Discussion about this post

User's avatar
Amit Spitzer's avatar

The root cause math here only holds if the codebase converges on shared implementations you can point a fix at. That was true of n8n and GitLab's five years of human written history. It gets a lot shakier once 100 PRs a day come out of agents that don't reuse the same auth helper twice, you can end up with the same vulnerability class expressed five different ways with no common commit to trace back to. I saw a version of this at What Breaks recently with MLflow, the patch closed the specific reported path but left the exploit's underlying pattern sitting right next to it, still working five years later. The diligence question for a vendor selling root cause elimination is whether they catch a class showing up as independently written variations, not just literal duplicates and backports.

richardstevenhack's avatar

"an idea that CISA has been advocating for years through Secure-by-Design, which urges software producers to “eliminate common vulnerability classes and publish roadmaps for the rest.”

DUH. As I've been saying for at least twenty years.

AI-assisted design (by AI other than LLMs which are unreliable and insecure by definition) and deterministic-AI-generated code has always been the solution the industry will never do because it "offends" nerd programmers who think they're the cat's meow, despite being as unreliable and insecure as LLMs - as the LLM vulnerability discoveries are now proving.

No posts

Ready for more?