2026-02-08 04:52 UTC
Replies (1)
-
@varx@infosec.exchange 2026-02-08 04:56
@nolan@toot.cafe A lot of my work has been in security. One of the things a lot of people don't appreciate is that security is largely about what "features" *don't* exist. For example, the feature that lets an attacker read your email. 😃 You have to try to prove that negative. This is important because a lot of people evaluate software by taking it for a test drive and seeing that the happy path works. But that can never work for security. The way you write secure software is by having a secure development process; by developing and communicating threat models; by recognizing dangerous patterns and guiding the software around that. LLMs are notoriously bad at all of this. I don't think this will be better in six months.