
Big Bad Wolf: AI doesn't break security, it reprices it
The article argues that AI does not fundamentally break cybersecurity but rather reprices the economic balance between attackers and defenders. It posits that AI strengthens defenses with cheap correctness checks while weakening those relying on economic deterrence due to verification asymmetries. The author concludes that the inherent complexity of defense makes it more costly than attack, a dynamic AI exacerbates.
- ▪AI reduces the cost of security tasks when a cheap and reliable correctness check is available, which strengthens formal verification but weakens economic deterrence.
- ▪Defenders face a verification asymmetry because they lack a simple oracle to confirm success, whereas attackers can easily test if their exploit worked.
- ▪Attacking a complex system is inherently cheaper than defending it because attackers only need to succeed once, while defenders must secure every component at all times.
- ▪Integrating AI into defense introduces new attack surfaces, such as prompt injection and context window leakage, increasing the complexity of the system.
Hacker News (AI / LLM) files mainly under ai. We currently carry 7,587 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | Substack |
| Canonical URL | https://salivan.substack.com/p/big-bad-wolf |
| Publication time | Sun, 04 Oct 2026 19:28:10 +0000 |
| Retrieval time | 2026-10-04T20:19:05.904Z |
| Last seen | 2026-10-04T20:19:05.904Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | Twyst0KX4Q6b · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Big Bad WolfAI doesn’t break security. It reprices it.Salman SaghafiOct 04, 2026ShareRecent headlines obsess over rogue AI outsmarting cybersecurity defenses, but the real threat is quieter: critical Internet defenses are built on economic assumptions that AI is undermining. AI slashes the cost of a task when a cheap and reliable correctness check is available. That single fact strengthens defenses that enforce security properties but weakens those that rely on economic deterrence.Every textbook condemns “security through obscurity” and praises “formal verification”. Yet security through obscurity is everywhere, while formally verified security is limited to niche use cases.It’s the economy, stupid.Security is never free.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at Substack.