We have a year to fix security everywhere(jyn.dev)
297 points by saikatsg 2 days ago | 336 comments
tl;dr: A speculative near-future scenario (referencing fictional models like GLM 5.3-flash and GPT-6 Astra) argues that cheap, open-weight LLMs with safety guardrails removed will soon enable anyone to run automated cyberattacks against real infrastructure for the cost of a consumer workstation. The author urges urgent action: governments should mandate and fund pentesting and patch deployment, while companies should hire security engineers, use frontier models defensively, invest in supply-chain security and memory-safe languages, and drastically speed up patch triage and rollout before attacker capabilities outpace defenses.
HN Discussion:
  • ~Personal computers and end-user devices are overlooked in the security discussion
  • LLM threat is overblown since dangerous information is already freely available
  • Author overestimates current LLM performance on consumer hardware
  • We have even less than a year; the threat is already here
  • Security has been chronically underinvested for decades; maybe AI panic will finally force change