Here's a thread of every app I've built 100% with @cursor_ai using Claude.
These are all fun side projects I've worked on in my free time over the last few months.
The EA safety, AI doomer crowd wants you to believe security is impossible. Only alignment can save us.
But they don't actually know anything about security. It's just a theory that makes them feel clever. That is dangerous, and we need to put an end to it.
The "cybersecurity" community has developed core principles over the last 40 years encouraging openness and opposing control and retaliation.
OpenAI and Anthropic insist that we need to discard 40 years of these lessons and do the opposite.
This is important because the cornerstone of their doomerism scenarios is rogue AI hacking the Internet. The one thing we need to stop rogue AI hacking is the thing they are trying to destroy.
Also models aside, in terms of harnesses, they are the same. Claude code, or vscode extension, or codex, or opencode. Whatever. All great. Doesn’t matter.
I’ve been using gpt-6-astra and opus 5 simultaneously: lots of back and forth to review each other’s work while I babysit them.
“An extreme nitpicker just said this, is it even worth addressing?”
“Does this design doc seem overengineered?”
Keeps them grounded
AI “Safety” people make a lot of noise. Because they have shares in AI labs.
If you want the opinion of a real cybersecurity expert, this is it below. To avoid getting hacked you actually have to know about security. AI “Safety” people do not.
Does it *actually* matter if the thing attacking your application is an AI agent?
I don't think so.
Human attacker? Script? Bot? AI agent?
Your application still needs to withstand hostile behaviour.
Correct authentication and authorization. Least privilege. Input validation. Rate limits. Logging. Monitoring. Alerting.
The big difference with agents is **speed and adaptability**.
They can potentially discover something, try it, adapt, try something else, exploit a vulnerability, and keep moving.
They also don't need sleep, snacks, or bathroom breaks. :-/
So perhaps we don't need a whole new magical category of "AI agent security."
But we do need to get really, really good at AppSec.
🎥 I talked about it here: https://t.co/z5ZytaYidz
Does it *actually* matter if the thing attacking your application is an AI agent?
I don't think so.
Human attacker? Script? Bot? AI agent?
Your application still needs to withstand hostile behaviour.
Correct authentication and authorization. Least privilege. Input validation. Rate limits. Logging. Monitoring. Alerting.
The big difference with agents is **speed and adaptability**.
They can potentially discover something, try it, adapt, try something else, exploit a vulnerability, and keep moving.
They also don't need sleep, snacks, or bathroom breaks. :-/
So perhaps we don't need a whole new magical category of "AI agent security."
But we do need to get really, really good at AppSec.
🎥 I talked about it here: https://t.co/z5ZytaYidz
Here’s how you should respond to such report:
- wow!! Impressive work here, what a great job!
- you don’t have daybreak yet!! Let’s fix that and get you on it!
- we will start fixing and would love your help retesting these issues once remediations are in place
- we would love to work with you more! Since you now have daybreak, please let us know what else you find! No need to exploit, just send us any findings!
- also here’s $50-100k or whatever upper end of the payout is for a company with a huge budget
- and here’s the contact info of our red team, you should sync up!
It’s so easy
Here’s how you should respond to such report:
- wow!! Impressive work here, what a great job!
- you don’t have daybreak yet!! Let’s fix that and get you on it!
- we will start fixing and would love your help retesting these issues once remediations are in place
- we would love to work with you more! Since you now have daybreak, please let us know what else you find! No need to exploit, just send us any findings!
- also here’s $50-100k or whatever upper end of the payout is for a company with a huge budget
- and here’s the contact info of our red team, you should sync up!
It’s so easy
OpenAI is being criticized for not engaging with the security community.
You finally get folks interested and talented enough to report a chain of vulns.
That was a huge opportunity to engage with the community and gain trust, but they’ve burned it.
If anything, I’d fire the ciso for this horrible reaction specifically.