Reading view

Half our dev time now goes into security. Some thoughts on open source’s future.

I develop and maintain infrastructure for thousands of agencies for a living and honestly, the last few months have been draining.

Since roughly April, about half of our dev time has gone into security. Hardening, audits, reviewing input handling, capability checks, dependencies. Rinse and repeat, because of new AI-driven attacks we need to stay ahead of.

Maybe an unpopular opinion, but I don’t think this will last. The same AI models they use to find holes in our code are the ones we turbocharged and use to check our code before we release it. They scan, we scan first. There are only so many types of security bugs, and once a codebase has been tested and fixed like this for a few months, there’s not much left to find.

And when that happens, I think open source will come out of this in really good shape. Code that has been attacked from every direction and survived is code you can actually trust.

My bet is that within a few months, “it’s open source” becomes a reason to trust software instead of a reason to worry, and people will realize it.

Right now though, it’s just tiring.

Anyone else? Or is it just me?

submitted by /u/Aurelio_Umbrella
[link] [comments]
  •  
❌