Hackers: We wont let artificial intelligence get the better of us – ComputerWeekly.com
Artificial intelligence (AI) doesnt stand a chance of being able to replicate the human creativity needed to become an ethical hacker, but it will disrupt how hackers conduct penetration testing and work on bug bounty programmes, and is already increasing the value of hacking to organisations that are prepared to engage with the hacking community rather than dismiss it outright.
This is according to the hackers who contributed to the latest edition of Inside the mind of a hacker (ITMOAH), an annual report from crowdsourced penetration testing firm Bugcrowd, which sets out to offer an in-depth look at how hackers think and function, and why they do the things they do. This year unsurprisingly leans into AI in a big way.
When it came to the existential questions around whether or not AI could outperform the average hacker or render them irrelevant, 21% of respondents said AI was already outperforming them, and a third said it will be able to do so given another five years or so.
The vast majority, 78%, said AI would disrupt how they work on penetration testing or bug bounty programmes some time between now and 2028, with 40% saying it has already changed the way people hack, and 91% of hackers saying generative AI either has already, or will in future, increase the value of their work.
Outperforming a human doing repetitive, sometimes monotonous, work such as data analysis is one thing, but hacking as a vocation also encourages creativity of thought, and it is here that the community seems to feel humans will continue to have an edge, with 72% saying they did not think AI will ever be able to replicate these qualities.
Ive done a fair amount with AI, and as impressive as it is, I dont think it will be replacing humans for quite some time, if ever, said one respondent, a 20-year cyber security veteran who hacks on the Bugcrowd platform using the handle Nerdwell.
AI is very good at what it does pattern recognition and applying well-known solutions to well-known problems, he said. Humans are biologically designed to seek out novelty and curiosity. Our brains are literally wired to be creative and find novel solutions to novel problems.
Another Bugcrowd hacker, who goes by the handle OrwaGodfather, added: AI is great, but it will not replace me. There are some bugs and issues, just like any other technology.
It can have an effect on my place in hacking, though. For example, automation has huge potential to help hackers, said OrwaGodfather, who started hacking in 2020 and when away from his keyboard works as a professional chef.
It can make things easier and save time, he said. If I find a bug when performing a pen test and I dont want to spend 30 minutes writing a report, I can start by using AI to write descriptions for me. AI makes hacking faster.
Whatever their gut feelings may be, Bugcrowds hackers are scrambling aboard the AI train, with 85% saying they had played around with generative AI technology, and 64% already incorporating it into their security workflows in some way a further 30% said they planned to do this in the future.
Hackers who have adopted or who plan to adopt generative AI are most inclined to use Open AIs ChatGPT (a Bugcrowd customer) cited by 98% of respondents with Googles Bard and Microsofts Bing Chat AI at 40%.
Those that have taken the plunge are using generative AI technology in a wide variety of ways, with the most commonly used functions being text summarisation or generation, code generation, search enhancement, chatbots, image generation, data design, collection or summarisation, and machine learning.
Within security research workflows specifically, hackers said they found generative AI most useful to automate tasks, analyse data, and identify and validate vulnerabilities. Less widely used applications included conducting reconnaissance, categorising threats, detecting anomalies, prioritising risk and building training models.
Many hackers who are not native English speakers or not fluent in English are also using services such as ChatGPT to translate or write reports and bug submissions, and fuel more collaboration across national borders.
Over the past decade, Bugcrowds annual report has also served a secondary purpose, that of helping to humanise the hacking community and disrupt negative and unhelpful stereotypes of what a hacker actually is.
This is particularly important given that, in spite of years of pushback and attempts to educate, many people who should know better readily and intentionally conflate the term hacker with the term cyber criminal.
Weve taken on the responsibility of helping the market understand what a hacker actually is, Casey Ellis, Bugcrowd founder, chief technology officer and report co-author told Computer Weekly at the recent Infosecurity Europe cyber trade fair.
I think when we started, everyone assumed it was a bad thing, he said. Some 10 years on, were now at a point where people understand that hacking is actually a skill set. Like most skill sets, its dual-use. Its like lockpicking. If youve got that skill, you can become a locksmith, or a burglar. Theres nothing wrong with lockpicking its how youre actually using it. Hacking is the same.
The 2023 ITMOAH report shows how some fundamental shifts in hacker culture and demographics look set to shake up the cyber security landscape in the coming years.
For the first time, the report reveals, the majority of active hackers, between 55% and 60%, are now members of the Generation Z cohort currently in their teens and early 20s, while between 33% and 36% are Millennials aged from their late 20s to early 40s.
And despite hackings cultural roots in the 1980s, only 2% are members of Generation X, those born between the mid-1960s and approximately 1980, the youngest of whom are now about 45 years old.
So, are the stereotypes of teenage hackers actually proving accurate, and more pertinently, are the kids all right? Were seeing a pretty rapid acceleration of participation from people that are under 18, said Ellis. Its still a very small population, only 6%, but its up from 3% year-on-year, which is a big shift.
He said this trend will become increasingly relevant because todays teenagers think about technology in a fundamentally different way to those born even a few short years earlier.
Ive got a 15-year-old daughter and the way she interacts with technology is completely different to me, said Ellis. Her introduction to technology was all about the interface mine was all about the plumbing. We just think about the internet in a fundamentally different way.
Now, I know stuff that shell never know because I grew up with the nuts and bolts, but shell think about the interface in a way that I probably never will because Im so consumed with the nuts and bolts.
You talk about Millennials as digital natives, but Gen Z and younger are actually digital natives, he said. Theyre able to wander through that environment in an intuitive way that we cant really understand. I can try to empathise with that, and I can get most of the way there, but I recognise the fact Ill never fully understand because its not my experience.
This generation is also proving adept at challenging the mores and assumptions of their elders that have often been built into technology, and Ellis said this gives them an advantage in figuring out what is coming next, and where future vulnerabilities may lie.
The other part of this trend is that todays teens are more politically and socially motivated, and more diverse, in ways that older people are not. This factor is already changing the cyber landscape and will certainly continue to do so.
Take Lapsus$, the teenage-run cyber extortion collective that attacked the systems of ride-sharing service Uber in 2022 for no particular reason other than they didnt care for Ubers ethics.
One of the big things that Ive been saying since Lapssus$ is that as defenders, were not ready for a chaotic act, said Ellis. Weve been thinking about cyber criminals, nation states, threat actors as having a symmetric motivation.
A nation state wants to advance the nation, cyber criminals want money. Theyre predictable. And there is symmetry in what theyre doing. Folks that come in with more of an activism bent, you dont really know what they want. And in the case of Lapsus$, its like we just want to make a mess because those guys suck. How do you defend against that? We havent really been thinking in that way since Lulzsec, which was probably the last example of a group that did that.
Of course, the teens on Bugcrowds platform are not attacking organisations in the same sense as Lapssus$ did, but in its story there is a lesson for the hacking community, and the defenders, and clearly the potential to channel activity that might otherwise be expended on malicious acts into legitimate security work is immense.
The full report, which can be downloaded to read in full from Bugcrowd, contains a wealth of additional insight into hacker demographics the gender gap is increasing, likely due to the extra pressure the Covid-19 pandemic put on many women motivations to hack, what hackers think ordinary security teams need to do better, and more besides.
Read the rest here:
Hackers: We wont let artificial intelligence get the better of us - ComputerWeekly.com
- Three US Policy Developments Regarding Artificial Intelligence for Behind-the-Scenes Entertainment Workers - iatse - May 15th, 2025 [May 15th, 2025]
- How Penn is reimagining research in the age of artificial intelligence - Penn Today - May 15th, 2025 [May 15th, 2025]
- Cracking The Tight World of Artificial Intelligence - thehudsonindependent.com - May 15th, 2025 [May 15th, 2025]
- ISS BLOG - Stepping Through the Portal: What Artificial Intelligence Means for My Own Job and Perhaps Your Self-Storage Position, Too - Inside... - May 15th, 2025 [May 15th, 2025]
- This Is My Top Artificial Intelligence (AI) Chip Stock to Buy in May (Hint: It's Not Nvidia or AMD) - Yahoo Finance - May 15th, 2025 [May 15th, 2025]
- 1 Artificial Intelligence (AI) Stock to Buy Hand Over Fist Before It Soars Higher - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- Photo Editing and artificial intelligence (AI) are contorting the natural world and societal norms - Niagara-on-the-Lake Local - May 15th, 2025 [May 15th, 2025]
- 1 Top Artificial Intelligence (AI) Stock Down 32% to Buy Before It Skyrockets - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- This Incredibly Cheap Artificial Intelligence (AI) Stock Could Jump 8% as per Wall Street Analysts, But Don't Be Surprised to See It Soar Higher - The... - May 15th, 2025 [May 15th, 2025]
- 3 High-Flying Artificial Intelligence (AI) Stocks That Can Plunge Up to 92%, According to Select Wall Street Analysts - Yahoo Finance - May 15th, 2025 [May 15th, 2025]
- Prediction: This Artificial Intelligence (AI) Stock Could Be Worth More Than Nvidia by 2030 - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- Serve Robotics: An Interesting Play On Artificial Intelligence And Automation(NASDAQ:SERV) - Seeking Alpha - May 15th, 2025 [May 15th, 2025]
- Zainab Iftikhar: Helping humans use artificial intelligence to better support mental health - Brown University - May 15th, 2025 [May 15th, 2025]
- On the Very Real Dangers of the Artificial Intelligence Hype Machine - lithub.com - May 15th, 2025 [May 15th, 2025]
- Pope Leo XIV cites 'developments in the field of artificial intelligence' as reason for papal name - All Israel News - May 15th, 2025 [May 15th, 2025]
- Nasdaq Recovery: 3 Artificial Intelligence (AI) Stocks That Are Still Too Cheap to Ignore - Yahoo Finance - May 15th, 2025 [May 15th, 2025]
- Analysing the UKs artificial intelligence policy - Open Access Government - May 15th, 2025 [May 15th, 2025]
- 1 Top Artificial Intelligence (AI) Stock Down 32% to Buy Before It Skyrockets - The Globe and Mail - May 15th, 2025 [May 15th, 2025]
- Here's an Unexpected Artificial Intelligence Winner You Probably Weren't Thinking About - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- Artificial Intelligence (AI) In Video Surveillance Market Transformations: What the Industry Will Look Like... - WhaTech - May 15th, 2025 [May 15th, 2025]
- Correction or Not: This Artificial Intelligence (AI) Stock Is Worth Buying for the Long Haul - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- Artificial Intelligence as Co-Creator: Rethinking Art and Authorship - observer.com - May 15th, 2025 [May 15th, 2025]
- Use of Artificial Intelligence ramps up in bakery equipment - Bakingbusiness.com - May 15th, 2025 [May 15th, 2025]
- Got $3,000? 2 Artificial Intelligence (AI) Stocks to Buy and Hold for the Long Term - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- South Korea promotes use of artificial intelligence in drug development - Anadolu Ajans - May 15th, 2025 [May 15th, 2025]
- Transition 2025 Series: National Security in the Age of Artificial Intelligence - Council on Foreign Relations - May 15th, 2025 [May 15th, 2025]
- Prediction: This Artificial Intelligence (AI) Semiconductor Stock Will Soar After May 28 - The Motley Fool - May 15th, 2025 [May 15th, 2025]
- Will the Humanities Survive Artificial Intelligence? - The New Yorker - April 27th, 2025 [April 27th, 2025]
- Artificial Intelligence transforming the vacation-planning process - Fox Business - April 27th, 2025 [April 27th, 2025]
- These 2 Artificial Intelligence (AI) Chip Stocks Could Soar 50% to 112% in the Next Year, According to Wall Street - Yahoo Finance - April 27th, 2025 [April 27th, 2025]
- 2 Top Artificial Intelligence Stocks to Buy While They're on Sale - The Motley Fool - April 27th, 2025 [April 27th, 2025]
- AI Takes the Field: How Artificial Intelligence Is Powering the Next Era of Sports - PYMNTS.com - April 27th, 2025 [April 27th, 2025]
- 'Godfather of AI' reveals the startling odds that artificial intelligence will take over humanity - Daily Mail - April 27th, 2025 [April 27th, 2025]
- Prediction: Palantir's New Deal With NATO Could Revolutionize How Artificial Intelligence (AI) Is Used in the Public Sector. Here's Why. - Yahoo... - April 27th, 2025 [April 27th, 2025]
- ASCRS 2025: Bonnie An Henderson, MD, on leveraging artificial intelligence in cataract refractive surgery - Ophthalmology Times - April 27th, 2025 [April 27th, 2025]
- 2 Artificial Intelligence Stocks to Buy With $2,000 - The Motley Fool - April 27th, 2025 [April 27th, 2025]
- Alumni explore the future of artificial intelligence at Imagine RIT symposium - Rochester Institute of Technology - April 27th, 2025 [April 27th, 2025]
- Israels use of AI on the battlefield: How the IDF targets Hamas leaders with artificial intelligence - All Israel News - April 27th, 2025 [April 27th, 2025]
- Are you using artificial intelligence, such as ChatGPT, to write or edit your work? - dnronline.com - April 27th, 2025 [April 27th, 2025]
- These 2 Artificial Intelligence (AI) Chip Stocks Could Soar 50% to 112% in the Next Year, According to Wall Street - The Motley Fool - April 27th, 2025 [April 27th, 2025]
- 2 Top Artificial Intelligence (AI) Stocks to Buy Right Now - The Motley Fool - April 27th, 2025 [April 27th, 2025]
- AMD Jumped Today -- Is the Artificial Intelligence (AI) Stock a Buy? - The Motley Fool - April 27th, 2025 [April 27th, 2025]
- 6 EdTech AI trends: How artificial intelligence is reshaping education - Amazon Web Services (AWS) - April 27th, 2025 [April 27th, 2025]
- Why Colorados artificial intelligence law is a big deal for the whole country - The Colorado Sun - April 27th, 2025 [April 27th, 2025]
- In new sci-fi novels, artificial intelligence causes problems and the moon somehow turns into cheese - Toronto Star - April 27th, 2025 [April 27th, 2025]
- Rockets to introduce ClutchBot as generative artificial intelligence mascot - Rockets Wire - April 27th, 2025 [April 27th, 2025]
- ADVANCING ARTIFICIAL INTELLIGENCE EDUCATION FOR AMERICAN YOUTH - The White House (.gov) - April 25th, 2025 [April 25th, 2025]
- Some of California's troubled bar exam was drafted by nonlawyers with help from artificial intelligence - ABA Journal - April 25th, 2025 [April 25th, 2025]
- Trump Executive Order Calls for Artificial Intelligence to Be Taught in Schools - EdSurge - April 25th, 2025 [April 25th, 2025]
- Colorado lawmakers move to ban sexually exploitive images, video created with artificial intelligence - The Colorado Sun - April 25th, 2025 [April 25th, 2025]
- US Department of Labor applauds President Trumps executive order advancing artificial intelligence education for young Americans - U.S. Department of... - April 25th, 2025 [April 25th, 2025]
- 1 Magnificent Artificial Intelligence (AI) Stock to Keep an Eye on Before It Starts Soaring - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- Artificial Intelligence in Agriculture is Changing the Way Farmers Farm - Farms.com - April 25th, 2025 [April 25th, 2025]
- Artificial intelligence tool development: what clinicians need to know? - BMC Medicine - April 25th, 2025 [April 25th, 2025]
- President Donald Trump Just Dealt a Jarring Blow to Nvidia. Can the Artificial Intelligence (AI) Chip King Recover and Reclaim Its Previous Highs? -... - April 25th, 2025 [April 25th, 2025]
- Palantir Surged Again Today -- Is the Artificial Intelligence (AI) Stock a Buy? - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- How Artificial Intelligence Is Enhancing Cryptocurrency Security and Fraud Detection - Programming Insider - April 25th, 2025 [April 25th, 2025]
- The Impact of Artificial Intelligence on Education - The A&T Register - April 25th, 2025 [April 25th, 2025]
- 2 Artificial Intelligence (AI) Stocks That Could Soar in the Second Half of 2025 - Yahoo Finance - April 25th, 2025 [April 25th, 2025]
- Advancing Artificial Intelligence Education for American Youth (Trump EO Tracker) - Akin Gump Strauss Hauer & Feld LLP - April 25th, 2025 [April 25th, 2025]
- Why Pony AI Is Winning the Artificial Intelligence Race Today - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- Artificial Intelligence in Military Market is Forecasted to Reach US$ 15.62 Billion in 2029, Says Stratview Research - openPR.com - April 25th, 2025 [April 25th, 2025]
- Nurses Perception of Artificial Intelligence-Driven Monitoring Systems for Enhancing Compliance With Infection Prevention and Control Measures in... - April 25th, 2025 [April 25th, 2025]
- 4 Reasons CrowdStrike Is Still a Top Artificial Intelligence Stock Buy Right Now - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- Prediction: 2 Artificial Intelligence (AI) Stocks That Could Be Worth More Than Nvidia by 2030 - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- 3 Artificial Intelligence (AI) Stocks That Could Soar in the Second Half of 2025 - The Motley Fool - April 25th, 2025 [April 25th, 2025]
- AI-powered diagnostics: What physicians need to know about artificial intelligence diagnosing patients - Medical Economics - April 25th, 2025 [April 25th, 2025]
- Palantir Surged Again Today -- Is the Artificial Intelligence (AI) Stock a Buy? - MSN - April 25th, 2025 [April 25th, 2025]
- Commentary: From artificial intelligence to 'natural stupidity' - The Business Journals - April 25th, 2025 [April 25th, 2025]
- Nvidia Is Expensive. Here Are 3 High-Yield Artificial Intelligence Plays That Aren't. - Nasdaq - April 23rd, 2025 [April 23rd, 2025]
- Incorporation of explainable artificial intelligence in ensemble machine learning-driven pancreatic cancer diagnosis - Nature - April 23rd, 2025 [April 23rd, 2025]
- Artificial intelligence in the Kyrgyz Republic: a silent transformation in the making? - World Bank Blogs - April 23rd, 2025 [April 23rd, 2025]
- Does Netflix Have the Right Artificial Intelligence (AI) Ideas? - The Motley Fool - April 23rd, 2025 [April 23rd, 2025]
- Impact of artificial intelligence on elections topic of Edmonds Civic Roundtable May 5 meeting - My Edmonds News - April 23rd, 2025 [April 23rd, 2025]
- 1 Market-Beating Artificial Intelligence (AI) ETF That Could Turn $250,000 Into $1 Million - Nasdaq - April 23rd, 2025 [April 23rd, 2025]
- The Oasis Group and AdvisorEngine Release Research Report on Artificial Intelligence Note Takers - Yahoo Finance - April 23rd, 2025 [April 23rd, 2025]
- This May Be the Best Artificial Intelligence (AI) Semiconductor Stock to Buy Right Now - The Motley Fool - April 23rd, 2025 [April 23rd, 2025]
- 2 Artificial Intelligence (AI) Stocks to Buy on the Dip Right Now - The Motley Fool - April 23rd, 2025 [April 23rd, 2025]
- 2 Artificial Intelligence (AI) Stocks That Could Soar in the Second Half of 2025 - The Motley Fool - April 23rd, 2025 [April 23rd, 2025]
- 3 Artificial Intelligence (AI) Stocks That Can Skyrocket Up to 232%, According to Select Wall Street Analysts - The Motley Fool - April 23rd, 2025 [April 23rd, 2025]