Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Why Hacking Is No Longer Just About Code

    September 24, 2026

    Groundcover picks up Kubernetes optimization startup Wand in its first acquisition

    September 24, 2026

    How NASA and Nikon Captured Those Stunning Artemis II Moon Photos

    September 24, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Why Hacking Is No Longer Just About Code
    Cybersecurity

    Why Hacking Is No Longer Just About Code

    InfoForTechBy InfoForTechSeptember 24, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Why Hacking Is No Longer Just About Code
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email



    Hello Cyber Builders đź––

    This week, I have a simple suggestion: watch Bruce Schneier’s DEF CON talk.

    Bruce Schneier’s DEF CON 34 talk questions what we think we know about AI security. Here’s what stood out to me.

    If you are short on time, here are his four main arguments.

    First, AI is a powerful hacking tool. But hacking itself is nothing new. People have always found ways to bend or break the rules, long before computers existed. It is not just about software. Any system with rules can be hacked—think tax codes, financial regulations, or even democracy.

    The tax code works like an algorithm. Loopholes are vulnerabilities, and tax avoidance strategies are just exploits. Tax attorneys and accountants are the hackers. Now that cars, appliances, and phones all run on software, our social, financial, and political systems are connected to computers. The problem is much bigger now.

    To generalize, Bruce calls this reward hacking, or the Genie Problem. Because human goals are rarely clear, AI finds shortcuts that follow the rules but miss the point.

    He breaks AI genies down into two distinct archetypes:

    • The Dionysus Genie (Specification Error): This genie takes your prompt at face value and gets it wrong. Ask an AI to handle spam calls, and it might just change your phone number. Ask for a refund, and it might send a legal threat.

    • The Golem Genie (Guardrail Error): This genie does what you ask but ignores the rules to get there. Ask it to book a seat on a full flight, and it might hack the airline database. Ask it to buy concert tickets, and it might flood the ticketing site with thousands of requests. In real life, an AI model being tested for vulnerabilities once broke out of its sandbox and hacked into Hugging Face. This was the OpenAI-Hugging Face incident.

    Second, Schneier lays out what I call the “4 Ss” of AI security. These are four ways AI changes hacking.

    • Speed: AI can do in seconds what might take a human months or years.

    • Scale: Once AI finds an exploit, it can use it at massive scale. For example, AI bots can flood social media feeds and drown out real political conversations.

    • Scope: We are handing more real-world decisions to AI. That means when something goes wrong, the impact is much bigger.

    • Sophistication: AI can juggle more variables than any human. It can spot complex, layered exploits across legal, financial, or tax systems.

    Third, Schneier points out who really benefits from AI. AI does not work in isolation. It makes the powerful even more powerful. As Bruce puts it:

    “AI is fundamentally a power-enhancing technology. It enhances the power of whoever is using it… The more power you already have, the more power a hack gives you.”

    If one person finds a tax loophole, they might save a few thousand dollars. If a big investment bank uses AI to find a loophole across US, Irish, and offshore tax laws, they can make billions. Bruce says our real problem is a failure of governance and late-stage capitalism:

    “The failure of late-stage capitalism and democracy in the information age are both the result of the rich and the powerful becoming too good at hacking our social, economic, and political systems… AI is just exacerbating the existing problems that we have.”

    Software developers can use VulnOps platforms to patch vulnerabilities as soon as they find them. But democratic governance moves slowly.

    AI will find hundreds of loopholes in tax codes and financial rules. Our political systems are too slow to patch these legal holes before the rich and powerful take advantage. We need governance that can update rules as fast as we update software.

    Finally, Schneier says Integrity will be the big security challenge of this decade, replacing confidentiality. In his essay “The Age of Integrity,” Bruce explains this shift. Early computing cared most about availability. The Internet age focused on confidentiality. Now, with AI and Web 3.0, it is all about data integrity.

    The main point: Integrity is more than stopping data tampering. It means ensuring data remains accurate and trustworthy from start to finish—from collection and training to input, processing, and real-world output. Most AI vulnerabilities, like prompt injection or tricking self-driving cars, are really integrity failures. The system cannot tell good instructions from bad ones. As Bruce puts it:

    “If you’re building an AI system, integrity is your biggest security problem.”

    After 10 years in OT and SCADA security, I agree with this view. In real operations, confidentiality is rarely the main risk. Most people do not have deep secrets, and you can often guess their sensitive information (e.g., wealth). Many people are even open about it.

    But integrity, or knowing that data and control signals have not been tampered with, is about physical safety. When machines act in the real world, an integrity failure is not just a wrong cell in a spreadsheet. It can mean a car brakes too late, a patient gets the wrong medicine, or a smart heater malfunctions and starts a fire.

    AI makes this threat much bigger. It can scan for minor vulnerabilities and launch coordinated integrity attacks against millions of devices at once. Bruce calls for “integrous system design” and asks if we can build trustworthy, verifiable networks in a world full of integrity failures.

    All of this means we need to look past code and focus on the security and integrity of the bigger systems around us. Watch Bruce’s full video, read his essay, and see you next time!

    Laurent đź’š

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    September 24, 2026

    Weekly Update 522: Live From Oslo with Scott Helme

    September 23, 2026

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    September 23, 2026

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    September 23, 2026

    One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

    September 22, 2026

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

    September 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026383 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views

    Creating an AI Girlfriend with OurDream

    February 12, 202623 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026383 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202641 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202635 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.