llms write insecure code and then devs believe it isn't
6
can't the models just generate secure code?
7
secure software processes are very manual
8
limitations of our security programs today
9
what can scale with the robots?
10
- paved roads
11
- better runtime protection with rasp
12
- security tool copilot
13
codemodder: a modern, oss codemod library
14
thank you!
Description:
Explore the critical issue of code security in an era of AI-generated software through this thought-provoking conference talk from Conf42 DevOps 2024. Delve into the challenges posed by large language models producing insecure code and developers' misplaced trust in AI-generated solutions. Examine the limitations of current security programs and manual processes in keeping pace with rapidly evolving AI capabilities. Discover scalable solutions to address these concerns, including paved roads, enhanced runtime protection using RASP, and the concept of a security tool copilot. Learn about CodeModder, an open-source library for modern code modification. Gain valuable insights into securing the future of software development as AI becomes increasingly prevalent in coding practices.
Who Secures Our Code When an Army of Robots Is Writing It? - DevOps Security Challenges in AI-Driven Development