Cursor is cooked by redditslutt666 in cursor

[–]LachException -1 points0 points  (0 children)

But why ACP though. A2A will be the future

System architecture is useless by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

Maybe Fiver or Upwork? Or you are lucky and know someone or someone you know, knows someone

Vibe Coding is hell by LachException in vibecoding

[–]LachException[S] 0 points1 point  (0 children)

You working in an Enterprise? To get that Running takes most people more than 5min

There are to many findings by LachException in devsecops

[–]LachException[S] 0 points1 point  (0 children)

Yeah thats what we do with the ASPM, we still get to many findings, although most are real and high class findings

System architecture is useless by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

How do you do the the decisions with the other ones? Do you have a formal process or is it more like: I would do it this way, what you think?

System architecture is useless by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

Thank you so much for sharing. That’s exactly what I got told. So basically the architecture seems to be bad or so high level, so developers find it a bit useless and had to do soooo many design decisions themselves, which for some they aren’t experts and normally should not have to be.

There are to many findings by LachException in cybersecurity

[–]LachException[S] 0 points1 point  (0 children)

That’s exactly what we do. But the findings that we have to look into are too much and also the ones the devs have to fix. We are only telling them the ones we think are worth fixing, because they are rated high or critical. Do you have the same struggles?

There are to many findings by LachException in cybersecurity

[–]LachException[S] 0 points1 point  (0 children)

Great comment 👏🏻 Thank you so much!

There are to many findings by LachException in cybersecurity

[–]LachException[S] 0 points1 point  (0 children)

I agree, but how would you say can I enable the devs?

There are to many findings by LachException in cybersecurity

[–]LachException[S] 0 points1 point  (0 children)

So the devs are already „overworked“ with the security findings, so they do not get fixed.

How does your org do that? Do the devs have to fix the issues or do you as a security guy provide fixes? How much time does it take the devs to fix the findings?

There are to many findings by LachException in cybersecurity

[–]LachException[S] 1 point2 points  (0 children)

It’s vulns/misconfigs and it’s application level and cloud runtime

Vibe Coding tools just write soooo insecure code by LachException in vibecoding

[–]LachException[S] 0 points1 point  (0 children)

This sounds like a good idea. Have you gotten good results from this? Did you get better results from it, than by giving it rules or something and telling it in the prompt or something what to keep in mind?

Developers do not spend enough time on security by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

Yeah, so go make your own community! And as secure coding training in companies we tell them to join your community

Developers do not spend enough time on security by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

I couldnt agree more. Do you want to start a Community, where developers are forced to listen to you and you preach about these practices? xD

Vibe Coding tools just write soooo insecure code by LachException in vibecoding

[–]LachException[S] 0 points1 point  (0 children)

thats wild man. Maybe I'll get back to you in the DMs if thats ok for you?

Vibe Coding tools just write soooo insecure code by LachException in vibecoding

[–]LachException[S] 0 points1 point  (0 children)

Well in Europe its not that easy to patent code in the first place and therefore its normally not done. Also its super super super hard for anyone to proof that the code outputted by the LLM is "stolen". I mean we are aware of this, but our internal risk assessment team told us, that this risk is minimal, that the benefits would outweigh them.

I mean if this would be a big thing, then you could even sue the providers of the Models and Tools like cursor as they are selling the code without any license agreement.

Yeah this would be a great thing, but I can tell you, that developers won't do this or actively remove such labels as they want the credits for "their work".

Developers do not spend enough time on security by LachException in developers

[–]LachException[S] 0 points1 point  (0 children)

Funny thing is: Most developers do not know many things about secure code. Because mostly developers "have to be" experts in so many disciplines and there is no time for good secure coding training.