Elektrine lite

← Feed

@varx@infosec.exchange

2026-02-08 13:41 UTC

@nolan@toot.cafe I can see companies successfully discarding reusability (as repugnant as that would be), but maintainability isn't something you can escape. That's my bet. Security also isn't something you can test your way out of. Tests show that the software *does* a thing, rather than that it *doesn't* do a thing. There are such things as security tests but they're usually written with specific implementations in mind, preventing certain kinds of easy mistakes from creeping into the codebase unnoticed. You can't take a set of security tests for one implementation and trust that they'll do anything for another one. (Many are also regression tests for a specific impl, written in retrospect...)

Replies (1)

  • @nolan@toot.cafe 2026-02-08 18:34

    @varx@infosec.exchange For sure, the test I mentioned above was in response to a known use-after-free in Firefox. That said, I find it interesting that a lot of people seem to be saying, "AI can do _other_ people's job, but the thing I'm a specialist at? No way." This could be construed as a variant of the Gell-Mann amnesia effect (experts can spot the BS) or just cope. I'm not sure, but I do know that many people at the security company I work for are taking claims like this seriously: https://socket.dev/blog/the-next-open-source-security-race-triage-at-machine-speed

    Open ##2649400