It seems the <sarcasm> tag was missing, I assume, but as shown by many companies and open source projects, agents with the right prompts are much better at finding security problems than 99% of developers (for various reasons).
> but as shown by many companies
… but as shown by many shovel sellers… their shovel…
Here I fixed it.
Sometimes it's easier to start with doing the right thing than to just try to fix problems later.
Many devoted fans of AI like comparing LLMs to compilers for higher-level programming languages.
They argue that just as programmers once wrote ASM and C, the arrival of Java and Python meant you no longer had to be a neckbearded autistic kid to write software that doesn't leak memory or segfault.
Arguments like this show me you’ve never done software engineering seriously.
Despite compilers (written by some of the smartest engineers on Earth) trying hard to prevent developers from writing shitty software, those new age "engineers" still managed to ship software that crashes, leaks, and generally sucks.
I'm not saying this email client is not secure (although I'd bet 5$, it is). But it seems beyond silly to assume software is automatically safe just because a new piece of tech can potentially find vulnerabilities. Intent still matters. And the 99% would never have the intent to write secure software.