Elektrine lite

← Feed

@mttaggart@infosec.exchange

Post #4382627

2026-08-04 20:40 UTC

There's a really uncomfortable duty of care question facing defenders with ethical objections to generative AI—myself included. If the bad guys are attacking you with heavily obfuscated malware that takes significant time and effort to manually analyze, and the generative tool that is demonstrably excellent at performing analysis and indicator extraction is right there, are you obligated to use it? Are you neglecting your duty of care to those under your defense if you don't? I'm not sure, but I don't think it's an easy answer.

Replies (9)

  • @mttaggart@infosec.exchange The age old two-masters problem.

    Open ##4382626

  • @chroma@raccoonisland.social 2026-08-04 20:42

    @mttaggart@infosec.exchange If, in the software field, you must use AI to stay competent and keep your services safe then, at least for me, it’s time to leave the field. Is a really easy answer.

    Open ##4382817

  • @mttaggart@infosec.exchange 2026-08-04 20:50

    It's a collision of two scales of moral choices, and reasonable people can disagree about which takes precedence. I admit to leaning toward the immediate duty of care, but also recognize that without additional collective action, that evaluation never gets us anywhere better.

    Open ##4382933

  • @cR0w@infosec.exchange 2026-08-04 21:08

    @mttaggart@infosec.exchange I've been thinking on this for a while too and it's tough. My take for now is that if I can do the work properly without GenAI at the expense of some time, then that time cost offsets the general "cost" of using GenAI. If for whatever reason the task requires GenAI, then it absolutely falls into the duty of care category. I do think that there is also a place for teams to have a reasonable range of approaches among the team members. For example, I have teammates that use AI tools but they all know I don't so we approach the same tasks differently. So far I have never "lost" when we would see who could do a task quicker or better, me without AI and them with it. Because of that I have no incentive to change my position, but I also know that may not always be the case.

    Open ##4383225

  • @cjust@infosec.exchange 2026-08-04 21:35

    @mttaggart@infosec.exchange my 2 bits: It's kind of a trolley problem where the actual harm that is inflicted by pulling the lever is actually unknown. While I wouldn't argue that that the use of AI tools equates to tying people to railroad tracks (at least yet) - there is a non-zero value of harm that would be inflicted upon [ a person | culture | society | the environment ] by making a conscious decision to "pull the lever" (use the AI/LLM tool). There are literally entire courses in philosophy that grapple with the trolley problem (to no real resolution) and I don't expect that the answer to your dilemma is going to be much easier here.

    Open ##4383762

  • @mttaggart@infosec.exchange This is a very interesting perspective. My inital take on breaking the argument down.: Assume using AI does harm. Should be easy enough there. Water and energy usage, lowered earning power for people in many sectors, etc. Assume AI posiitively impacts some security function. Again, pretty easy. Even if it can be exploitrd with hidden instructions, etc. and isn't always reliable it is probably faster and more effective at immediate triage with a manual follow up at least. I could believe a benefit exists there. So then the moral argument is whether acceptable to contribute to an indirect mediated harm to many in order to provide a benefit that is more immediate to a smaller group of people.

    Open ##4383783

  • @tehfishman@ioc.exchange 2026-08-04 21:37

    @mttaggart@infosec.exchange it's real thorny. Additional concerns: long-term usage causes you to slowly de-skill, which means you progressively become less capable as a defender. And the LLM tools will almost certainly become more expensive over time because the industry is in the sweetheart deal phase, leading to you having to charge more for defense. Both of which are negative for the overall goals of providing defense.

    Open ##4383788

  • @mttaggart@infosec.exchange Disable Javascript if possible.

    Open ##4385511

  • @jdp23@neuromatch.social 2026-08-04 21:11

    @mttaggart@infosec.exchange agreed, it really isn't an easy answer.

    Open ##4395608