Making frontier cybersecurity capabilities available to defenders

https://www.anthropic.com/news/claude-code-security

Making frontier cybersecurity capabilities available to defenders

Claude Code Security is one step towards our goal of more secure codebases and a higher security baseline across the industry.

As a founder of an auditing firm, I definitely feel the heat of the competition when big LLM companies push products that not only compete with us an auditors but also with our own AI-based offerings (https://zkao.io/).

If I were to venture a guess, there's different world in which we might exist in the next 5-10 years.

In one of these futures, we, as auditors, seize to exist. If this is the future, then developers seize to exist too, and most people touching software seize to exist. My guess here is as good as any developer's guess on if their job will remain stable.

In another one of these futures, us auditors become more specialized, more niche, and bring the "human touch" needed or required. Serious companies will want to continue working with some humans, and delegating security to "someone". That someone could be embedded in the company, or they could be a SaaS+human-support system like zkao.

On the other hand, vibe coders will definitely use claude code security, maybe we should call it "vibe security"? I don't mean it as a diss, I vibe code myself, but it will most likely be as good as vibe coding in the sense that you might have to spend time understanding it, it might make a lot of mistakes, and it will be "good enough" for a lot of usecases.

I think that world is a bit more realistic today, than the AGI "all of our jobs are gone in the next years" doom claim. And as
@zksecurityXYZ
, I don't think we're too scared of that world.

These tools have been, and are making us stronger auditors. We're a small, highly specialized team, that's resilient and hard to replace. On the other hand large consultancies and especially consultancies that focus on low hanging fruits like web security and smart contracts are ngmi.

zkao - AI Bug Detection for Circom

Find bugs in your Circom code with AI-powered analysis

Developers will not cease to exist. The developers of tomorrow will simply being doing things that developers today can’t possibly even imagine.

Auditors though, they are cooked.

>Auditors though, they are cooked.

I think you're massively underestimating the complexity and depth of a good security audit service.

I don't.
God bless you, the beautiful thing about computer security is that this attitude has kept us happily in business for many years.
Say more? It's really hard to navigate the antecedents of this argument.

People who don't do intense security work for a living underestimate the complexity of it. This might find some vulnerabilities, but it's not really capable of producing new methods and attacks. What it replaces isn't a high quality human researcher; it replaces current static code review systems.

If AI models never had stack smashing writeups in their corpus, they'd never be able to invent stack smashing.

So, by any reasonable measure, I've spent a career doing "intense security work", with a particular focus in vulnerability research, and I do not agree with this at all.