Season 1, Episode 71

The AI That Found A Bug In The World’s Most Audited Code

The AI That Found A Bug In The World’s Most Audited Code

0:000:00

Listen on:

About this episode

Matt Knight spent five years as OpenAI’s CISO. Now he runs what colleagues call “the most interesting job at the company”: leading Aardvark, an AI agent that finds security vulnerabilities the way a human researcher would—by reading code, writing tests, and proposing patches. It recently found a memory corruption bug in OpenSSH, one of the most heavily audited codebases in existence. In this conversation with a16z’s Joel de la Garza, Matt traces the evolution from GPT-3 (which couldn’t analyze security logs at all) to GPT-4 (which could parse Russian cybercriminal chat logs written in slang) to today’s models that discover bugs humans have missed for decades. They also discussed the XZ Utils backdoor that nearly compromised half the internet and why 3.5 million unfilled security jobs might finally get some relief, and how Aardvark could give open source maintainers a fighting chance against nation-state attackers. If you enjoyed this episode, please be sure to like, subscribe, and shar

Recent Episodes

Can Open Source Keep AI Power From Concentrating?

a16z Podcast·Ep. 1191· 485·

MTS host Sophia Dew visits the Open Source AI Summit in San Francisco to ask researchers and founders across the AI stack a central question: can open source prevent AI power from concentrating in the hands of a few companies? Lukasz Kaiser, co-author of Attention Is All You Need, argues that today’s concentration may be a feature of the current technological paradigm rather than a permanent feature of AI. Transformers reward enormous amounts of data and compute, but future breakthroughs could make smaller, more specialized models far more capable. Across conversations with researchers and builders working on open models, infrastructure, and applications, Sophia explores why China has taken the lead in open-weight models, whether the U.S. needs more open-model startups, what it means for companies to own their own intelligence, and where openness alone falls short, particularly when access to compute remains concentrated. Resources: Follow Lukasz Kaiser on X: https://x.com/lukaszkaiser

Your AI Doctor Is Coming | Julie Yoo

a16z Podcast·Ep. 1190· 1707·

a16z General Partner Julie Yoo joins MTS host Sophia Dew to explain why she believes healthcare could benefit more from AI than almost any other industry, and why decades of slow technology adoption may actually give healthcare an advantage in the AI era. Julie traces healthcare’s evolution from paper records and fax machines through electronic health records and telehealth, and explains why AI represents something different: an organic adoption wave driven by tools that doctors and patients actually want to use. Because healthcare never built the same layers of legacy software as other industries, it may now be able to leapfrog directly into agentic AI. They also explore how AI could dramatically lower the cost of care, why consumers are becoming a more important payer, where Julie sees the biggest opportunities for healthcare founders, and a future where everyone has a highly personalized AI doctor in their pocket for life. Resources: Follow Julie Yoo on X: https://x.com/julesyoo Fol

Aaron Levie on Why Open AI Wins

a16z Podcast·Ep. 1189· 1865·

Box co-founder and CEO Aaron Levie joins MTS hosts Theo Jaffee and Sofia Puccini to make the case for open-weight AI, unpack the economics of open versus closed models, and explain why he believes more openness could strengthen rather than undermine the U.S. AI ecosystem. Aaron argues that open models create more use cases, push closed labs to innovate faster, and don't fundamentally change where the economics of AI ultimately accrue. They debate model distillation, America's competition with China, why restricting access may simply accelerate competing AI ecosystems, and whether U.S. labs should begin releasing open-weight versions of previous-generation models. They also get into what the latest frontier models mean for knowledge work, how AI has changed software engineering at Box, and why Aaron believes companies cutting engineers may simply not be ambitious enough. Finally, they discuss why enterprises are unlikely to bet on a single model and why the layer that routes between mod

The A.I. Mob That Attacked Hugging Face + METR’s Ajeya Cotra

Hard Fork·Ep. 211· 4726·

This week, we’re diving into two new reports about the OpenAI-Hugging Face hack. We discuss what’s new and how they fundamentally change our understanding of what happened. Then we’re joined by Ajeya Cotra, one of the investigators at METR, to discuss the rogue agents’ message board and chain-of-thought transcripts and how the world should respond. Guests: Ajeya Cotra, co-author of the METR and Redwood Research report on the OpenAI-Hugging Face hack. Additional Reading: Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident The Hugging Face Attack Surprised Me The Hugging Face Incident and the Road Ahead Nvidia Buys Hugging Face in $12.9 Billion Deal We want to hear from you. Email us at [email protected]. Find “Hard Fork” on YouTube and TikTok. Subscribe today at nytimes.com/podcasts or on Apple Podcasts and Spotify. You can also subscribe via your favorite podcast app here https://www.nytimes.com/activate-acce