How Will AI Shape AppSec?
Leveraging LLMs productively requires skill and intent
Large language models (LLMs) are rather ubiquitously presented as a technology so transformative that we are supposedly standing on the verge of the next industrial revolution. But the truth, with respect to application security at least, is a bit more pedestrian. The LLM value proposition for AppSec is, at best, unclear. We have seen some genuinely innovative and productive uses, but these case studies are usually presented in ways that discount the significant engineering effort necessary to make them work. Moreover, for each novel demo there are many more “solutions” that are nothing more than a chatbot duct taped to a preexisting tool. The strategy behind these sales pitches is to use blitzscaling to entrench LLMs as dependencies in other businesses before the venture capital dries up; before these services are no longer heavily subsidized. The message being all you need is a little “AI” pixie dust to help you find more exploitable vulnerabilities faster with little to no additional effort.
Continue reading...