Post #4168202
2026-07-28 16:05 UTC
@drwhax@infosec.exchange One thing I don't see anyone addressing is how we got into this situation in the first place, or how we get out of it, and I'm not talking about the LLM or any of the already well known and discussed downsides of that.
How did the software get so insecure in the first place? How do we prevent security vulnerabilities before they occur? Most of the risks aren't unknown or even novel, so why haven't we prioritized the solutions?
Replies (1)
-
@drwhax@infosec.exchange 2026-07-28 16:16
@zimzat@mastodon.social No one wants to fund it is what I think. Suhosin did something like this for PHP, now it's just jvoisin maintaining snufflepagus: https://github.com/jvoisin/snuffleupagus I don't remember if there was something similar for other languages. Grsecurity for the Linux Kernel, that's the three I know :/