Cryptographer Matthew Green: AI may make lawful hacking impossible
TL;DR
- Cryptography professor Matthew Green argues AI-driven patching could make software so bug-scarce that lawful government hacking stops working.
- Xbow's Hamid Kashfi disputes the scarcity claim, estimating that for every AI-found reported bug, roughly 20 go unreported.
- Luta Security's Katie Moussouris says intelligence agencies have 'at least until after the next presidential election' before feeling pressure.
"I'm concerned that AI is going to make software much too secure." That is Matthew Green, a cryptography professor, in an X thread and longer blog post that TechCrunch reports went viral within the cybersecurity community earlier in August. Green's thought experiment: what if AI makes bugs so scarce that law enforcement cannot lawfully hack criminals anymore, and the political pressure for backdoors comes back louder than it did during the 2014 'going dark' fight after FBI director James Comey took it public.
The piece is one of hundreds of AI cybersecurity items we've tracked this quarter, but the framing inverts the usual one: better security itself becomes the political problem.
Not everyone in the story agrees on the timing. Luna Tong, a researcher who has worked at prominent bug-finding firms, tells TechCrunch there is a "gold rush of bugs right now but it's a temporary phenomenon." Paolo Stagno, CTO of the zero-day marketplace Crowdfense, calls the current exploit-based system the "most democratic system we have," while conceding what could replace it if vulnerabilities disappear.
Hamid Kashfi pushes back harder. The DarkCell founder, who works at Xbow, tells TechCrunch that "for every AI found and reported bug out there, there are probably 20" that are not reported. Aurora ransomware running Cursor and Claude Sonnet against more than 20 organizations, a case we covered this week, is one recent data point on the attacker side. Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation, points at the other end of the pipeline: developers who "vibe-code" with AI tools are shipping new vulnerabilities into the wild, and the old fight over "exceptional access" is not resolved.
Katie Moussouris, founder and CEO of Luta Security, sets the clock. "We have some distance to go before the latest phones and laptops are completely bug free," she says. "There will be some point at which finding bugs will be much harder." Her estimate for when the intelligence community starts to feel it: "I think we have at least until after the next presidential election."
Shared on Bluesky by 1 AI expert
Originally reported by techcrunch.com
Read the original article →Original headline: TechCrunch: Security Researchers Debate Whether AI Bug-Finding Will Eventually Kill Government Hacking Ops