I see this reoccurring discussion very often of people absolutely despising AI usage in CTFs or any competitive penetration testing or programming. This post isn’t to necessarily defend AI, nor dismissing other the detrimental outcomes that result from AI usage. Im relatively new to offensive security but here are my current thoughts:
Though I don’t quite use AI like the top competitors- Reality is in the current world, businesses do not care if you use AI as long as their goal for a penetration testing or software development is cleanly and safely hitting it’s goal. It’s essentially a view of better automation for leverage instead of a ‘Claude do this make no mistake’. As someone in tech, I love automation.
Now I haven’t necessarily experienced this myself as I’m on the younger side but I like to think of this day of age akin to when the browser was popularized to the normal person. It was a completely new concept to the individual who was familiar with learning strictly from books. I’m sure there were philosophical discussions if receiving knowledge from a browser search was efficient or damaging. In the era of browsers that is why we were asked to cite sources that were backed by academic resources. I believe unfortunately, if we don’t adapt and use it we fall behind. This is just a hard to grasp evolution of the field and world.
AI is unmistakably the future whether we collectively hate it or not. As I grow further in offensive security, my goal is to accomplish tasks manually, so I know what is actually happening, but also to be able to accomplish that given task more rapidly and proficiently with using autonomous AI agents.
Back to CTF and competitive use, what I’d like to see is separation of AI and manual competition. I think it would be very hard to deploy though as we do most of this remotely and that’d require some clever and intrusive monitoring software. I would love to see it for in-person CTFs and fascinatingly I did see it at DEFCON in the Pack Hacking Village CTF.
Leave a comment