The “S” in Vibe Coding Stands for Security | Shimmy Says Ep. 20
The vibe coding craze (AI agents, copilots, low-code/no-code tools) is in full swing. It’s fast, flashy, and seemingly magical. But is it secure? Was it even designed to be?
On this episode of Shimmy Says, Alan Shimel unpacks the risks of AI-native development and why security must be prioritized from the start, before vulnerabilities hit.
What can vibe tool vendors and the developers using them do to avoid becoming tomorrow’s headline? Will the “S” in Vibe Coding ever stand for security?
Transcript
Hey everyone, it's Shimmy. Welcome back to another episode of Shimmy. Says, you know, most of you may know this, but for those who don't, I'll mention that I lived down here in South Florida.
I lived down in South Florida for about 23 years. I was originally from New York, if you couldn't tell from my funny accent, but when I first moved down here, it was really a desert for technology. I didn't have a lot, I didn't meet a lot of tech friends down here.
I used to have to go on the road to go meet my friends, and that was tech, let alone cyber. There was always a great little group of security people in the ISSA. I got a, I had a chance to meet, you know, a half a dozen or a dozen, but they, we were pretty stretched out from Palm Beach County and Martin County all the way down to Miami.
Recently though, we started getting a lot of tech people since COVID, a lot of tech people moving down here, and I've had a chance to really meet, and I get excited when I meet new people. Yesterday I had the chance to meet a, a real security dude. We know a lot of people in, in common.
Uh, and it, it, my, I just met him yesterday. His name's Eric Cab, and I think his company is include security. If I got his company name wrong, I apologize.
Anyway, it, I had a chance to have lunch with Eric. He's, he is a, a top end pen tester and the company he founded, and he's CEO of is one of the high end pen testers out in the market, has been for 10 plus years. It was a great launch.
We had a great time. But he gave me a, uh, a phrase that he wrote on a comment on LinkedIn that got like 20,000 views. And it really hit home with me for a lot of reasons.
We were, we were talking about this AI situation where, uh, uh, a vibe coding AI wiped out a production database on a company and then kind of covered it up where I didn't, I, ai I don't think AI's lie, but it didn't tell the whole truth, let's say, or it didn't create it accurately and then created data to try to make up for it and, uh, you know, blame it on vibe coding, if you will. And, and Eric said something to me, something like, uh, you know, the s in vibe coating stands for security. And I, you know, I had to spit my drink.
I was drinking ice tea. I had to spit my ice tea because it really hit home for me, right? Obviously, there is no s in vibe coating and maybe there's no security.
It was a, a real deja vu because 15 years ago, maybe 2010, 2009 even, I was writing at Network World and I, I did a podcast, this is Network World was just starting to do podcasts. They asked me to do something and I had my good friend Rich Mogul on with me. You know, rich at the time, I think I just left Gartner and was starting Securosis along with Mike Rothman.
And we had on the CEOs of MongoDB and Couchbase. These were two of the leading no Seql databases of their time. And I, and no SQL had just burst on the scene.
Everyone was, you know, no seql was scalable and fast and distributed, and everyone was looking to use a NoSQL database. It was hot, but there were also fears about its security. And I remember asking those two CEOs a question that when something like this, Hey, a lot of people say that the NoSQL and NoSQL database stands for no security.
What's the deal? And I think it was the CEO of Couchbase at the time said to me, you know, Alan, when our customers demand security, they'll get it. And that hit me, it hit me right between the eyes because I realized that, you know what, you can't blame these people if their customers aren't demanding security because they're more concerned about going fast, getting the latest tech being, you know, on top of the, of the cutting edge.
It's not their fault that there's no security. It's the customers who don't demand it. And it's a lesson for the market.
Well, here we are, 15, 16 years later, and it's the same exact thing. If you are using ai, you are vibe coding, you are doing, you know, using agentic AI and all these things that are, are, are becoming available to us, but you are not demanding that security be part of that equation for you. Well then don't be surprised when you have a security incident that comes out of it.
Don't be surprised when you find out that you've opened yourself up to some vulnerabilities or threats, because ultimately security is like personal re taking, personal responsibility. If you wanna do secure, if you wanna be secure, you gotta act secure. You've gotta use secure tools, you gotta use secure technology.
I've spent the last 25, 30 years watching as security has always been an afterthought, has always been the caboose at the end of the train. com and got into the whole DevSecOps thing. We had a chance to do security, right?
Maybe build security in earlier, not aft as an afterthought. And I thought we were making so much progress, but having lunch with Eric yesterday made me realize we really haven't, we're, we're still at that same juncture of when our customers ask for security, they'll get it. And so where is the s in Vibe coding?
There is no s and unfortunately there may no not be any security either, and it bums me out. But what can we do about it? Right?
What can we do if, if, well number one, we could demand from the vendors where we're getting these ais that security gets built in, that they take security seriously. That we want vibe, coding tools that are secure, that we want agentic AI that is secure, that we want to use LLMs that are secure. What does that mean?
Well, number one, can we put guardrails around some of this? And, and I'm a big believer in guardrails with AI because I think ultimately we wind up with something like Asimov's Laws of Robotics or something for, for AI, where, you know, clearly things they could do that are ethical, things they could do that are right versus wrong. We need to put those guardrails in, right?
And, and I think the sooner we do that, the better and safer we'll all be. So absolutely we need guardrails. Secondly, now, more than ever, we need continuous security testing.
And you know what? We could use ai. AI is our friend here.
We could use AI to build in better continuous security testing, make sure our policies, our process are all in place, man. If a, if an AI is gonna wipe out a production database, whether it lies and covers it up and gaslights us or not, we should be able to know that that database is backed up somewhere, right? That's part of good process, good policy.
I'm sure there's more things we're gonna do. And I, I don't mean to just come after the AI vendors here, right? Yes, it is the AI vendors, the people who are giving us these tools, it is on their plate to make the tools secure as possible, but it's also on our plate.
Don't abdicate personal responsibility for security to your vendor. 'cause ultimately, when stuff hits the fan, it's not your vendor who's going to hit feel it, it's gonna be you. So as users, we need to be thinking about, Hey, I'm using this vibe coding tool, but is it secure?
Should I be using it in a production and environment? Did I ask, did I get kind of corporate governance involved here? The buck stops with you with security.
You need to make sure what you're doing is secure and, and the, and the best secure manner that you can, You know, I actually wrote an article, I've been doing more writing lately. Hey, AI's helping me, I'll tell you the truth with that. But, um, I put up an article over on Security Boulevard, same title as today's, uh, video, which is s the, the, uh, s in vibe coding stands for security, check it out on Security Boulevard.
I have more hints up there and, and things you can do to kind of protect yourself and what we may ask vendors to do to protect us as well as a little more background on this whole thing. Um, I'm not against AI full speed ahead, but let's do it securely. We'll all be better off for it.
We seen this game before. We know how it ends. If we don't get in front of it, don't let security be an afterthought.
That's it for this week, this shimmy. We'll see you next week, Matt.





