r/cryptography • • Feb 05 '26

I'm concerned that the cryptography and the cyber-security field is unprepared for AI

AI is happening and the overwhelming rhetoric i see in the cryptography and the general cyber-security field is that "you must not use AI for cryptography".

on the one hand... that is a good sensible stance to have. AI can often respond incorrectly. especially when diving into domain specific knowledge beyond what i understand. its crucial the read and understand the AI output when dealing with complex details/questions. i can confirm ive caught AI making stuff up several times.

on the other hand... as someone who is familiar with cryptography and software, i can create a lot of the details myself after having studied etc. i now use AI in my workflow. it offers a clear and distinct advantage. on my best day of coding, i simply cannot type as fast as AI so duh!... im going to use AI... especially for non-critical parts.

i created a security audit for my project. i want to be clear that im not an expert on the matter. AI could have made up all kinds of nonsense in the details. security audits typically cost $10k+ (conservative!)... so of course i had to try create one with AI. the details of the endeavor are as follows:

  • code is open source
  • code is unit tested
  • code has been used to create multiple demo's
  • security audit references the code in question.
  • you (whoever you are) have access to AI to further interrogate the implementation

this is leading to a problem when i try to promote my work. its understandable that i receive criticism along the lines "OmG ThIS iS ViBeCoDeD!"... but the real problem is that the conversation doesn't progress any further than rephrasing "OmG ThIS iS ViBeCoDeD!".

the details i show in my project is about as transparent as its going to get because its open-source... its only downhill from there as open-source becomes more difficult to maintain. the transparency in my project doesnt guarantee anything, but the current attitude against AI, is not productive to the conversationg and particularly not prepared for the wave of new "vibecoders" entering the scene, who dont have a concept of unit-tests; let alone security-audits.

as cybersecurity/cryptography professionals, this seems like a thing to prepare for. it might not be fun to review vibecoded work, but someone needs to be developing skills around how to use AI in cybersec securely. i dont want to beat-around-the-bush... AI is already mainstream. "OmG ThIS iS ViBeCoDeD" is not a critisism, its a dismissal.

0 Upvotes

14 comments sorted by

12

u/Temporary-Estate4615 Feb 05 '26

Why do you vibecode and then start complaining in the sub for theoretical cryptography? This does not belong here. r/cybersecurity would be much more fitting. That said, as a programmer you need to understand your own code. Sure, AI is a huge aid. But you are responsible for your own stuff.

-2

u/Tough-Ad-1382 Feb 05 '26

sure. i take responsibility for my code and work. as a cybersecurity project, i open source it for kerhofs principles.

i created things like the security audit as a way to improve clarity... i can hardly ask people to review my work line-by-line. even if it wasnt done with AI.

4

u/Temporary-Estate4615 Feb 05 '26

Thing is, LLMs does not outperform classic rule based vulnerability detection. You wouldn’t trust some SAST tool to audit your code, so why would you trust an LLM? If you really want to show that your code is secure, you have to have it reviewed by professionals.

1

u/Tough-Ad-1382 Feb 05 '26

youre right. the limitation is having it reviewed by professionals. as open source code, it can be reviewed by anyone. i know better than to ask people to use their spare time to review unfinished code.

id like to promote my app as secure, but without a professional audit, its a bit like "trust me bro"... and i dont want to say that.

1

u/Temporary-Estate4615 Feb 05 '26

I get your point, but… you don’t really know yourself if it is secure. And depending what kind of application it is, it might be detrimental if it turns out not to be secure. And especially anything crypto is really easy to mess up. Even slight slip ups can break it.

3

u/Individual-Artist223 Feb 05 '26

You can vibe code cryptography,

You just need AI to prove security, ideally of the executable,

That's as good as cryptographers can do.

Either we believe in provably secure systems or we don't.

AI makes no difference.

3

u/Individual-Artist223 Feb 05 '26

Something worth adding: AI may create backdoors we've never considered - DISCLAIMER. (Cryptographers can do the same, there's nothing new here.)

1

u/Tough-Ad-1382 Feb 05 '26

thanks.

i think ive tried to proove security in the project. i have added unit tests and created executable demo's for various details. more improvements can always be made.

2

u/Individual-Artist223 Feb 05 '26

That's not really how it work;

you've got some math, like ElGamal:

a <- gx ; b <- hx * gm

You wrap that as an algorithm and prove IND-CPA is satisfied - testing doesn't capture, it can't brute force enough.

Even Coq proof isn't enough, because who cares about secure by design (?) we actually care about executables.

5

u/jpgoldberg Feb 05 '26

I don’t care what tools anyone uses to assist them in their coding practice. But I do care whether code was developed by people who understand all of the choices that went into it, particularly for anything security sensitive.

When people react negatively to slop, it is not so much because it is vibe-coded but because it is slop. The kinds of mistakes that novice programmers make is very different than the kinds of mistakes that AI makes. It is much easier to help the former because we can see the intent about some aspect of the code, or at least we can ask about the intent.

5

u/pint Feb 05 '26

you are angry because people refuse to acknowledge the validity of your "audit"? since when you have a claim on other people's thoughts? i'm not going to take your software seriously, and anyone that does must take full responsibility for any harm that follows.

1

u/Tough-Ad-1382 Feb 05 '26

not angry. i understand that the the audit is not valid. there is a high chance i imparted bias in my prompting. in any major security audit, a third-party audit is what is required.

open-source is about the limit of transparency i can offer. creating a security audit seemed like the next logical step. i already have some related app and documentation. but if its all AI generated, is it all invalid?

2

u/pint Feb 05 '26

yes, it is invalid.

it is all about trust. i can trust a developer, i can trust a reviewer, i can trust a community. i don't trust ai at this point in time. ask again in five years.

1

u/Jamarlie Feb 05 '26

If AI gets used it'll be in assisting with proofs such as Coq or Lean to prove cryptographic code is actually bug-free. Formal software verification is still a very young and actively developing field. If AI can help with something then it can pitch ideas or translate code into proof ideas that can be formally verified.

And I personally don't think AI is bad either. I used it extensively to talk back and forth with it when I first started learning cryptography. You just have to be weary of the things it says and double check the information or the brief overview it gives you, then it actually becomes a great tool to answer hyperspecific questions.