Cybersecurity and the Gap Between Skill and Ability

📡 Schneier on Security · 2026-07-08

Cybersecurity and the Gap Between Skill and Ability

Cybersecurity and the Gap Between Skill and Ability - Schneier on Security Schneier on Security Menu Blog Newsletter Books Essays News Talks Academic About Me Search Powered by DuckDuckGo Blog Essays Whole site Subscribe Home Blog Cybersecurity and the Gap Between Skill and Ability Last week, national security agencies from the Five Eyes—that’s the rich, English-language-speaking countries club—jointly released a statement warning of the increasing cyber risks of AI models: in particular, their ability to autonomously hack into systems and networks. The statement was more measured than some of the breathless headlines about it, and the advice they gave is pretty much the standard advice everyone gives—albeit with newfound urgency. Internet risks are nothing new, and cyberattacks—both large and small—have been a significant issue since long before the current crop of generative AI models. What’s been changing over the decades, and what AI is changing even faster, is the gap between skill and ability. For most of human history, the two terms were synonymous—but computers have decoupled them. As the gap between the two expands, humans empowered with these AI tools can do more: more writing, more research, more analysis and also more damage than ever before. These models can, with little detailed direction, autonomously hack into networks, steal data, deploy ransomware and destroy systems. And to the extent there is a solution, it’s going to involve harnessing AI for the defense. In 1998, seven people from the hacker group L0pht testified before Congress . They told a mostly clueless Senate committee that they could take down the internet in 30 minutes. That was partly real and partly bravado, but it illustrates an important point: hacking into systems, stealing data and causing damage all required skill. Contrast the L0pht hackers with hackers derided as “script kiddies.” They didn’t understand computers, or security. Instead, they used hacker tools written by others. Their actions required minimal skill and even less knowledge. But once those hacking tools became widespread, the number of potential attackers increased. That number has continued to increase, as quality and availability of prewritten attack tools has grown. And it is growing dramatically with AI. Today’s AI systems—not just the frontier models, but most of them—are capable of carrying out cyberattacks automatically. They all do better in the hands of skilled attackers, but increasingly they are able to act autonomously with only minimal prompting. The thing about people with ability but no skill is that they are often outsiders, not part of any professional community, and not bound by any rules or norms. This phenomenon is much more general than in cybersecurity. Any doctor can tell you how to untraceably poison someone, and many virus researchers know how to create a bioweapon. Any bridge engineer can tell you how to place explosives to blow a bridge up. The reason that murderous doctors and terrorist engineers are so rare is that the lengthy process of acquiring those skills also instills a moral and ethical code. If every random person has access to good poisoning advice, that puts us all in danger. Modern AI systems are, in effect, a universal adviser to help people do harmful things. And while the current AI megacorporations are trying to build guardrails to prevent people from asking questions whose answers will enable the questioner to do harm, that’s not going to work in the long term. Smaller, cheaper, open-source models, including models that can run on people’s computers, and especially groups of models that run in concert with each other, are just as good as the frontier models from companies like OpenAI and Anthropic. And they continue to get better. These models will be passed around from person to person, like script kiddie hacker tools, and they won’t have any such guardrails. Instructing AI models to spy on people and report any malicious prompts to the authorities fails for similar reasons. The megacorporations can do that, but the locally run open source models won’t. This could buy us a few months at best. A third possibility is to somehow make the models themselves unable to hack into computers, create bioweapons or do anything else that might harm people or society. That won’t work, for the same reason we can’t teach doctors how to treat poisonings without also teaching them how to poison. It’s the same knowledge. It’s the same with construction and demolition. And it’s the same with cybersecurity. We want these AI models to be able to review computer code, find vulnerabilities and automatically fix them. The benefit to our collective security will be enormous. Unfortunately, the same knowledge can be used for attacks. Where this leaves us is in a world of increased volatility. Super-powered humans with AI assistants will be able to do both wonderful and horrible things. This brings us back to the Five Eyes statement. Everything they recommend is something security professionals have been recommending for years, if not decades. They are things talked about at that congressional hearing back in 1998, titled “Weak computer security in government: Is the public at risk?” Even the Five Eyes admitted that their security advice is not new, only more urgent. What’s new is how fast things are changing: “The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.” The Five Eyes point to AI technology—not necessarily chatbots, but AI more generally—being used to strengthen every aspect of defense, to “detect vulnerabilities earlier, improve software quality, monitor unusual behavior, and respond faster to incidents—reducing both the cost and impact of incidents.” Excellent advice from the Five Eyes security agencies. We need to do this with every risk that AI heightens, not just cybersecurity. This essay was originally published in The Guardian . Tags: AI , computer security , cyberattack , cybersecurity , hacking , LLM Posted on July 8, 2026 at 7:03 AM • 9 Comments Comments shorturl.at/psuj0 • July 8, 2026 8:15 AM Attempted murder COVERED UP BY C0PS and the ACTUAL VICTIM TURNED INTO A F3L0N. This is not $P@M s h o r t u r l . at / psuj0 s h o r t u r l . at / psuj0 • July 8, 2026 8:15 AM Attempted murder COVERED UP BY C0PS and the ACTUAL VICTIM TURNED INTO A F3L0N. This is not $P@M s h o r t u r l . at / psuj0 KC • July 8, 2026 11:23 AM From the linked statement: Leaders who act now will reduce exposure, strengthen resilience, and build confidence with customers, partners, and investors. Those who delay will face growing and avoidable risk. @Rontea, this reminds me of your summary . wiredog • July 8, 2026 12:21 PM Man, that WaPo article on L0pht was a real flashback. You could go through it and replace “internet” with “AI” and have the same security story. Clive Robinson • July 8, 2026 1:19 PM @ Bruce, ALL, With regards, “current AI megacorporations are trying to build guardrails to prevent people from asking questions whose answers will enable the questioner to do harm, that’s not going to work in the long term.” That is already and always will be an exercise in futility with Current AI LLM systems. As I’ve explained before and again earlier today, the issue is the Observer problem in a Shannon Channel, https://www.schneier.com/blog/archives/2026/07/google-is-suing-chinese-scammers-who-are-using-gemini.html/#comment-455821 And that’s long before you get into the use of, “Smaller, cheaper, open-source models, including models that can run on people’s computers, “ The expense in these “Open Weight” models is not the LLM DNN the user choses to run… but the ML generator to produce the weights of high enough quality. In theory such harmful information could be left out of the training data set, but it will not be long before someone just re-builds any missing data into an 3xisting model. In effect “the genie is out the bottle” and adding new information is not that hard or eepensive. Rock'em-Sock'em Robots • July 8, 2026 2:42 PM “Adversaries are already using AI to move faster and more effectively. Defenders must do the same. Organizations that integrate AI tools into their security operations can detect vulnerabilities earlier, improve software quality, monitor unusual behavior, and respond faster to incidents – reducing both the cost and impact of incidents.” While it’s a nice idea that an AI defender can be trained to secure systems from AI attackers, the reality is it’s a cat-and-mouse game in which neither side can really maintain the upper hand. For every AI defender, someone will come up with a better AI attacker. Just adding agentic AI introduces yet another attack surface into an already complex the security apparatus. Clive Robinson • July 8, 2026 4:16 PM @ Bruce, ALL, “The reason that murderous doctors and terrorist engineers are so rare is that the lengthy process of acquiring those skills also instills a moral and ethical code.” It’s a bit more complicated than that and has quite a bit to do with basic personality types. Doctors and Engineers are mostly actually “creative types” that want to bring what is see by society as “benefits of worth” or more simply “good things to society”. They actually believe in the main to “moving humanity forward”. The fact that they spend much if not more of a decade from their teens through twenties becoming educated and attaining the knowledge to achieve this goal is testament to the “creative good” mentality. Those who wish to harm society generally want quick access to instruments of harm and do not have the mental outlook that will get them a “Professional Education” thus even practical knowledge. That is they are Walter Mitty types thinking they are “Men of action on a mission”… Which also generally means they are failures in ordinary life which is what can act as a driver for their antisocial attitudes and behaviours. Further the few with professional educations that become intent on harming society, generally value their own lives quite highly. Thus tend to create methods / devices for agents. Which is in effect the Hacker script writer and script kiddy scenario playing out. We saw this with 9/11 when it was reported that one of the attackers had told a flight instructor they did not need to know how to take off or land just fly… With regards to, “If every random person has access to good poisoning advice, that puts us all in danger.” Most “random people” do have access to “good poisoning advice” it’s fairly freely available in libraries and in the likes of PubMed research. The thing is that most don’t have the ability to understand the information to go “from page to poisoning”. A fun test of this is a two part question to ask people (I used to use it in job interviews), 1, Do you know how to measure Ph? 2, Do you know how to make the reagents? Many would not be able to say yes to the first and of those that do very few of those would be able to answer the second. Asking many AI’s produces information that few can understand such as, < blockquote> “To make pH measuring reagents, you can prepare your own buffer solutions using chemicals like mono potassium phosphate and KOH. For a pH 7 buffer, mix 10g of mono potassium phosphate per liter of distilled water and adjust the pH with KOH until it reaches 7.00.” And if you do an internet search you get the likes of, ‘https://spectrascientific.com/the-ultimate-guide-to-ph-reagents/ Which says a lot without saying anything useful so in no way can be said it’s an, “ultimate guide to ph reagents” For those that want an experiment for children to do to teach them the practical first steps, Buy a purple cabbage grate/shred it up and boil it till the water becomes strongly purple or dark blue. Pour the purple water into a clean glass measuring jug and let it cool. To show it working as a Ph reagent you need an acid and an alkali. The kitchen cupboard/pantry can usually supply vinegar or lemon juice which are acidic and baking soda which is an alkali, in small quantities these are usually “kiddy safe”. If you want to calibrate your reagent you add small amounts of acid or alkali untill you reach the “mid colour”. This information is freely available on the Internet, but only if you know how to properly search for it then understand it. By the way it’s worth telling young curious children about the early history of both Chemistry and Metrology. And how they all started in the “kitchen” long before people could read/write and before “negative numbers” or “zero” were understood as concepts. Anonymous • July 8, 2026 4:25 PM open-source models, including models that can run on people’s computers You mean to imply that there exist, by definition, open-source models that cannot run on people’s computers? Rontea • July 8, 2026 4:31 PM @KC 10x, it was Godard’s vision in his 1965 Alphaville. Subscribe to comments on this entry Leave a comment Cancel reply Blog moderation policy Login Name Email URL: Remember personal info? Fill in the blank: the name of this blog is Schneier on ___________ (required): Comments: Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/ Notify me of follow-up comments by email. Notify me of new posts by email. Δ ← Google Is Suing Chinese Scammers Who Are Using Gemini Sidebar photo of Bruce Schneier by Joe MacInnis. Powered by WordPress Hosted by Pressable About Bruce Schneier I am a public-interest technologist , working at the intersection of security, technology, and people. I've been writing about security issues on my blog since 2004, and in my monthly newsletter since 1998. I'm a fellow and lecturer at Harvard's Kennedy School , a board member of EFF , and the Chief of Security Architecture at Inrupt, Inc. This personal website expresses the opinions of none of those organizations. Contact Info Related Entries Google Is Suing Chinese Scammers Who Are Using Gemini Cybersecurity Mission Creep in the US The Realities of AI Video Surveillance AI and Liability Embedding Forbidden Text in Spyware to Discourage AI Analysis Featured Essays Four Ways AI Is Being Used to Strengthen Democracies Worldwide The CrowdStrike Outage and Market-Driven Brittleness How Online Privacy Is Like Fishing How AI Will Change Democracy Seeing Like a Data Structure LLMs’ Data-Control Path Insecurity AI and Trust The Value of Encryption The Eternal Value of Privacy Terrorists Don't Do Movie Plots More Essays Blog Archives Archive by Month 100 Latest Comments Blog Tags 3d printers 9/11 A Hacker's Mind Aaron Swartz academic academic papers accountability ACLU activism Adobe advanced persistent threats advertising adware AES Afghanistan AI air marshals air travel airgaps al Qaeda alarms algorithms alibis Amazon Android anonymity Anonymous antivirus Apache Apple More Tags Latest Book More Books Blog Newsletter Books Essays News Talks Academic About Me


📌 来源: Schneier on Security | 📅 2026-07-08

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)