中文
AI Engineer World's Fair

AI speeds up finding bugs and writing them at once; his answer isn't patching, it's replacing the foundation.

The AI bugpocalypse is here. Now what? - Jack Cable, Corridor · Jack Cable

20 min
AI CodingAgent

20 min total·Actually worth watching closely: ~3 min·2 must-watch clips

Orange = the 3 minutes worth watchingFor the rest, the guide is enough
Segment guide · 8 segments
  1. 0:01 1:56Listen

    Opening: the bugpocalypse is here

    He states his read up front — frontier models are shifting both ends of the equation at once, and the rhythm the security industry knows is breaking. He plants the thesis, then unpacks it piece by piece.

    It isn't one side that changed; both ends of the attack-defense equation are being rewritten at the same time.

    Mostly him talking through his view, with just a title slide on screen — you can look away.▶ Jump to 0:01
    Speaker · Jack Cable
  2. 1:56 4:30Skim

    Models can already run the whole attack chain

    He walks through model capability at finding vulnerabilities, writing exploits, and pushing the attack chain forward, and notes that attack surfaces are swelling in parallel now that AI is the default code writer.

    The open source libraries underneath modern software are the first casualty of this wave.

    The capability comparison on screen is the core of this stretch; one glance at the rise in the curves is enough, the rest you can just listen to.▶ Jump to 1:56
    Speaker · Jack Cable
  3. 4:30 7:04Listen

    Good news: there are no new vulnerability classes

    He revisits where the Secure by Design work came from and offers a counterintuitive optimism: almost everything models dig up belongs to a class documented thirty years ago — only the location is new.

    If the classes are old, the ways to prevent them at scale have existed all along.

    All argument and recollection; nothing on screen you need to watch.▶ Jump to 4:30
    Speaker · Jack Cable
  4. 7:04 8:32Listen

    Stop playing whack-a-mole

    He runs the numbers: pouring millions of dollars into having models find and patch vulnerabilities one at a time is a race you never finish; the money should go toward wiping out whole classes at once.

    Invest in the fundamental measures that still work no matter how capable future models get.

    Pure cost-and-strategy reasoning — listening is enough to follow it.▶ Jump to 7:04
    Speaker · Jack Cable
  5. 8:32 11:40Skim

    How much memory safety actually saves

    The quantified basis: roughly 60 to 70% of vulnerabilities in products written in unsafe languages simply wouldn't exist in Rust or Go, and Android's real-world numbers bear it out.

    Switching languages buys a guarantee, not a probabilistic improvement.

    Everything hinges on those few percentages — read the before-and-after on the chart; the narration is restating what's already there.▶ Jump to 8:32
    Speaker · Jack Cable
  6. 11:40 14:07Listen

    Rewrite the critical open source libraries

    He turns the conclusion into action: concentrate resources on migrating the most widely depended-on open source libraries to memory safe languages — one investment, lasting immunity.

    Once that's done, stronger models can neither introduce nor find this class of vulnerability.

    A position and a prioritization; no extra information on screen.▶ Jump to 11:40
    Speaker · Jack Cable
  7. 14:07 16:50Listen

    Setting the guardrails on coding agents

    He traces autonomy climbing the ladder — autocomplete, to code produced inside the editor, to parallel background agents running for hours, to agents reviewing code — and points out that even the best models still introduce vulnerabilities 20 to 40% of the time, with the errors shifting from one-liner bugs to authorization flaws that require understanding the business logic.

    The question is no longer whether agents are allowed, but whether the guardrails are good enough for security to sign off.

    A layered spoken argument; the few percentages stick after one listen, so there's no need to watch the screen.▶ Jump to 14:07
    Speaker · Jack Cable
  8. 16:50 19:41Listen

    Three recommendations for Congress

    The close turns to policy: prevent vulnerabilities in new code as development accelerates, harden the open source foundation with systemic rewrites rather than one-off discoveries and patches, and — as he explains through the letter he joined — lift export controls on these dual-use models.

    Adversaries already have powerful models and are already using them to exploit systems; the real variable is how fast defenders get the same capability.

    Straight policy argument at an even pace — fine to listen to while doing something else.▶ Jump to 16:50
    Speaker · Jack Cable