2 ms·
Security through obscurity is dead, and AI delivered the fatal blow
- gtadesktop1 21d agoYes, that's 100% correct. Security by obscurity is really bad, especially because with open-source projects, hundreds of people can review the code, find bugs, and improve it. According to statistics, significantly more cyberattacks succeed on closed platforms where the code isn't accessible. For anyone who wants to see the statistics, here's a link to some data—or rather, a statement from a security economist: https://www.researchgate.net/publication/220891308_Security_of_Open_Source_and_Closed_Source_Software_An_Empirical_Comparison_of_Published_Vulnerabilities https://www.researchgate.net/publication/220891308_Security_...
- merelydev 21d agoThat may be true for popular projects with allot of contributers, but for small projects, being closed source in the age of LLMs is not a bad idea especially for server side code, it can be more secure simply because the bots don't have access to your code and can't do analysis on it.
- silverFork 21d agoA trained AI I believe is capable of reverse compiling from machine language back to the source code. Access to the source code is not necessary for them I think.
- deleted 21d ago[deleted]
- merelydev 21d agoThis is why I said especially for server side code which does not ship binaries.
- gtadesktop1 19d ago[dead]