Elektrine lite

← Feed

@varx@infosec.exchange

2026-02-08 04:52 UTC

@nolan@toot.cafe I read that post (I follow the RSS feed) but there's a really important point that you don't seem to cover: Is that code usable? It passes a lot of tests. Is it good enough to use in a real browser? (Functionality, performance, security.) Is it easy enough to work with that you could get it into good enough shape to use? Is it maintainable? *How do you know?*

Replies (1)

  • @varx@infosec.exchange 2026-02-08 04:56

    @nolan@toot.cafe A lot of my work has been in security. One of the things a lot of people don't appreciate is that security is largely about what "features" *don't* exist. For example, the feature that lets an attacker read your email. 😃 You have to try to prove that negative. This is important because a lot of people evaluate software by taking it for a test drive and seeing that the happy path works. But that can never work for security. The way you write secure software is by having a secure development process; by developing and communicating threat models; by recognizing dangerous patterns and guiding the software around that. LLMs are notoriously bad at all of this. I don't think this will be better in six months.

    Open ##2408305