Marketing can open Claude Code on a random Tuesday and ship a full app by afternoon. No security review, no auth, sometimes not even a clue it just bypassed the API gateway entirely. Cameron and Kurt spend most of this episode on citizen development, and Cameron goes on record hating the term from the jump.
They get into why blanket approval processes fall apart the second you compare a read-only dashboard to something touching customer PII, why t-shirt sizing risk by data sensitivity actually works, and why "I told it to make it secure" is the most dangerous sentence in ProdSec right now. Also covered, the AppSec team getting blamed for wanting guardrails in the pipeline, the paved-way argument that closes the episode out, and an actual disagreement about whether security is a feeling.
Before all that, a quick hit on the near-autonomous AI attack that cracked 85 government accounts in four days, because the two problems are more connected than they look.
If you've ever heard "I didn't know it did that" from someone who just vibe coded their way past every control you built, this one's for you.
☕ New episodes every Wednesday.
Coffee, Chaos and ProdSec -> strong coffee, stronger opinions.
Podden och tillhörande omslagsbild på den här sidan tillhör
Cameron Walters and Kurt Hendle. Innehållet i podden är skapat av Cameron Walters and Kurt Hendle och inte av,
eller tillsammans med, Poddtoppen.