The DevSecOps Challenges of AI-Powered Coding with Alon Yamin
Copyleaks CEO Alon Yamin delves into the DevSecOps challenges organizations are encountering as they rely more on artificial intelligence (AI) coding tools to write software, which may lead to more vulnerabilities than ever finding their way into production environments.
Transcript
This is Textron tv. Hey guys, thanks for the throwaway here with Alan Yemen, who is CEO of copy Leaks. And we're talking about, well, all the vulnerabilities that seem to be generated by these AI tools that folks are using.
'cause well, it turns out that the AI was trained using code that was vulnerable, so shouldn't come as much as a surprise that it's generating code that is vulnerable. Aah, welcome to show. Thank you.
Thanks Michael. Thanks for having me. Um, yeah, there's a, a lot happening with AI and with code specifically.
So how big an issue is this gonna be? Because if we see an exponential increase in the amount of code that is being developed, um, won't that just increase the number of vulnerabilities that we're trying to fix and we just might be as far off as ever. Yeah, I think, you know, what's important is first be aware of the AI risks and what does it mean when you're coding using ai.
And I think the second thing is really making sure that you have solutions, you have, uh, technologies that you're working with in order to mitigate those risks. Um, specifically, um, you know, with AI code, we're seeing the two main risks. One is around copyright infringement, IP, and licensing.
Um, so, you know, this shouldn't come as a surpris in the end like any other piece of content. If code is getting created using AI, using large language models, um, it came from, you know, existing materials, existing data, existing data sets. Uh, what's really missing with AI code is having this visibility, this transparency around where this code actually came from.
So a lot of the time you kind of like get code that is sped out from copilot or any other LLM that you're using, but you dunno where it came from. Maybe it's under a license that says you're not allowed to use it in a commercial setting, for example, or that you're not allowed, um, to use it, uh, while changing the code. Um, so, uh, what what's important to know is that there are tools out there that are able to, again, mitigate those risks for you, let you know whether or not this code is original, whether or not it was u it it came from somewhere.
If it came from somewhere, let's say it's a, you know, a GitHub repository, what license it's under and whether or not it's, uh, safe to use it. So that's the first area. The second area is really risks that are, um, you know, inside the code.
So how do you know that the AI or the LLM that you're using is actually, uh, creating what, what you, uh, wanted to create and that there are no any like code, uh, vulnerability. Is there any issues with it that you know, not aware about? Uh, here, of course, one of the main things that is important is making sure that you have visibility around how code or content as a whole is getting created within your organization.
Uh, make sure you have AI policies, make sure you have visibility around where AI is being used. Make sure that you're able to enforce these policies. Um, and like any other powerful technology you need to have like some solutions that are able to, you know, mitigate the risks.
You can look, look, look at it a little bit like, you know, you have antivirus for, you know, any vulnerabilities you have on your laptop. You need similar things. Also while working, uh, with powerful technologies like, um, generating ai.
Um, One of the issues that I hear from developers is while they love these tools, they've come to realize that they don't have a lot of context for the code that gets generated by those tools and it makes it harder for them to discover the vulnerabilities 'cause they didn't write the code in the first place. So, um, how do we kind of get in there and figure out what's going on? Yeah, I think it's definitely an issue.
Um, I think a lot of the time if you understand where the code is coming from, you can understand also if this is something that you can trust. Is this something that you can have confidence in or not? So a lot of the times luckily we're able to track the original code that the LLM used in order to create whatever, um, um, output that is, uh, presented in that case, again, we're able to link it, uh, potentially to a specific co directory or a repository.
And then you can see is it like a website that you will trust and you as a human would get actually, uh, code from? Is it something that looks, uh, more shady or less trustworthy? So a lot of the time just having visibility around the real source of the content or the code, um, uh, will help you to mitigate these risks.
Um, what, but what's important to understand is that nothing is a hundred percent, it could be that the text adding created by these platforms that is somehow kind of like a mix of all these different sources that it created something that is, uh, pretty much original in that case. Uh, really when you're working with, uh, generative AI code, important to understand and distinguish between when it's created by code and when it's when it's created by ai and when it's created by you as a human. And if it's created by ai, I would, uh, inspect it a little bit more, um, scrutinize it, make sure that I really understand what's happening there more than I would with, um, human created code.
You talk to some people and they will describe a future that kind of looks something like this. There's one model writing the code, and there's another model that's inspecting the code and looking for vulnerabilities and these licenses issues. So will we see AI models and AI agents that are kinda optimized for that specific task that will sit alongside human developers?
Yeah, definitely. It's like, you know, at, at, at, at some point you get to a level where it's kind of like AI versus ai, uh, like any other technologies, you know, in the end, like you have vulnerability with your laptops. Again, um, it's not a human that is looking at the laptop.
It's like you have a software that is scanning the laptop and identifying vulnerability. So in the end, you know, it's very hard to kind of like combat that as, as a person, us as people, it's even hard to say, if this piece of code is created by AI or created by a human, we have no, it's very hard to distinguish. So you definitely need to have, um, strong AI platform solutions that will help you, um, uh, tackle this issue.
And in the end, this is, uh, yeah, it's a, a, a game of AI versus ai and in the end, as AI getting more and more sophisticated, there is going to be more and more need of AI tools, AI models that will be able to mitigate the risk. And of course, working in the way hand in hand with, uh, human developers, um, that will always be there. And I think there is, uh, really importance also for, you know, human insights and human innovation and that I don't see, you know, disappearing anytime soon.
Mm-hmm. Um, as we go forward, will the state of application security get worse before it gets better then? I mean, what should we expect?
Yeah, I think, um, probably yes. I think it's already a bit worth than it, than it was before. And I think the problem is, is that it also takes time for the market to adjust to this new situation.
Even if there are tools and technologies out there to mitigate some of these risks, the market is still very young. So there is lack of understanding of, you know, what are the tools that I need to have in place, what's the strategies around or AI policies that I need to have in place in order to really make sure that I'm, I'm working with these technologies in a safe way. So I think we're in kind of like this area of in between where, uh, there are definitely a lot of risks out there.
Um, I think the situation now is much better than, you know, it was even like a year ago, you know, where, um, church EPT just came out and generative AI became u uh, you know, much more widely, uh, used. There was a period in the beginning where, you know, companies, individuals were like, you know, I wanna make sure that AI is not being used at all in marketization. I'm afraid of it, I how to control it.
Um, and of course that's, that's not a strategy 'cause AI is all over. Uh, it's around us. Uh, we, we, if we'd like it or not, I think now things are shifting and we are getting to a point where organizations, enterprises, um, and individuals, um, understand the benefits of working with generative ai, but also understand that while you are working with this powerful technology, you gotta have tools in place to mitigate the, some of the risks that are coming with it.
Um, so I think we're getting to a point where, um, um, you know, things are getting better and better over time. We're starting to use technologies, we're starting to use softwares, uh, that are able, again, to mitigate these risks. But it's important to understand that this is an ongoing, uh, uh, thing.
You know, as technology is getting more and more sophisticated, the tools that are protecting against it, uh, needs to adopt as well. There are always, you know, the ai uh, market is probably the most dynamic market in the technology, uh, world right now. So nothing is, uh, stale.
And it's important to always see, um, you know, what, what are the new technologies? What are the new, uh, threats and what are the new, uh, challenges and make sure that you're up to date and, uh, using the right tools, uh, in order to protect yourself. Are the bad guys kinda looking at all this and basically lick their chops because they're saying, wow, there's gonna be a lot more vulnerabilities out there for us to take advantage of.
I think definitely it's already out there. I think it's easier than ever before to do, um, you know, shady things. Uh, using these, uh, these technologies, it's uh, much easier to do things in much larger scale than ever before because you have access to these technologies.
Um, so you are also able to disguise yourself in, you know, different ways now, uh, including, you know, impersonating to other people if it's with, uh, audio, if it's, you know, via text, et cetera. So there are definitely completely new threats, uh, to be aware of. And that of course, open doors to, you know, bad actors to take advantage of it.
Um, I've, I think we're seeing it all over. We're seeing it with code, we're seeing it, uh, you know, with text even take the elections. Uh, in the last years because of ai, there are so many new, uh, threats around the election and around like how we, um, basically, um, um, accessing content, treating content, um, uh, having confidence in content.
I think the main issue is how are you making sure that the information that you're seeing now, if it's a piece of code that you're getting from AI, or if it's a piece of text, is something that you can trust, is something that you can confidence, have confidence in, in order to, you know, take next steps with, integrate it with your work, et cetera. So, um, definitely I think there are new risks, definitely. I think, uh, uh, you'll have people that will take advantage of it, but the good thing is, you know, this will create a whole, um, or or already creating a whole industry of, you know, how are we protecting and how are we making sure that you're working with these, uh, powerful technologies, but doing it in a responsible and, uh, as safe as possible way.
So what's your best advice to folks then about how to approach all this? 'cause the genie's out of the bottle, it's not going back in, but how do I kind of wrap my arms around this in a way that provides maybe some much needed adult supervision? Yeah, so I would suggest, uh, don't just kind of like trust AI and just go with it.
I would say it's great to work with ai, it's important to work with ai, but make sure that while you're doing that you have tools in place that you're using in order, again, to mitigate risks that are coming with it. If it's ip, if it's security, et cetera. Um, try to look for tools that are able to provide visibility around what it is that the content that AI is, uh, is producing, where it's coming from, how regional it is, where it's been used before.
Is this a source that you can trust? Uh, is this, uh, licensed or not, et cetera. So those are all solutions that are out there that you're able to leverage and will allow you to work with AI in a more, uh, of a safe way.
Um, and then even beyond that, I think there are a lot of things that are, you know, just being aware, uh, that you have these risks with ai. There is like this kind of like education aspect of it, of like, don't just blindly, you know, work with AI and trust that everything, uh, will be fine, scrutinize it a little bit more. Um, you know, I think there is, uh, uh, no replacement for, you know, human developers.
And those are one of the, uh, uh, main reasons because you want someone to make sure that the AI is doing what it's supposed to be doing and what you're expecting it to, to be doing. So don't just kind of like blindly trust it. Make sure that you have kind of like the human factor also as part of the process, while of course using other tools, um, that are able to help you to do so.
Um, but I would definitely, uh, push people to be aware but also not be afraid of the technology in the end. There are so many amazing, uh, you know, benefits for working with these technologies, specifically for Covid being, you know, the scalability, the how fast it is, uh, et cetera. So, uh, definitely a lot of things to get excited about, but like any other powerful technology just to be, be be aware of the risks as well.
So as I kind of think about all this through the end of that whole cycle, um, will this all kind of drive people to embrace a concept called platform engineering more aggressively? 'cause I kind of need to bring some mortar to the chaos and I can't have everybody doing their own little DevOps thing on the side. Yeah, I, I believe so.
I think, you know, it, it's, it will be very interesting to see, um, in the next few years how things will go. I think the more we're seeing more and more, um, security vulnerabilities, the more we'll see organizations actually like hurting from working with these technologies. Uh, the more you we'll see more processes in place, the more you'll see more governance in place.
Um, and those are things that we're already seeing. Um, so I definitely think that, uh, that there are a few directions, you know, this can take. One thing I think no matter what will be important is again, having this, uh, visibility and transparency around where, where AI is, even where AI is being used, in what capacity is it doing what you're expecting it to, to, to be doing.
Um, those are things that I think, uh, regardless will be important no matter where it'll go. Uh, but I think we definitely, uh, should expect to see More, more of that. All right, folks, you heard in here, AI coding is quickly going from things we were highly skeptical of to maybe now too much of a good thing.
Hey Alan, thanks for being on the show. Yeah, thanks for having me. Thank you.
All right. And back to you guys in the studio.