Glasswing: Insuring Critical Software for the AI Era

What the Glasswing project wants to do isn't sexy but is important: in an era of AI mass-generating code, building systematic security assurance for critical infrastructure software.

The Project's Problem Awareness

The starting point is a scissors gap: on one side, AI makes code output explode, so average review depth necessarily drops; on the other, the world's critical systems happen to run on a small handful of open source software that has long been short on money and people—Heartbleed in OpenSSL, the xz backdoor—cautionary tales still warm to the touch. Glasswing's approach is to aim resources at this intersection: identify the most critical and most fragile foundational software, and invest money and engineering effort into hardening, auditing, and supply-chain protection—where AI is both a source of risk and an auditing tool.

The Timing Is Just Right

Initiatives of this kind have been proposed many times over the past decade; this time the context is different: AI has both created new attack surfaces (vulnerabilities in generated code, poisoned dependencies, weaponized automated vulnerability-hunting) and, for the first time, made large-scale code auditing economically feasible (the cost of having a model scan through ten million lines of code is acceptable). Both attack and defense have gotten new weapons, and whoever systematically applies them to infrastructure first gains the initiative. Whether this project succeeds is another matter; the direction it points is right: the security of critical software shouldn't have to be backstopped solely by a few volunteers' 2 a.m. enthusiasm.

via: Hacker News