Elektrine lite

← Feed

@varx@infosec.exchange

2026-02-08 04:56 UTC

@nolan@toot.cafe A lot of my work has been in security. One of the things a lot of people don't appreciate is that security is largely about what "features" *don't* exist. For example, the feature that lets an attacker read your email. 😃 You have to try to prove that negative. This is important because a lot of people evaluate software by taking it for a test drive and seeing that the happy path works. But that can never work for security. The way you write secure software is by having a secure development process; by developing and communicating threat models; by recognizing dangerous patterns and guiding the software around that. LLMs are notoriously bad at all of this. I don't think this will be better in six months.

Replies (2)

  • @varx@infosec.exchange 2026-02-08 05:02

    @nolan@toot.cafe The strongest steelman position I can make for the use of LLMs is that a senior developer can use them for fast feedback and maybe brainstorming. (As long as they're happy to accept a list of serious downsides and externalities.) When I see junior devs use them, the LLMs lead the dev down the garden path, creating more and more complicated workarounds where a senior dev would back up and take a fundamentally different approach. And when I see senior devs treat them as a team of junior devs that can independently produce a body of work, well... that's not a good way to work with actual junior devs! You have to carefully review their work, do mentoring, etc. There are somewhat analogous things you can do with agents but I don't have the sense that this is what people are really doing.

    Open ##2408306

  • @nolan@toot.cafe 2026-02-08 05:04

    @varx@infosec.exchange The Web Platform Tests are a pretty high bar of quality. If you read through them, most of them are about bizarre edge cases that, yes, include security, e.g. https://github.com/w3c/IndexedDB/issues/476 The code is probably awful when it comes to maintenance, reusability, etc., but I'm starting to wonder if any of those values matter anymore. There are of course exceptions, e.g. a common joke in W3C circles is about the "hit testing spec" that doesn't exist, but WPTs are otherwise pretty exhaustive.

    Open ##2408307