Secure code requires that you take security into consideration while designing and writing the code. Then you go back and review the code for anything you missed, then have a second set of eyes do the same. With ChatGPT you basically just end up playing the free edition of bug bounty whack-a-mole but with your own software.
Conversation
Notices
-
Marcus Hutchins :verified: (malwaretech@infosec.exchange)'s status on Saturday, 18-Mar-2023 03:32:27 JST Marcus Hutchins :verified: -
Marcus Hutchins :verified: (malwaretech@infosec.exchange)'s status on Saturday, 18-Mar-2023 03:32:28 JST Marcus Hutchins :verified: I'm all for making programming easier, but the problem with using ChatGPT to write code is that it doesn't write secure code by default. It lowers the bar to writing code, but raises the bar for securing code because users basically have to manually review code they didn't write.
Adrian Cochrane repeated this.
-