4 ms·
>Every executive/leader I've shown Claude Cowork to has gone from 'what is AI' to 'vibecoding whole apps' in weeks. Do you, and those executives, own the risks
by Ucalegon 5mo ago
>Every executive/leader I've shown Claude Cowork to has gone from 'what is AI' to 'vibecoding whole apps' in weeks.
Do you, and those executives, own the risks associated with that practice? Are those risks actually indemnified?
Its neat that 'anyone can do anything' but if they don't actually know what the risk to business or 3rd parties, why is this a good thing, especially in the enterprise where there are actors who are explicitly looking for this type of environment to exploit?
- baxtr 5mo agoWhat kind of risk do you see?
- Ucalegon 5mo agoDepends on what types of apps are being built, what data they touch, and what those apps are exposed to from a network perspective. Ie; all of the fundamentals of information/network security. Generally speaking, most executives do not have an information/network security background but do have privileged access to extremely valuable information, even if an attacker just has access to their email.
- ninjagoo 5mo ago> most executives do not have an information/network security background but do have privileged access to extremely valuable information, even if an attacker just has access to their email. In a properly structured organization, of which there are many and who are required by regulations and/or best practices, senior executives tend to have need/role-based access to information, just like everyone else in the organization. So they may have access to strategic business information, but not patient records or payroll. They may have access to planning data, but not the financial records of individual or clients. Etc. etc. Smaller or newer orgs may not have this compartmentalization, but in general I think the principle holds true for orgs over a certain number of folks in size.
- Ucalegon 5mo agoI do not disagree with anything you said. Generally, when it comes to 'privileged' information within an executives inbox it is business information or trust releastionships and not specific PII/PHI of an user. It was me being terrible at trying to impart that even the most begin seeming access may have major consequences even if it is not a total compromise of everything given the massive scope of 'what could happen' with executives vibe coding applications, like something managing their inbox past their EA, or something trivial seeming.
- dpoloncsak 5mo agoRight but your Head of HR may have access to the drive with employee PII in it, or your CTO may be able to view your IT team's password manager. These are 'proper' (sometimes) access controls, but can still be abused. Not from email...but you get the idea.
- ageitgey 5mo agoThese are largely friends and peers, so they ultimately own their own risks. But I'm not saying it is good or bad. I'm just telling you what is happening in the real world. Every senior person I know, whether a high tech exec or a solo coffee bean importer, is vibing to some degree. Some will be more successful than others. I've been working in tech since the late 90s. This is the biggest and most sudden change in company behavior I've ever seen. The only thing that comes close was the web 1.0 world in the 90s where everything suddenly became websites. That creates tons of risks and opportunities. Good and bad. Maybe a great time to start a security company. But maybe a terrible time to be a small time web app developer when your clients can get 'good enough' in minutes for dollars on their own.
- Ucalegon 5mo ago>But I'm not saying it is good or bad. Wait, you exposed people to a technology, taught them how to use it, then you are not going to own the implications of that action without teaching them about the risks or telling them how they need to ensure they don't shoot themselves in the face or violate their duty of care? Do you understand what you are saying and the implications of that in the real world relative to the insurance contracts that they have? Your company is associated with HIPAA, you should have a much higher standard than this.
- ageitgey 5mo agoYou are assuming like 12 things that aren't true in this response.
- Ucalegon 5mo agoExplicitly name them then.
- tclancy 5mo agoPlay the ball, not the man, dude. Hectoring people on the Internet because you're stressed out about something isn't going to magically fix how you feel. Digging into their profile to make it personal is three steps too far.
- infecto 5mo agoI found the Microsoft guy!
- Ucalegon 5mo agoWhat does this even mean?
- infecto 5mo agoJust going on and on about compliance when you have no idea about the details. It’s a classic example of how IT fails most large orgs.
- Ucalegon 5mo agoCompliance isn't required due to a vendor. Compliance is due to the legal obligations thanks to local regulations and obligations that are defined through contracts with 3rd parties. Saying 'found the Microsoft person' expresses a lack of understanding of the domain.
- infecto 5mo agoYou kind of just proved my point. Sorry I should not have been joking but i don’t think you have a grasp what’s going on around you. This is how IT acts in my enterprise orgs. There is absolutely a need for compliance and governance but unfortunately the people in these roles are typically not technically minded and have low incentives to innovate so you get these folks only really arguing for their jobs.
- Ucalegon 5mo agoCool story bro. Do you think the MSFT sales person, or anyone who has the financial incentive to innovate, doesn't want you to innovate? They want you on Azure and O365 regardless, they don't care. Hell, Microsoft will give you will give you 150k [0] of credits to do so. But keep talking as if you have some magical, unique, special insight that escapes contracts and the law, compared to the people who, sadly, have to deal with reality. [0] https://www.microsoft.com/en-us/startups https://www.microsoft.com/en-us/startups
- BoredPositron 5mo agoWhat risks? You don't even known what they are building and you start the FUD train.