3 ms·
>No human should ever be forced to look at the code behind my vibe coded internal admin portal Except security researchers. I work in cybersecurity and we alre
by integralid 7mo ago
>No human should ever be forced to look at the code behind my vibe coded internal admin portal
Except security researchers. I work in cybersecurity and we already see vulnerabilities caused by careless AI generated code in the wild. And this will only get worse (or better for my job security).
- raw_anon_1111 7mo agoAnd you haven’t seen security vulnerabilities in the wild based on careless human generated code?
- icedchai 7mo agoYep. Unless you inspect the payload and actual code / validation logic, there is nothing to distinguish an API that "works" and is totally insecure from one that is actually secure. I've seen Claude Code generate insecure APIs that "worked", only to find decided to add a user ID as a parameter and totally ignore any API token.