메뉴
BL
TechCrunch AI 36일 전

오픈AI, 오픈소스 보안 취약점 패치 지원 나서

IMP
8/10
핵심 요약

OpenAI가 보안 기업 Trail of Bits와 협력하여 오픈소스 프로젝트의 보안 취약점을 찾고 패치하는 'Patch the Planet' 이니셔티브를 발표했습니다. AI를 악용한 사이버 범죄가 증가하는 가운데, OpenAI의 보안 도구를 활용해 소프트웨어 산업의 근간인 오픈소스 생태계를 방어하겠다는 전략적 의미가 담겨 있습니다.

번역된 본문

OpenAI는 오픈소스 커뮤니티가 사이버 보안을 강화하고 버그를 방어할 수 있도록 돕기 위한 새로운 이니셔티브를 월요일에 발표했습니다. 이 프로젝트는 1995년 영화 '해커스(Hackers)'의 상징적인 유행어인 '해킹 더 플래닛(Hack the Planet)'을 능청스럽게 비틀어 만든 이름인 '패치 더 플래닛(Patch the Planet)'으로 명명되었으며, OpenAI가 보안 회사인 Trail of Bits와 협력하여 오픈소스 유지 관리자들이 프로젝트를 안전하게 지킬 수 있도록 돕는 방식으로 진행됩니다.

OpenAI에 따르면, Trail of Bits의 보안 담당자들이 오픈소스 유지 관리자들과 직접 협력하여 잠재적인 코드 문제를 검토할 예정입니다. 이 과정에서는 'Codex Security'와 같은 OpenAI의 보안 도구들이 지원 용도로 사용될 것입니다.

OpenAI는 월요일 성명을 통해 "많은 유지 관리자들이 이미 제한된 시간과 자원을 그대로 쓴 채, 더 많은 보고서를 더 빠르게 분류해 달라는 요구를 받고 있다"며 "패치 더 플래닛은 보안 엔지니어가 유지 관리자에게 전달되기 전에 발견된 문제를 검토하고, 프로젝트와 협력하여 패치 및 테스트를 개발하며, 초기 수정이 이루어진 후에도 팀이 계속해서 보안을 개선할 수 있도록 재사용 가능한 워크플로우를 구축함으로써 그 부담을 줄이기 위해 고안되었다"고 밝혔습니다.

즉, Trail of Bits의 엔지니어들은 코드 구급대원(EMT)과 같은 역할을 하게 됩니다. 이들은 OpenAI의 소프트웨어 지원을 바탕으로 오픈소스 프로젝트 유지 관리자가 잠재적인 문제를 식별하고 우선순위를 정하는 것을 도와줄 것입니다.

다소 야심 찬 프로젝트처럼 들리지만, 장기적으로 어떻게 작동할지, 혹은 (가능하다면) 어떻게 규모를 확대할 계획인지는 다소 불분명합니다. 오픈소스 프로젝트는 상업용 소프트웨어 산업이 기반을 두고 있는 디지털 토대이지만, 안타깝게도 생태계의 탈중앙화된 구조와 미흡한 모니터링으로 인해 많은 소프트웨어가 안전하지 않은 상태입니다. 오픈소스 프로젝트의 버그는 상업용 코드베이스에 큰 문제로 변질될 수 있습니다. 몇 년 전 널리 사용되는 오픈소스 유틸리티에서 심각한 취약점이 발견되었던 'Log4j(로그포제이)' 사태가 그것을 보여주는 좋은 예입니다.

Anthropic의 공개된 보안 도구인 'Mythos' 같은 도구를 둘러싼 우려의 대부분은, AI가 이제 코드베이스 내의 기존 버그를 자동으로 식별하고 이에 대한 익스플로잇(공격 코드)을 스스로 만들어낼 수 있다는 사실에서 기인하는 것으로 보입니다. 사이버 범죄의 자동화가 새로운 것은 아니지만, 이러한 도구들이 악의적인 행위자들에게 확실히 훨씬 더 큰 편의성을 제공할 잠재력을 가지고 있는 것은 부인할 수 없습니다.

OpenAI는 그 공식을 정반전으로 뒤집어 AI를 활용해 오픈소스 커뮤니티가 스스로를 더 잘 보호할 수 있도록 돕고 있습니다. 이는 오픈소스 커뮤니티가 절실히 필요로 하는 기능이라는 점을 인정하면서도, Anthropic을 겨냥한 경쟁적인 움직임으로 읽히는 것은 어쩔 수 없어 보입니다.

원문 보기
원문 보기 (영어)
OpenAI announced a new initiative on Monday designed to help the open source community improve its cybersecurity game and ward off bugs. "Patch the Planet," (which is a not-so-subtle allusion to " Hack the Planet ," the iconic catch phrase from the 1995 movie Hackers ) will see OpenAI team up with the security company Trail of Bits to help open source maintainers secure their projects. OpenAI said security staff from Trail of Bits will work directly with open source maintainers to review potential code issues. OpenAI's security tools — like Codex Security — will be used to assist in the process. "Many maintainers are already being asked to sort through more reports, more quickly, with the same limited time and resources," OpenAI said Monday. "Patch the Planet is built to reduce that burden, not add to it: security engineers review findings before they reach maintainers, work with projects to develop patches and tests, and build reusable workflows that help teams continue improving security after the first fixes land." In other words, Trail of Bits engineers will function more or less like code EMTs — there to help open source project maintainers identify and triage potential issues, all supported by OpenAI's software. It sounds like an ambitious project, and it's somewhat unclear how it will function in the long term, or how it plans to scale up (if at all). Open source projects are the digital bedrock upon which the commercial software industry rests, but, unfortunately, due to the decentralized and poorly monitored structure of that ecosystem, much of the software is insecure. Bugs in open-source projects can turn into major problems for commercial codebases. The log4j debacle from several years ago — when a bad vulnerability was discovered in a widely used open source utility — is a good example. Much of the concern surrounding tools like Mythos (Anthropic's highly publicized security tool) seems to stem from the fact that AI can now automatically identify existing bugs within codebases and set about creating exploits for them. While the automation of cybercrime is not new, these tools undoubtedly have the potential to make it significantly more convenient for bad actors. OpenAI is turning that formula on its head by using AI to help the open source community better protect itself. It's hard not to read it as a competitive swipe at Anthropic, while also recognizing that it's something the open source community desperately needs. Topics AI , AI , open source software , OpenAI , Trail of Bits When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence. Lucas Ropek Senior Writer, TechCrunch Lucas is a senior writer at TechCrunch, where he covers artificial intelligence, consumer tech, and startups. He previously covered AI and cybersecurity at Gizmodo. You can contact Lucas by emailing lucas.ropek@techcrunch.com. View Bio June 18 Los Angeles Get an inside look at what it takes to scale and succeed from leaders at Mach Industries, Founders Fund, and Shinkei Systems. Through candid fireside chats and high-impact networking, you'll walk away with valuable insights and new connections. REGISTER NOW Most Popular Every new iOS 27 feature that's worth knowing about Lauren Forristal Aura's impressive e-ink photo frame doesn't even look digital Amanda Silberling The CEO of Allbirds' new AI biz has a plan. Now she needs a "brand-new team" Tim Fernholz The US says ASML's top chip tool may be in China, but how? Connie Loizos The 11 standout startups from YC's Demo Day, according to VCs Marina Temkin Dominic-Madori Davis NASA picks Eric Schmidt's rocket company for Mars mission, setting up a race with SpaceX Tim Fernholz SpaceX to acquire Cursor for $60B in stock, days after blockbuster IPO Sean O'Kane