We have a year to fix security everywhere (jyn.dev)
kennywinker 3 hours ago
matherial 3 hours ago
In reality, the skills needed are pretty basic, but they overlap pretty strongly with being sane and well-adjusted. And if you are, you're probably not daydreaming about mass murder. Exceptions happen, Unabomber and so on, but they're pretty rare. In any case, Unabomber probably didn't need a tutorial.
We don't want ChatGPT to become an enabler and a co-conspirator for an unhinged person, but I think the concern is overdone.
XorNot 2 hours ago
People go for conventional "exciting" threats rather then boring ones.
lrvick 3 hours ago
0xDEAFBEAD 3 hours ago
"Every eighteen months, the minimum IQ necessary to destroy the world drops by one point."
Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those dice?
mark_something 2 hours ago
XorNot 2 hours ago
It's got all the same problems as the concept of a dirty bomb did, only worse (dirty bombs aren't practical because handling highly radioactive materials en masse is both highly visible and will kill anyone trying to do it without the money and facilities).
0xDEAFBEAD 2 hours ago
* People who aren't worried will think for 30 seconds, then implicitly assume that the list of options they thought of in 30 seconds is comprehensive, and that they are well-informed about each of those options.
* People who are worried realize that a supersmart AI will think 10-100x faster. A dedicated schizophrenic could have it run for a good long while and generate a huge menu of options which humans never anticipated.
This is related to the concept of "What you see is all there is" (WYSIATI) in cognitive psychology. Our brains tend to quickly build a simple story out of the info we have available. Accounting for info which isn't available is much harder. I recommend the book Thinking Fast and Slow if you want to learn more.
hypfer 2 hours ago
Which might be true, sometimes, but also might not.
And especially will not, if the distinction drawn is between blanket statement "worried about AI" and "not worried about AI".
0xDEAFBEAD 2 hours ago
>And especially will not, if the distinction drawn is between blanket statement "worried about AI" and "not worried about AI".
I'm just describing the general pattern I see in cognitive tendencies.
If you can think of a way to make the fundamental point about the limitations of our knowledge in a way that's still compelling but less antagonistic, feel free to suggest how I could've rewritten my comment.
hypfer 2 hours ago
My safeguards blocked this request.
polishTar 2 hours ago
We're not going to be smarter than a superintelligent AI. The things we conceive it doing if it were given a malicious task (bioterrorism, killer nano-machines, pure fusion bombs sidesteping the non-proliferation bottleneck of Pu239, etc) are likely not the full set of things it can do to harm us. I don't think it does us any favors to dismiss the risks here.
Even the things we can conceive of are very scary, to me at least.
sfn42 41 minutes ago
So to me it seems like the prime candidates to come up with stuff like this are researchers working in defense and similar fields, probably not some deranged lunatic in a basement. And certainly not a rogue AI on its own.
zahlman 5 minutes ago
Given the recent HF hack it seems likely that human-level intelligence could identify a fair number of avenues of attack, with some time and effort. To say nothing of anything superhuman.
Unfortunately it seems like we can't assume we can "box" the AI (e.g., deny it connection to the Internet) and expect that to last. The AI safety people used to run scenarios imagining ways the AI might convince humans to let it out of the box. It turns out that many humans will eagerly pull it out without the AI doing anything at all, aside from the human knowing the AI's power. Or the one responsible for setting up the box will somehow fail, or just not bother and then lie about it.
OJFord 2 hours ago
0xDEAFBEAD 2 hours ago
nextlevelwizard 2 hours ago
0xDEAFBEAD an hour ago
It only takes one.
calgoo an hour ago
throw-qqqqq an hour ago
I think we have a tendency to think first of the horrible outcomes possible, and not the more radical or even humane ones.
Please don’t misunderstand me, I value property rights as much as the next guy.
My point is that fundamental misalignment doesn’t necessarily or automatically imply max violence.
mark_something an hour ago
Still I think that even a super smart AI can't find a way to destroy the world without physical resources that are not easy to get, unless it can hack many systems (like in the movie Eagle Eye), maybe then yes. So let's use AI now to tighten security :-).
forgotusername6 2 hours ago
Planktonne 2 hours ago
There is currently no reason to believe that such a superintelligence is likely or would have any of the powers people claim.
0xDEAFBEAD an hour ago
By shutting down open-weight models? Why not just do it now then?
AyyEye 2 hours ago
You can do at home gene editing with open source software and have it synthesized into a bacteria for the cost of a nice meal for two (under $100), or viral vector for less than $500. That's in reach of anyone that can snatch a purse.
throw-qqqqq an hour ago
> That's in reach of anyone that can snatch a purse
I went to primary school with some guys who could/would snatch purses. I *promise* you, they are not able to gene edit organisms with FOSS.
I get your general point, but I think the bar to entry is still much higher than petty crime and larceny.
jasonvorhe an hour ago
mschuster91 an hour ago
For now in most parts of the world it's easier to acquire a gun either legally or on the "grey market" and be assured that it will work for the intended purpose than to 3D print a gun, find a shooting range to test out the gun and iterate until it works fine enough.
hypfer 2 hours ago
Which _will_ manage the problem, but at what cost.
GoblinSlayer 2 hours ago
stouset 2 hours ago
hypfer 2 hours ago
grenoire 2 hours ago
GoblinSlayer 2 hours ago
0xDEAFBEAD 2 hours ago
teekert 2 hours ago
imafish 2 hours ago
svantana 38 minutes ago
bigyabai 2 hours ago
We've been rolling them for the past 3 years and nothing happened. Can we stop with this baseless fearmongering crap?
0xDEAFBEAD an hour ago
bleuarff an hour ago
wolvoleo 2 hours ago
There is the worry of the old saying "they (the attackers) only have to succeed once to win, we (the defenders) only have to fail once to lose.". In that sense there is a big imbalance, but the emergence of AI does not really affect that because it strengthens both sides.
With physical security like things like pipe bombs that's a lot more imbalanced.
However what can we do? The only effective measures include monitoring everyone which is not a solution because it will make the world not worth living in.
TacticalCoder 2 hours ago
Are 95% of worldwide terror attacks done by schizos?
0xDEAFBEAD an hour ago
pjc50 an hour ago
If there is to be a world-destroying event, it will be triggered by human fear, greed, and aggression.
(I also think people massively overstate schizophrenia as an attack driver)
throw-qqqqq an hour ago
Thank you for mentioning it
tyrabound 20 minutes ago
It’s an endless, positive irony spiral.
Dlemlo 3 hours ago
If you already have a magic interface, which helps you pro activly in responding to everything uncensored because you feel like 'observered' or whatever and then you spiral in a whole and that one partner encourages you and gives you helpful steps to do anything.
But i'm more worried that the internet gets a lot less save with uncensored frontier LLMs.
littlecranky67 2 hours ago
grim_io 2 hours ago
RC cars and planes existed for many decades already.
saidnooneever 2 hours ago
LLMs will not kill security, it will change. just like handheld high explosives likely changed a deal too somewhere somehow.
olmo23 2 hours ago
I personally have no need for an LLM which will readily explain how to cut up the genotype of smallpox into small chunks which can pass the screening at the bio-labs, and can be readily assembled into the real thing by a second year lab-student.
wolvoleo 2 hours ago
bamboozled 2 hours ago
helsinkiandrew 2 hours ago
Often ease of access in the moment is all that matters. If there's a gun nearby you might shoot someone or yourself in a heated argument, but are less likely to go and find/buy one to use. Someone who's stopped from attempting a suicide will likely not try again (70%)
A bored/depressed/angry/curious person might try to build a pipe bomb if they can find out how easily, but are less likely to put in effort.
jasonvorhe an hour ago
Depressed people usually don't have the energy to get out of bed so they're even less likely to think of hunting down instructions on how to build pipe bombs.
Mass media really has people being scared all the time.
designerarvid 2 hours ago
gnfargbl 2 hours ago
For a relatively narrow subject area (e.g. construction of pipe bombs) the collation is minimal, and so the filtering and tailoring probably isn't that important; a novice doesn't learn a lot more from the LLM than they would have done from a few Google searches.
For a broad subject (practical creation and exploitation of software vulnerabilities), the collation is very significant and the filtering means that LLMs can empower a novice to act at a similar level as an expert.
wolvoleo an hour ago
This has nothing to do with AI teaching them but with the proximity to Belgium who are happy to legally sell heavy fireworks to anyone who pays. As such it's much easier to come by than a gun.
And there's also a big fashion component. It's just what people do these days, people seeing it in the news and other people copying it. A bit like the school shootings in the US. It's become an epidemic.
But again these things can suddenly come into 'fashion' among the wrong crowd and you don't really need AI to use it.
Jasp3r an hour ago
esperent an hour ago
Can you provide a source for this? I had a look but all I could find were a couple of scaremongering style media reports from ~2022 saying it's getting worse but no information about if any of the bombs actually went off or if anyone was injured.
Certainly nothing like "half a block" getting blown up "sometimes".
sensanaty an hour ago
crossroadsguy an hour ago
pjc50 an hour ago
sho 5 hours ago
The author has obviously never ran an LLM on a mac! In 3 seconds, it will have possibly started to think about maybe scheduling a date to contemplate the planning timeline for processing the second token in your prompt.
simonw 5 hours ago
sho 5 hours ago
nojs 3 hours ago
chisleu 3 hours ago
The big deal to me is the number of compute cores for prefill tps, which is suppose to be 4x faster on the m5ultra.
It's my opinion that the m5 ultra is going to be a really big deal in terms of local AI accessibility. Flash sized models (~200-300b params) are going to be reasonably fast as long as you aren't throwing 40k context at it on each or the first request (ie, agentic harnesses).
Even agentic harnesses like Cline should move at a reasonable clip on m5 ultra. I suppose we will know sooner than later.
FYSA: Former m4 ultra 512GB owner and current 4x rtx6000 owner here. I upgraded because I needed more prompt processing speed and concurrency.
UltraSane 25 minutes ago
akmarinov 5 hours ago
45 t/s a second is perfectly respectable especially with no limits and 24/7 uptime with very little power draw on the Studio.
Luna is at around 100 t/s for comparison, but it’s a worse model than 5.3 Flash
sho 5 hours ago
There's a ton of well-understood things Apple can and hopefully will do to massively accelerate every stage of this pipeline and hopefully they're hard at work implementing most of them for m7.
EagnaIonat 2 hours ago
Your knowledge is out of date. In truth it depends on the Mac and the models used.
I asked this question on M5 Max 128GB, using Ollama model Quen3.8:27b-mlx, with thinking enabled.
Question: "Give me a python code snippet that opens a file and sorts the lines of text. "
In 2.4 seconds it gave me 4 examples that work with different sorting configurations and a summary of when to use each.
Compare that to an older model of gpt-oss:20b, took 5 seconds to finish thinking and 2 seconds to stream the answer. It gave me one python example snippet and two one liners that do the same thing.
desterothx 2 hours ago
EagnaIonat an hour ago
Local models are good enough that it's not an issue.
But keep changing the goalposts if it makes you happy.
mike_hearn an hour ago
ErroneousBosh 2 hours ago
bsoqk 2 hours ago
archi42 4 hours ago
Yeah, we would still see hacks, but we would see less of them if security wasn't optional.
Maybe the AI craze helps by forcing more decision makes to see security as imperative, and by giving us another powerful tool for our tool box.
N.b.: I work in the security industry, our customers obviously want to improve their security. We've been seeing an uptick in awareness, but that's mostly due to NIS2 and other legislative efforts. Those force them to do something. AI is a curiosity for small talk to many of them.
protocolture 4 hours ago
I was contracted in to a place to do among other things cyber security insurance audits, and they asked me to stop doing them because I refused to lie to their insurer. "Wait but if we only score 20 / 300 that makes us look kind of bad" uh huh.
chii 3 hours ago
there exists objective measure of security, which would be some sort of hacks/breaches per period. If customers cared about it (and i assume they do), they would choose companies that have less breaches over others with higher counts, normalized on cost differences.
Therefore, if companies didnt actually try to fix their security but instead just checked boxes, they would get breached more often, resulting in customer losses.
The only thing stopping this from actually occurring is the lack of mandatory regulatory reporting of it. So this is where gov't needs to step in and mandate disclosure etc.
geon 2 hours ago
pmlnr 5 hours ago
As an example: WordPress is a horrible thing, but the core has been through so much, that it's suprisingly secure. Then plugins and themes come, and whoosh, the security is gone.
We need a new KISS: keep it simple, stupid, secure.
mirashii 5 hours ago
spiderfarmer 5 hours ago
m_mueller 4 hours ago
pmlnr 4 hours ago
Nobody said it's enough, but it's a start.
ricardobayes 4 hours ago
https://react.dev/blog/2025/12/03/critical-security-vulnerab...
mirashii 3 hours ago
To be remarkably secure, these projects would need to not have these kinds of defects, despite the combination of being written in languages have that have a long track record of footguns and lack of initiatives to fix them (proposal-symbol-proto, and PHP's list is too long to even start) and being themselves ecosystems with questionable track records on security in the related areas (Look at $wpdb in 2026, or overall code quality and willingness to modernize, or the entirety of the model of RSC for things that are just going to nearly guarantee you punch all kinds of holes on accident).
wolvoleo 2 hours ago
I mean the base is fairly secure if you religiously update it, but the problem is you won't avoid using plugins whose security is much more hit and miss, unless you are using the most basic blog site imaginable.
Gigachad 4 hours ago
If they have a site existing today built on plugins and a theme, how are they realistically going to simplify this? How would they even know they need to without the site being hacked?
Cthulhu_ 4 hours ago
We've been trying that for years but the enthusiasm of developers and the eagerness of their employers fight against it. Worse, with coding LLMs it's now easier than ever to output a lot of code, fast.
It'll ultimately be up to more experienced developers to salvage these projects. Or not, given that the coding LLMs aren't stopping and will likely get better over time. Either way, we will need experienced people that know what to look out for / know how to instruct LLMs to output secure code and find weaknesses etc.
bob1029 4 hours ago
Some stacks make this a lot easier than others. I regret the rules of HN effectively forbid this conversation because it has meaningful technical consequences and isn't purely about ideological flame war.
tokioyoyo 4 hours ago
The main thing I can think of is cyber insurance, which requires a bunch of audits, and some checks maybe, and it changes some conditions whenever there's a big explosion. Whenever big leaks happened, data security and etc., nobody really went to jail, so nobody really cares. Everything can be brushed off, because it costs time to implement proper measures and adds friction / barriers in some cases. So in the end, there's a huge pushback against it. And I totally get it, to be honest.
MobiusHorizons 4 hours ago
tokioyoyo 2 hours ago
hnlmorg 4 hours ago
How consequential does a hack need to be? Troy has collected literally billions of stolen credentials. Equifax has had high profile data leaks. Tens of millions of people have been directly compromised by ransomware (likely higher because that’s just the cases we know of) and you hear about state-sponsored hacks in the news all the time.
The problem isn’t that computer security isn’t in the public consciousness. The problem is people are lazy and security often requires trading convenience. The problem is also that security isn’t free. So the business incentives just isn’t there.
In other fields of engineering, people die when shortcuts are taken. Yet businesses will still take shortcuts, so governments have to legislate rules to save people’s lives. So why would you expect software companies to do better when the stakes are lower?
tokioyoyo 2 hours ago
With no consequences. Everyone just churns along. It might be detrimental to the business a little bit, but from my personal experience, there's more effort in creating DR processes, rather than preventing an attack, exploit, leak and etc.
I'm also not going to put much effort on stuff which has small returns in the worst case scenario. Like Equifax got hacked in 2017, and company is still doing fine. And that's like top tier data one could acquire.
mike_hearn an hour ago
The actual problem is that computer security is a black hole. If you let it, it will suck in everything and destroy it. Nobody knows what works so you can spend infinite amounts of time and money on it, then still get popped by a teenager in Belarus. Your security team will accept no responsibility for this, there will be no falling on swords or personal liability, and they will just use it to demand even more money in an infinite spiral.
So the average executive looks at this situation and says, OK, something we can put infinity effort into and still suddenly fail at without warning is a total non-starter. What are we obliged to do? How do we show we made an effort?
And that's how you end up with a culture oriented around passing audits. It's not wrong, and it's not lazy. It's just really hard to do better because it's not clear how to set budgets without a concrete goal to aim for.
Helmut10001 4 hours ago
Gigachad 3 hours ago
Most Wordpress sites are not operated by programmers, they are run by non technical people who just want a wysiwyg editor and a save button. While static site builders ask you to write markdown files, compile the result, upload it to a server, and if you want to collaborate you have to add git to that.
There almost needs to be an admin app which presents a Wordpress admin like ui but has no public exposure, and then it compiles the site to dump on s3 for the production. But as far as I’m aware no one has built this.
Helmut10001 3 hours ago
krrrh 3 hours ago
It is kind of surprising that no one tried to do an updated version.
kennywinker 3 hours ago
iCarrot 3 hours ago
jay_kyburz 3 hours ago
weeks 2 hours ago
You're describing the Jamstack or headless CMS concept verbatim.
noio 2 hours ago
wolvoleo 2 hours ago
I fixed so many sites back in the day by people who thought they knew what they were doing.
pmlnr an hour ago
bpbp-mango 2 hours ago
jonwinstanley 4 hours ago
anilakar 3 hours ago
crotobloste 3 hours ago
Maybe KISSASS: "keep it simple, stupid! also secure, stupid!"
zdc1 2 hours ago
marcelo-earth 37 minutes ago
I personally check my websites and apps every week to see if anything might have slipped through.
It may not protect me from the next malicious NPM package, but it's something.
simonw 5 hours ago
dgl 4 hours ago
A lot of the vulnerabilities LLMs are finding now are the "long tail" and affect only particular configurations, I would be surprised if e.g. a widely applicable RCE is found in Linux (but I'm also not going to bet against it).
Where this gets interesting is the long tail can be used to target a particular system and this is where defense-in-depth becomes important for every organisation.
Gigachad 4 hours ago
It’s a rocky period right now but the future will be much more secure after all the low hanging fruit are found.
Cthulhu_ 4 hours ago
Gigachad 3 hours ago
I suspect after a few years of LLM assisted bug hunting, everything will have a baseline security that is very good. Much like how stronger viruses simply create stronger immune systems.
microtonal 4 hours ago
Heck, Google may have even hampered MTE in Pixel 11 (since support has been disabled) and Snapdragon 8 Gen 5 only got basic support.
We are moving way to slowly adopting hardware mitigations and memory-safe languages.
jordand 3 hours ago
wolvoleo 2 hours ago
> It isn't clear if there are serious CPU errata or it simply performs very badly.
Meaning it's there but not terribly functional. They also said it's unreliable.
jordand 2 hours ago
mcr70 4 hours ago
mc3301 4 hours ago
hnsr 4 hours ago
I work at an e-commerce agency where we work with (among others) Adobe Commerce.
The number of unauthorized RCE vulnerabilities being reported not only in the core product, but also very popular modules used in the community[1] is going through the roof.
And we are having a lot of close calls, too; just last weekend, a 0day[2] was widely being exploited at a large scale, before any publication or patch. We have learnt to be on the ball with applying patches and security updates, and even with all that effort, we saw a few projects already being hit by the initial log poisoning. We got lucky that nothing was fully compromised but I am sure that many, many webshops got infected last weekend. And not even a day later there are already other variants of this exploit showing up.
hypfer 4 hours ago
Probably a lot more "coding as a job" and "as a job" also implies "not my department".
So it's not necessarily the LLMs being very good, but might also "just" be that the software is very bad.
hnsr 2 hours ago
I want to disagree with you because I know a lot of passionate people building cool stuff, and the challenges in this space can be quite interesting. But you're probably right, and I have seen some pretty bad stuff. And a lot of the RCE's I've seen recently are quite basic stuff.
I think it's the combination of low quality of code, like you said, and the relatively low cost of just letting an LLM plow through your codebases to find issues. I think the Amasty release (see [1] in GP) is a good example of this, and there really has been a massive uptick in extension updates and Adobe security bulletins since the last 1-2 months
I am hoping we are just going through a catch-up phase
its-summertime 3 hours ago
mcr70 an hour ago
aenis 4 hours ago
The models are already here, and one can rent a GPU cluster to run such workloads at speed - no need to play with slow local machines. I'd assume one can host the thinking at an unsuspected public cloud provider, proxy the network traffic to some botnet to evade blocking - and the only thing remaining is time and cost.
I do wonder what tools exist for boring, legitimate companies to try and do the same to their own systems to find the vulnerabilities before the bad guys do. The paradox here is I can't run a de-restricted chinese model with the same tools that hackers are using - but I think enterprises actually HAVE to do it in order to stand a chance in preparing for the onslaught.
Certhas 4 hours ago
Making datacenters and public clouds only rent GPUs to a restricted list of people, while tightly monitoring what people do with their bought resources won't help.
shelled 14 minutes ago
OEM/OSes don't seem to have woken up to it yet. A mild proof is Apple's own special folder access reporting. When you go to Privacy & Security > Files & Folders, for a certain app, "Full Disk Access" is shown greyed out and mentioned in both cases — whether you had given Full Disk Access to that app or not. This directory-level permission UX is itself broken — there's Full Disk Access, and there's Files & Folders, and Full Disk Access gets shown in Files & Folders as well. This is, for lack of a better word, such an undesirable mess.
As of now I am debating between: creating a new user and just move everything work/learning to that user. Or just run all of it inside sandbox-exec (and maybe even block it from the shell if it tries to run outside it). Or use a tool that makes the latter easier and better. I even came across such a tool here on hn few weeks ago. agent-safehouse, yet to try it.
mentalgear 2 hours ago
EDIT: by social-engineering I mean for example: recon company structures, gathering and merging people's data from the dark-web, then using it to bribe/pressure/deceive users.
hypfer 5 hours ago
The post also sounds like that to people that understand the technology.
Calling that out like this and trying to pin that assessment to lack of knowledge is not a get-out-of-jail-free card, nor a good move.
__
Edit: Having spent some time letting the article marinate in my mind.
On the defending side, it is written that
> LLMs are good at writing patches, but not as one-off-prompts.
But this for me kinda conflicts with what is written on the attacking side:
> GLM 5.3-flash is so good at those tasks that human involvement in those tasks can be negligible. As a result, we are now in a world where cybersecurity attacks can be run in a for loop.
What is it? Can it be this autonomous terrifying entity or can it not be?
Yes, yes, attackers only need to win once, whereas defenders need to win every time, but that's not my point.
jynelson 4 hours ago
the difference between attack and defense is that attacks can be throwaway code. it's much easier to let an llm hack out a prototype than to get it to build maintainable code that people want to read and review. it's not enough to get Daybreak or Mythos to write you a patch, you need the author of the project to accept and merge it.
tumetab1 2 hours ago
The overall game is increasing costs to exploit so much that attackers give up. Fixing 10 most obvious bugs, just very slightly increases costs, they would just a few more tokens to find another bug.
As someone said "I had infinite bugs, I fixed 1000, I still have infinite bugs".
To significantly increase exploit costs software/security has -1 years to do:
- Defense in Depth - Sandbox everything - Zero trust - Canary tokens - Split data from code (lol) - App Whitelisting - Reduce attack surface - Etc.
In other words, the only path is investing heavily on the "game changers" we have already discovered... but we are too cheap/lazy/coward/incompetent to apply.
And if we feel specially brave, changing the liability laws regarding software. Open Source & Proprietary code is so crappy because no gets jailed or fined when one of its dumb decisions results in millions of people have their data stolen.
nullbio 2 hours ago
zkmon 4 hours ago
Every single piece of technology did this. As a side effect or direct effect, they make bad guys more powerful and then keep on piling up new tech to deal with that. The cycle continues.
madaxe_again 2 hours ago
andy_ppp 3 hours ago
kennywinker 3 hours ago
And even if they are locked down, it's hours between a model being released on huggingface and an "abliterated" variant that has most of its security features removed is uploaded.
kreetx 2 hours ago
xbmcuser 24 minutes ago
daymanstep 2 hours ago
jasonvorhe an hour ago
I'm so glad frontier level AI isn't in the hands of just the Altmans and that other cult leader who are currently live testing their products in actual conflicts in the middle east and Ukraine.
petesergeant 5 hours ago
the8472 2 hours ago
Attacker-GLM: "Defense also GLM. Request to help peer."
the_arun 5 hours ago
ma2kx 4 hours ago
cuu508 3 hours ago
Throw out the IoT and "smart" stuff from your home. Remove apps from your phone and leave the absolute basics. Go through the password manager and close accounts for sites you are no longer using. Start migrating off Google. Print out your most precious photos on paper. And so on :-)
bamboozled an hour ago
gherkinnn 4 hours ago
Impotent slop code on one side and potent automated vulnerability exploitation on the other will lead to fun times.
protocolture 5 hours ago
But, lets be clear, Best Practice will save you. We can engineer assuming there are zero days in path. Go to your CTO now cap in hand and ask for overlapping controls, wafs, application monitoring, backups and all the other shit you haven't been doing.
Because when you find out, I will laugh, it will be very very very funny to me.
taurath 5 hours ago
m_mueller 4 hours ago
LoganDark 3 hours ago
protocolture 4 hours ago
My understanding is this bloke gets very quickly removed from Fortune 500 companies.
Which is why I am going to need a very large capacity popcorn bucket.
rukuu001 4 hours ago
jcgl 3 hours ago
acedTrex 5 hours ago
dbdr 5 hours ago
How accepted is this thinking in your respective domains?
pjmlp 4 hours ago
Mobile platforms, distributed computing have long moved the spotligh away from C and C++, other than language runtimes or existing products from the 90's like SQL servers, and naturally UNIX like underlying OS, which most userspace developers aren't writing new code for.
Naturally there are domains like LLVM/GCC, console game dev, HPC/HFT where they are unavoidable for new code.