle policy exceptions to create vulnerabilities, as exemplified by a case involving a Microsoft 365 tenant.

Read the full article at Graham Cluley