Totally flirting for your password…

What does a world with automated social engineering look like?

And how should that change the way we approach security and disclosure?

So what exactly is new?

  • We can make text bots that far more realistically imitate a conversation with a human.
  • We can make human quality speech from text. We can even imitate voices of a particular person extremely well.

How do we currently think about security and vulnerability disclosure?

  • Full disclosure — just publish it all — including ideally a proof of concept. This gets things fixed faster, and helps avoid repeating the problem in future products.
  • Coordinated disclosure — where security researchers work with vendors to minimize total harm from vulnerability — though of course this only makes sense if vendors are cooperative and responsive.

What this means for AI advances

So what do you do?

  • “Ask for source” — meaning that someone would need to reach out to the exploit author, or some designee, in order to get the proof of concept code; perhaps undergoing some vetting process first. This currently sometimes exists on an ad-hoc basis, but trusted institutions could be adapted to manage access with vetting perhaps analogous to biosafety levels in biology.
  • “POC as a service” — where the author or their designee would maintain control of the POC (proof of concept) code, and if someone wanted a demonstration, the POC code would be run from their servers. This lets use of POC code be permissioned and/or logged, hopefully preventing malicious use.
  • What if a POC for an “automated NLP big data spear phishing system” used ask-for-source?
  • What if a “google duplex” for social engineering used proof-of-concept-as-a-service?

--

--

Founder of the Thoughtful Technology Project & GMF non-res fellow. Prev Tow fellow & Chief Technologist @ Center for Social Media Responsibility. av@aviv.me

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Aviv Ovadya

Founder of the Thoughtful Technology Project & GMF non-res fellow. Prev Tow fellow & Chief Technologist @ Center for Social Media Responsibility. av@aviv.me