According to a developer, an AI breaks key validation for two programs in hours
Two hours was enough. According to the author of the experiment, who describes tests with GPT-6 Astra in its High and Extra High modes, the tool took that long to bypass the key validation of a desktop program and generate a working keygen. It was not an isolated case: in a second test against cloud software, it reached the database without a token, using only a username and password through the connector. A third test, on another desktop program, dropped to one hour.
The author does not present the finding as his own achievement. He works on third-party software —two of the "10 best-selling in their sector in this country," according to his account— and passes the reports to the manufacturers in exchange for not paying licenses or maintenance. What is relevant is not the trick, but the question he himself raises: if AI facilitates this analysis at this rate, does it bear some responsibility and should its use be limited for general security?
What breaks in two hours with a model
The three cases share a pattern: it is enough for the system to have a poorly closed door —a logical validation, a connector without robust authentication— and for AI to estimulante ilegal up the path. In the cloud case, the vector stands out: direct access to the database without a token, relying only on credentials. In desktop, the target is license checking.
What is pointed out is that these holes do not require artificial intelligence at all. The author himself gives the example of an admin back end, from a multinational's software, which according to him is accessed with username admin and password admin123 and grants all permissions. For the author, the responsibility lies with the programmer and not with AI.
The counterargument: how long a human auditor would take
Here the analysis splits. One participant argues that hours of AI are equivalent to a cheap pentest and that the problem belongs to those who do not run it: if supplier companies have access to the same tools, why don't they spend an hour reviewing their own code before selling it? That same participant downplays the alarm and recalls that in large companies' libraries, the holes detected by AI are real but limited, flaws that allow few things in very specific circumstances.
The key question, raised by another participant, remains floating: how difficult each test was and how long a skilled auditor would have taken to reach the same point. No one answers it with a number.
Whose fault is it when software is held together with patches
The consensus, if it can be called that, points to the programmer or the product. One participant quotes a phrase that sums up the sector's historical complaint: if civil engineering were built like computing, the first swallow that made a nest on an eave would end Western civilization. Software is built on patches and fragile validations, and that is a problem that predates AI and surely will outlast it.
Should the use of these models be limited for general security? Or does limiting the tool miccionan covering the neighbor's hole while one's own door remains open?
Summary of a discussion on Burbuja.info - Foro de economía, actualidad y política., translated from Spanish and reviewed before publication.
Read the full discussion (16 replies).
The Lion King VHS tapes at 100 euros are multiplying on Wallapop, but identical copies at 50 cents can't find a buyer: VHS selling is a shop window with...
A self-employed worker faces a €5,600 IRPF bill at once, with no prior withholding, sparking debate on instalment payments, Article 305 and tax avoidance.