3 ms·
I'd love to see data, but my intuition is that the average developer has access to dramatically better security reviews and far lower cost than ever. There's m
by brookst 8d ago
I'd love to see data, but my intuition is that the average developer has access to dramatically better security reviews and far lower cost than ever.
There's more software being written than ever so maybe raw numbers of RCE's could be up, but as a percentage, I'd really expect them to be down. Especially among any fairly common software, as all it takes is anyone working on it to get the idea to test.
- d4mi3n 8d agoWhat I’m seeing is more developers pushing more code of dubious quality without the ability to respond to feedback on said code. You can have the best security review in the world, but if the author of the code is not equipped to understand the feedback it ends up being a moot point. The challenge to me seems less technical and more cultural: how do we keep ourselves intellectually honest and engaged when we now spend the majority of our time orchestrating agents and outsourcing the design and thought processes?
- fc417fc802 8d agoHey claude, compare this security review to the current codebase and patch up anything that needs it.
- tyre 8d agoOne issue for developers is that the most powerful models refuse to do comprehensive reviews. You can’t ask Fable 5.1 to find every exploit in your codebase, because that’s indistinguishable from what a bad actor would do.
- Timwi 7d ago> I'd love to see data, but my intuition is that the average developer has access to dramatically better security reviews and far lower cost than ever. Where? If I ask Claude to do a “security review” of my software, it gets blocked as a possible hacking attempt.