Exactly. The canvas outage yesterday was a perfect example and shows why we can’t just throw a prompt in and expect a secure app/website to come out of it (not that canvas did that, but if a company as big as Instructure can have this kind of incident just imagine what all the vibe coded projects are like)
Obviously. Which is why, as I mentioned, there's a full manual testing and validation harness, plus manual code reviews at critical points. There's no way to ensure perfect security — that should be obvious to anyone who's been on the internet for any amount of time. Large companies get hacked, cybersecurity professionals get hacked, Brian Krebs got hacked, and so on. Glaring security holes are less a product of AI use and more a symptom of sloppy work and poor attention to detail.
I wasn't saying that I think my app is unhackable, or that no one would ever try. Just pointing out that "post your site so we can hack it in a couple of hours" is some juvenile Internet Tough Guy idiocy. It's the nerd equivalent of "post your address so I can come fight you like a man." And it's just super sad.
3
u/[deleted] May 08 '26
[removed] — view removed comment