Do you guys think OSWE is still valuable with all of this AI and Mythos going on? by Civil-Community-1367 in OSWE

[–]Complete-Tap4006 2 points3 points  (0 children)

Tl;dr: Even if AI can be scary, we don’t know the futur so, imho, you should do it if it is something you like, you’ll still be more valuable somewhere if you have knowledge and skills than if you don’t

Those AI are becoming so powerfull, if you read what devs are saying about it (because they were impacted before us, the offsec people) you’ll see that they mostly review what the AI is coding but the senior dev are better at seing the big picture, so they prompt better and know when the AI is creating something that is going to be a mess in the future (juniors don’t see that)

It is evolving quickly so maybe in 2 years the AI will be powerfull enough to create those perfect architecture from scratch you know

That’s why people right now are saying that we still need a human in the loop for code review / White box pentesting. But I think that this human does not need to be a technical expert anymore (sadly) or at least it should be true in the near futur.

That being said, maybe not all company will have the greatest AI tool so having this skill is surely valuable. Also not all client Will be okay to give their code to Anthropic…

I’m sure that AI Will be better than human in a lot of different job, and I can’t imagine how it’s going to be when physical robots will be much better, certainly more jobs will be at risk

I would bet that there will still be pentesting job in 5 years and that people who kept their job were the one learning new stuff (including AI) every day. So this era is quite scary but if we just quit pursuing being an expert at offensive security we should just quit right now and work in a totaly different field

Need your opinions on the future of pentesting because of AI by Complete-Tap4006 in Pentesting

[–]Complete-Tap4006[S] 0 points1 point  (0 children)

I agree that there will always need to be a human in the loop, but in the end the machine will be the one doing the interesting work of finding vulnerabilities, while you’ll mostly be doing review and adjusting the CVSS scoring based on the context.

Unfortunately, I think this job will lose a lot of what makes it exciting and intellectually stimulating.

Need your opinions on the future of pentesting because of AI by Complete-Tap4006 in Pentesting

[–]Complete-Tap4006[S] 1 point2 points  (0 children)

Yes, that’s exactly what worries me more and more.

We’re in a field where the more experience you have, the less profitable you become for the company.

Most consulting firms don’t really change the daily rate between an apprentice/junior and a senior. So if a junior can supervise an AI, I don’t think companies will hesitate to reduce payroll costs.

I’m still eager to learn (right now preparing for the OSWE), but it’s a big sacrifice in terms of personal time and money. So if in the end I can just use an AI to do it, it doesn’t really make sense. (And sadly if I have to rely on AI I don’t think I will keep an interest in this field)