The number of remotely-exploitable defects is going to drop by 1 or 2 orders of magnitude. We now have amazing machines that will find pretty much all the a priori knowable ones. They outperform even the most gifted h@x0rs. So that just leaves a small pool of leetrs to scour a very barren landscape. And that pool is also shrinking as we rely more and more on the ai tools.

Perhaps we are going to go up a level with hacking done by probing the systems and the system of systems.

It all boils down to money/resources, like always.

Pre-AI, the advantage went to the entities with the largest budget to hire the best and brightest security engineers.

Post-AI, it'll go to the entities with the largest inference budget.

Right now we're in a transitionary period where it's kind of a tossup which approach is more practical, but at the end of the day - it's still all about how much money you can throw at the problem. I'm just hoping the threshold climbs high enough it's no longer practical for governments to be able to compromise individual actors' devices because doing so would waste a 0-day that's far, far more valuable than prosecuting one arbitrary person is worth.

It's not as simple as money, people are motivated by other things as well. There's no amount of money you could pay me to intentionally hurt children, but I'd do a lot of things to protect them. And a lot of things people say they're doing in the name of protecting them but has ulterior motives, so it's complicated.

I agree, but broadly speaking it doesn’t change much that what I described breaks down at the level of an individual. There are very few instances where the global talent pool is small enough that individual beliefs become a constraint.

There’s (almost) always someone else out there that is willing to do it, and there’s (almost) always a dollar amount that you can’t turn down.