An AI breaks the security of three commercial programs
Three commercial programs. About five hours in total, according to his account. A developer who reports software bugs to manufacturers claims to have used an AI model identified as GPT-6 Astra, at its High and Extra High levels, to bypass the license validation of two desktop programs and break into the database of a cloud tool. The demonstration is not about the code, but about the question it leaves open: if AI facilitates this analysis, should its use be restricted for general security?
How long each attack took and what failed
The account is specific. First case, desktop software: about two hours to bypass license validation and develop a keygen. Second, cloud tool: another two hours to access the database without a token, only with username and password and a cloud connector design. Third, desktop again: approximately one hour to sustancia ilegal the license validation. Two of the products are, according to the author of the experiment, among the ten best-selling in their sector in the country.
The person telling this anticipates the obvious accusation: the responsibility lies with the programmer, not the machine. But he insists on the other question. And there the consensus breaks down.
Does AI bear part of the responsibility for these failures?
For many participants, the answer is no. No generative tool writes license validation incorrectly, nor leaves a user with a default password, nor forgets the access token. The model, it is said, only does in hours what a skilled auditor would do in days.
The counterargument is more uncomfortable. If an AI detects these holes so quickly, why doesn't the manufacturer detect them earlier? The suspicion points to old software, maintained with patches, and to companies that validate code with dozens of tools and still don't review it. In libraries from large companies, the drip of vulnerabilities is also high, counters another view, but their failures tend to be limited to very specific circumstances, not wide open.
«If civil engineering were done like computing, the first swallow that built a nest on an eave would have ended Western civilization», summarizes Kozak with an old phrase that is circulating again.
admin/admin123: the flaw that doesn't need AI
The list of cases includes the classic that requires no model at all: an administration panel of a multinational accessed with admin and the password admin123, with all permissions. The example serves to shift the focus: if the hole is in the configuration, AI is the least of it.
It remains unresolved what type of password protected with SHA-256 falls in two hours, and whether the described scenario holds up to comparison with a professional pentest. Another comment summarizes the unease with sarcasm and mentions, in passing, Sam Altman's announcements about an AI that monitors others.
With these ingredients, the final question is not whether AI should be limited, but whether the industry has any real incentive to fix what has been broken for years. No one would bet on either answer.
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (16 replies).
An IT vocational qualification at 36: 12 months of training, yes. Remote work from Asia, no. The sector only hires on-site juniors, and only if they're lucky.
An employee bought her fruit shop for €30,000. Five years on, with no staff and frozen rent, she earns €3,000 net per month. The keys to a business transfer…