00:00:00.800 --> 00:00:03.040
Let's talk about vibe coding for a second.
00:00:03.680 --> 00:00:04.879
You know the feeling.
00:00:05.440 --> 00:00:12.400
The code is flowing, the tests are passing, you and your AI assistant are on a roll.
00:00:12.720 --> 00:00:20.800
And then six weeks later, you're staring at the code thinking, why did we do it that way?
00:00:21.440 --> 00:00:27.120
That feeling that you are feeling, that's called security drift.
00:00:27.600 --> 00:00:31.359
Hi, I'm Tanya Jenka, also known as SheHacksPurple.
00:00:31.600 --> 00:00:38.560
Welcome to DevSecStation, a podcast for software developers who want to build more secure software.
00:00:38.799 --> 00:00:48.880
In each episode, I'll share a short practical lesson about secure coding, software security, and how to build safer systems without slowing development down.
00:00:49.039 --> 00:00:52.799
You can jump in at any episode, at any time.
00:00:53.119 --> 00:00:54.960
No homework required.
00:00:55.759 --> 00:00:58.399
This episode is sponsored by MAISE.
00:00:58.799 --> 00:01:08.959
One of the biggest problems in security right now is that every vulnerability or cloud scanner says everything is critical, and honestly, no one has time for that.
00:01:09.200 --> 00:01:20.560
MAZES uses AI agents to investigate vulnerabilities in context, so you can focus on the issues that are actually exploitable in your environment and not just theoretically scary.
00:01:20.879 --> 00:01:32.319
Their AI agents also generate and prioritize fixes that knock out multiple vulnerabilities at once, which is honestly the kind of scaling that security teams really need right now.
00:01:32.560 --> 00:01:37.760
Learn more about maze at mazehq.com slash devsec.
00:01:38.400 --> 00:01:47.680
If you use Copilot, ChatGPT, Cursor, or any AI-powered coding assistant, even occasionally, this episode is for you.
00:01:48.159 --> 00:01:54.879
I want to pause for a second and define what I mean by security drift because clarity is kindness and important.
00:01:55.519 --> 00:02:07.120
Security drift is when software keeps functioning, but the security assumptions it was built on slowly change, without anyone explicitly choosing to change them.
00:02:07.359 --> 00:02:15.919
So the code still works, nothing's actually obviously broken, but the protections that you thought were there aren't quite the same anymore.
00:02:16.159 --> 00:02:20.639
And this doesn't come from bad decisions, this comes from convenience.
00:02:20.960 --> 00:02:28.400
AI assistants are very good at helping you move fast, but they are terrible at knowing your threat model.
00:02:29.120 --> 00:02:36.240
They optimize for what compiles, what looks idiomatic, and what they've seen before.
00:02:36.479 --> 00:02:43.280
They do not optimize for your environment, your data sensitivity, or your risk tolerance.
00:02:43.680 --> 00:02:46.800
Essentially, they don't have any context.
00:02:46.960 --> 00:02:51.039
And that's a very normal scenario where this can happen.
00:02:51.280 --> 00:02:56.400
So imagine this: you ask your assistant to generate a helper function.
00:02:56.639 --> 00:02:58.240
It gives you something that works.
00:02:58.479 --> 00:02:59.120
Great.
00:02:59.360 --> 00:03:04.879
Later, you ask it to extend that logic and it copies a pattern from earlier.
00:03:05.120 --> 00:03:12.319
Then someone else asks it to refactor a file and it removes a check because it looks like it's redundant.
00:03:13.360 --> 00:03:16.639
No one made a conscious decision to weaken security.
00:03:16.960 --> 00:03:19.039
It just drifted.
00:03:19.360 --> 00:03:28.960
The code still works, the tests still pass, but the authentication logic is just a little bit thinner, the validation is just a little bit looser.
00:03:29.120 --> 00:03:32.159
Maybe some of the logging disappeared.
00:03:32.719 --> 00:03:38.319
This is not necessarily an AI problem, but it is definitely a workflow problem.
00:03:39.680 --> 00:03:41.199
How do we avoid this?
00:03:41.439 --> 00:03:49.520
The bad, but unfortunately, very common approach that I see is treating AI-generated code as correct by default.
00:03:49.759 --> 00:03:52.400
It looks clean, it compiles, it feels professional.
00:03:52.560 --> 00:03:53.840
I'm sure it's good.
00:03:54.240 --> 00:03:57.759
But AI is extremely confident even when it's wrong.
00:03:58.000 --> 00:04:01.280
And confidence does not ensure security.
00:04:01.680 --> 00:04:08.159
A better approach is reviewing AI-generated code the same way you'd review code from a teammate.
00:04:08.319 --> 00:04:09.520
And this helps.
00:04:09.680 --> 00:04:16.240
But it still assumes that reviewers remember to look for security issues every time while they're trying to move fast.
00:04:16.399 --> 00:04:19.199
And this is where drift could potentially sneak in.
00:04:19.439 --> 00:04:26.959
The best approach is not reviewing harder, it's constraining the patterns AI is allowed to introduce.
00:04:27.279 --> 00:04:37.279
So what I mean by that is you explicitly decide which security-sensitive patterns are acceptable and you make everything else harder for it to use.
00:04:37.519 --> 00:04:42.079
In practice, this looks like a few very specific things.
00:04:42.560 --> 00:04:51.839
So you keep one or two known good examples of how your team does authentication, authorization, validation, or secret handling.
00:04:52.079 --> 00:04:59.439
You treat those examples as the source of truth and you expect the AI-generated code to always match them.
00:04:59.680 --> 00:05:02.800
If the code does not match, it does not get merged.
00:05:02.959 --> 00:05:06.319
Not because it's bad, but it's inconsistent.
00:05:06.560 --> 00:05:10.480
And wherever possible, you back all this up with automation.
00:05:10.879 --> 00:05:17.839
So feed all of those good examples into a reg server or add it to your prompts that you work with every day.
00:05:18.160 --> 00:05:27.680
Then you add on top of that tests, linters, or static analysis that double-check those patterns so humans don't have to remember them every single time.
00:05:28.000 --> 00:05:36.319
When AI is forced to stay inside a known pattern, it stops making security decisions on your behalf that you're not necessarily aware of.
00:05:36.480 --> 00:05:40.720
And that's how we get speed without getting security drift.
00:05:41.120 --> 00:05:45.120
If you do just one thing after this episode, please do this.
00:05:45.360 --> 00:05:50.319
Pick one place where AI writes code for you and add a guardrail.
00:05:50.560 --> 00:05:52.959
There's a manageable way that you can do this.
00:05:53.199 --> 00:05:56.959
Step one, identify where AI shows up in your workflows.
00:05:57.040 --> 00:06:02.160
Is it generating functions, tests, configurations, infrastructure as code?
00:06:02.399 --> 00:06:03.519
Whatever it's doing.
00:06:03.759 --> 00:06:08.000
Step two, pick one security-sensitive area.
00:06:08.319 --> 00:06:16.000
Authentication, authorization, input validation, secret handling sensitive data, your choice.
00:06:16.319 --> 00:06:19.040
Step three, make a rule.
00:06:19.360 --> 00:06:25.199
AI can suggest code here, but it must be reviewed against a known secure pattern.
00:06:25.759 --> 00:06:35.839
So this could be an internal code example, a checklist item in your PR template, or a simple comment such as, was this written by an AI?
00:06:36.000 --> 00:06:39.920
If yes, was security explicitly reviewed?
00:06:40.240 --> 00:06:43.839
Step four, if you can, automate all of it.
00:06:44.079 --> 00:06:51.680
Use a reg server, prompts, lint rules, tests, static analysis, anything that can help you catch drift.
00:06:51.920 --> 00:06:55.439
And just to be clear, we are not banning AI.
00:06:55.920 --> 00:07:01.279
We are protecting the security assumptions that your system depends on every day.
00:07:01.600 --> 00:07:03.120
Vibcoding's not bad.
00:07:04.879 --> 00:07:13.839
But speed without boundaries allows for subtle, quiet, unnoticeable changes that aren't always good.
00:07:14.160 --> 00:07:19.040
When you add secure guardrails, you keep the speed and the security.
00:07:19.199 --> 00:07:23.040
That's not us slowing down, that's us maturing.
00:07:23.439 --> 00:07:26.079
Thanks for listening to DevSecStation.
00:07:26.319 --> 00:07:31.680
If you enjoyed this episode, please subscribe, share it with a friend, or leave a review.
00:07:31.839 --> 00:07:34.240
It helps more people discover the show.
00:07:34.560 --> 00:07:39.439
If you'd like to learn more, I'm Tanya Jenka, also known as SheHacksPurple.
00:07:39.680 --> 00:07:43.360
And I teach secure coding training for software developers.
00:07:43.600 --> 00:07:46.800
You can find me online at shehackspurple.ca.
00:07:47.519 --> 00:07:49.360
Thank you for being here.