Read this before you vibe-code another app | The Verge
theverge.com · 2,105 words · saved by 1 readers
Your dream vibe-coded app might be a security nightmare.
Bob Starr was delighted with his vibe-coded website. “Boomberg” showed how much US tax money is going to tech companies, and Starr launched it online immediately after making it. It wasn’t until months after the site went live that he realized there was a problem: a hidden SQL injection risk. It could’ve left the site open for an attacker to read or alter data they shouldn’t have access to. “It was just a glaring oversight on my part. It was a complete blindspot in my state of learning this new technology and understanding it, and I’m sure there are others making the same mistake,” said…
saved by
related reading
- Vibe coding - Wikipediaen.wikipedia.org
- Not all AI-assisted programming is vibe coding (but vibe coding rocks)simonwillison.net
- Vibe Coding Cheatsheet - by John Damaskjohndamask.substack.com
- Dario Amodei, hype, AI safety, and the explosion of vibe-coded AI disastersgarymarcus.substack.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- The vibe coder's career path is doomedblog.florianherrengt.com
- davidbau.com Vibe Codingdavidbau.com
- Vibe Coding: Empowering and Imprisoning - Anil Dashanildash.com
- Vulnerability Research Is Cooked - Quarrelsomesockpuppet.org
- How to Vibe Code as a Senior Engineerblog.alexmaccaw.com
- Security incident disclosure — July 2026huggingface.co
- Vibe engineeringsimonwillison.net