Job losses are among the most discussed topics regarding artificial intelligence. One group of people thinks that AI will bring about the end of humanity. Another group fears that all professions will disappear.
I believe we are facing a much more real danger today.
That is the thoughtless integration of artificial intelligence into institutional systems.
Two incidents I encountered in the last few days have shown once again how serious a problem this is. What is interesting is that one of these incidents occurred in a public institution in Turkey, while the other took place at one of the world's largest technology companies.
The KGM Example
After the holiday, I logged into the General Directorate of Highways (KGM) system to check if there were any issues with my HGS (Fast Pass System) records.
The picture I encountered was quite surprising.
It was possible to access transit records using only license plate information without any identity verification.
More interestingly, although the vehicle we queried was a 2023 model, records from 2017 were visible in the system.
I understood the reason shortly after.
The system was tracking the license plate, not the vehicle.
In other words, if the same license plate had been used on another vehicle in the past, records from that period could also be viewed. In other words, one person could access another person's past journeys.
I called the call center to report the issue.
I was met with an AI-powered voice response system.
Out of curiosity, I provided a license plate number.
The system began sharing the relevant transit information without verifying whether the license plate belonged to me.
The point to pay attention to here is not the artificial intelligence itself.
The real problem is how the data and permissions accessed by the AI are defined.
At this exact point, the Personal Data Protection Board (KVKK) decision published last week comes to mind.
The Personal Data Protection Board has adopted a highly restrictive approach against the use of biometric data such as fingerprints, facial geometry, retina, and iris in employee attendance tracking.
The justification is also extremely logical.
This data is extremely sensitive. Once compromised, it is impossible to change.
However, one cannot help but ask the following question:
If, on one hand, systems that track attendance via fingerprints in companies are being scrutinized, while on the other hand, information regarding citizens' travel history can be accessed without sufficient verification, is the priority ranking being established correctly here?
There is a serious difference between knowing what time a person arrives at work and knowing which cities a person has been to, which routes they have used, and on which dates they have traveled.
In data security discussions, it is necessary to look not only at what data is collected but also at who can access which data.
The Meta Example
Around the same days, a remarkable piece of news was published regarding Meta.
Hackers managed to take over hundreds of accounts. Among them were accounts of well-known individuals and major brands.
According to allegations, the method was extremely simple.
They reached out to AI-powered customer service and made some change requests regarding the account.
The AI system fulfilled these requests without sufficient verification.
Email addresses were changed.
Password reset links were sent to the new addresses.
As a result, the accounts fell under the control of the attackers.
Meta later announced that the vulnerability had been closed.
However, the fundamental problem here was not the existence of artificial intelligence.
The problem was what permissions were granted to the AI and with what controls these permissions were limited.
The Real Problem Is Not Artificial Intelligence
These two examples appear completely different at first glance.
One is in the public sector.
The other is in the private sector.
One is in Turkey.
The other is in America.
But both tell the same story.
Many institutions think about efficiency first when trying to integrate AI into their systems.
Faster customer service.
Fewer personnel.
Lower costs.
Higher automation.
However, most of the time, the following question is not asked enough:
"What happens if this system makes a wrong decision?"
More importantly:
"What happens if an attacker tricks this system?"
Today, the process works in reverse in many institutions.
First, an AI project is launched.
Then CRM systems are connected.
Customer data is opened up.
Accounting systems are connected.
Call centers are connected.
Permissions are defined.
However, threat modeling studies are often an afterthought.
Yet, the correct approach is the exact opposite.
Before an AI project begins, possible attack scenarios must be identified.
What data will it access?
What operations will it be able to perform?
What decisions will it be able to make on its own?
At what point will human approval be required?
If an attacker tricks the system, what will be the worst-case scenario?
Taking AI into a production environment without providing answers to these questions poses a serious risk.
In the past, attackers looked for vulnerabilities in software.
Today, they are targeting decision-making mechanisms.
They are trying to trick artificial intelligence.
They are trying to exceed authorization limits.
They are trying to manipulate the logic of the system.
For this reason, cybersecurity in AI projects must no longer be a layer added later, but the starting point of the project.
The KGM and Meta examples teach us the same lesson.
Artificial intelligence systems pose a risk not because they are dangerous, but because they are authorized without sufficient thought.
In the age of artificial intelligence, the real security problem is not the algorithms themselves, but the doors we open to them.
What I Reviewed This Week; Günsan smart WiFi LED bulb
One of the products that caught my attention this week was Günsan's smart WiFi LED bulbs.
Günsan's products are not entirely foreign to me. I previously had the opportunity to review the brand's smart plug, and I must say that I found it successful. I especially liked that it could enter the smart home world without complicating the installation.
The product I encountered this time was smart WiFi LED bulbs.
Although smart home technologies have been in our lives for years, they have started to become more accessible recently. Many features that used to require serious installations can now be used simply by changing a light bulb.
One of the remarkable aspects of the models I reviewed was that they work not only with their own applications but also with common platforms such as Tuya and Smart Life, in addition to GG SMART. This provides a significant advantage for users who want to build a smart home structure consisting of different brands.
The bulbs, which use 9W LED technology, operate with low energy consumption. The white light model has light tones that can be adjusted between 2700K and 6500K. It is possible to prefer a more vibrant light in the study room or switch to warmer tones in the evening hours.
The RGB model offers 16 million color options. Different scenarios can be created when watching movies, reading books, or simply when you want to change the atmosphere of the environment.
I must say that I found the timer features particularly useful. Having the lights turn on at a certain time in the morning or automatically activating in the evening are among the small but effective details that make daily life easier.
As smart home technologies become more widespread, it seems we will start seeing such products more often. These bulbs, which I reviewed after Günsan's smart plug, show that the brand is progressing consistently in expanding its product family on the smart home side.
Most Read
Striking picture for Özgür Özel's 'New Party'
Özgür Özel gives a dated response regarding the number of resignations
The PKK opening and Özgür Özel’s path!..
Forest fire in Antalya brought under control
How did the newspapers view Özgür Özel's farewell to the CHP?
He killed his wife by slitting her throat: Their children witnessed the moments
What did the CHP do?
Özel’s new party move in the world press
The New CHP, against CEHAPE
Fire at TUSAŞ engine factory in Eskişehir under control