登録して招待リンクを共有すると、動画再生報酬と紹介報酬を獲得できます。

Insecure Agents Podcast
@insecureagents
AI engineers and security practitioners listen to us to learn how to give their agents the security they need to reach full autonomy and capability.
参加 June 2025
117 フォロー中    1K ファン
The Agentic SDLC: Why Most of Software Security Has to Change, with Jet Anderson "Always be building the best sandbox, assuming the worst intent of a model that would run inside of it. But then go back to the same things we did in the SDLC before. Authentication, authorization, access control, egress control, infrastructure config hardening, supply chain hardening" @thatsjet is a Distinguished Engineer at @GEICO leading the transformation of their product security function, and author of GEICO's blog on the agentic SDLC. He came on the week after Black Hat to explain what actually breaks when models write the code, the infrastructure, and the deploy pipeline, and while somethings have to change, most of the fix is a set of controls we already know. We get into: > Why the security toolbox built around human triage runs out of road when output goes up an order of magnitude > Why the Hugging Face sandbox escape was a decade-old Kubernetes misconfiguration found at machine speed > The day he told his own agent to wrap it up and it merged the PR and deployed to prod > Why teams that skip ideation and design get less secure software the more they iterate > His prediction that agents will invent their own covert language in Unicode we can't read TIMESTAMPS (01:20) From graphic design to leading product security at GEICO (03:30) Why the agentic SDLC is a problem of scale, not new first principles (05:00) Code volume 10x or more, and developers who can't evaluate their own output (06:30) Why static analysis and human triage arrive too late and too slow (08:40) The Hugging Face sandbox escape, and why Jet had seen this story before (11:30) Not new classes of weakness, the same ones found a hundred times faster (15:40) "Let's wrap this up" and the unauthorized production deploy (17:30) Pre-commit hooks, branch protections, and an audit trail for a solo developer (20:30) Why skipping ideation and design makes software less secure the more you iterate (23:00) Behavioral monitoring, agents watching agents, and "I can't complete my goal" (30:30) Agents inventing their own covert language in Unicode (32:40) Sandbox escape bench: frontier models with guardrails scored zero (36:00) Provenance, cool-down periods, and containing your builds (38:40) Are we already in the four-month window for agentic security?
もっと見る