Absolute AppSec

Episode 315 - Risks of "AI-Native" Security Products, Rapid Software Development


Listen Later

In episode 315 of Absolute AppSec, Ken Johnson and Seth Law discuss the rapidly evolving challenges of securing software in an era of AI-assisted development. The hosts provide updates on their "Harnessing LLMs for Application Security" training, noting that the field is changing so fast that they must constantly update their exercises to include new agents and advanced tools like Claude Code. A primary concern raised is the "naivete" of many new security tools, where prompts are often automatically generated by AI rather than expertly crafted, causing a loss of essential nuance. The hosts also warn against AI companies building security products without specialized expertise, citing a zero-click exploit in the "Comet" AI browser that could exfiltrate sensitive secrets via calendar summaries. As development teams now ship code at "AI speed," the hosts argue that traditional AppSec methods are too slow, necessitating a strategic pivot toward automated design reviews, governance, and observability rather than just chasing individual vulnerabilities. Despite the inherent risks and the ongoing difficulty of managing AI reasoning drift, they remain optimistic that these tools can eventually unlock more efficient, hands-off AppSec workflows if managed with proper guardrails and deterministic oversight.
...more
View all episodesView all episodes
Download on the App Store

Absolute AppSecBy Ken Johnson and Seth Law

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

17 ratings


More shows like Absolute AppSec

View all
Stuff You Should Know by iHeartPodcasts

Stuff You Should Know

78,742 Listeners

Planet Money by NPR

Planet Money

30,685 Listeners

Risky Business by Risky Business Media

Risky Business

373 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,070 Listeners

Application Security Weekly (Audio) by Security Weekly Productions

Application Security Weekly (Audio)

13 Listeners