Logo Oficial MASTR MASTR
Menú
Leer la publicación

Métodos de investigación

AI-assisted development and the need to inspect the result

software built with the latest and best AI models can be more secure than software written by developers.

Original en X ↗

Las publicaciones originales están en inglés. La navegación está disponible en siete idiomas.

01

Original en X ↗

Unpopular opinion:

software built with the latest and best AI models can be more secure than software written by developers.

I’ve seen this several times over the past few weeks.

But that doesn’t mean someone with no technical understanding can use these models to build something secure: Some vibe-coded stuff is downright horrifying.

You still need the knowledge to evaluate the code, recognise its weaknesses and verify that the protections actually work.

That said, I’m considering taking a much harder line with teams that ignore documented security findings, including authorised white-hat demonstrations that make the impact impossible to dismiss.

If a detailed report isn’t enough, a controlled demonstration may teach them the lesson they keep refusing to learn.

My patience with teams that market financial products while ignoring the holes in their own code is running out.

They cannot keep expecting free research and indefinite silence while their users carry the risk.

They cannot keep launching financial apps and advertising bug bounty programmes for credibility, then ignore documented vulnerabilities when someone actually does the work.

If they want the reputation that comes with taking security seriously, they can start by taking the findings seriously.

I’m sick of greedy liars collecting the revenue and fees while users absorb the consequences of their negligence.

We see where that leads every fucking day.

Investigaciones relacionadas

Métodos de investigación

What doing your own research requires

A discussion of independent checks, source quality and the responsibilities hidden inside the phrase DYOR.

Artículos originales3 min
Métodos de investigación

Evaluating a newly launched token

A practical starting point for reviewing the identity, distribution and risks of a new token.

Artículos originales3 min
Métodos de investigación

AI: decentralisation and control · 12 Sep 2026

When an American CEO (here Dario Amodei, Anthropic) is willing to warn the world about the very technology his company is banking on to bring in billions, you start to wonder how close to midnight we really are.

Comentarios y desahogos1 min
MASTR

Apoya la investigación independiente

Las investigaciones, las pruebas originales y las guías son de acceso libre. Las donaciones voluntarias ayudan a financiar la investigación y a mantener disponibles las herramientas de MASTR.

Abrir billetera