korrents
David Heinemeier Hansson

What David Heinemeier Hansson thinks about cybersecurity

@dhh · 695 positions · 10 changes of mind

Creator of Ruby on Rails, CTO of 37signals, and creator of Omarchy.

Everything they publish, on ppll ↗ Who they are, on wiqqi ↗

David Heinemeier Hansson did not write this page.

We collected these quotes from things they published elsewhere, and every quote links to where it was said. They have no account here and have not endorsed this site. Quotes are word for word; the short line under each one is our own restatement, not their wording. Their own site. Is this you? Claim it or ask us to remove it. Or tell us what is wrong here.

8 dated positions, 2021 to 2026, in their own words. Our reading of what David Heinemeier Hansson has said — not written or endorsed by them.

  1. So the irony here is that when you look at that field, it seems like we've reached levels of intelligence that virtually no human can match because many of these security holes are about stringing combo moves together. You find one little vulnerability here that by itself might not be the worst thing in the world, but then you combine it with four others, and suddenly you have RCE, remote command execution. Humans who are able to do that are very rare.

    ↗DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux | Lex Fridman Podcast #501youtube.com 3rd of 41 in this recording

  2. 24 months earlier
  3. The problem with passkeys is that they're essentially a halfway house to a password manager

    ↗Passwords have problems, but passkeys have moreworld.hey.com 1st of 3 in this piece

  4. And at the moment, I don't see how passkeys are actually better

    ↗Passwords have problems, but passkeys have moreworld.hey.com 2nd of 3 in this piece

  5. 6 months earlier
  6. having all your computing eggs in one basket leaves you mighty vulnerable to predatory behavior

    ↗You can own more than one type of computer!world.hey.com 1st of 2 in this piece

  7. 4 weeks earlier
  8. it's never been easier to confidently connect a computer to the internet, and have it serve up a web app securely on port 443

    ↗Dare to connect a server to the internetworld.hey.com 2nd of 2 in this piece

  9. 2 years earlier
  10. With the Mac, we have almost forty years of proof that computers don't need an App Store to be safe

    ↗The Mac proves Apple can safely open the iPhoneworld.hey.com 1st of 2 in this piece

  11. 9 months earlier
  12. security on the internet is instead based on hardened browsers, isolated processes, restricted device access, and other system-level protective techniques

    ↗The App Store is broken because it wasn't designed to workworld.hey.com 2nd of 3 in this piece

  13. 5 weeks earlier
  14. The internet can be a pretty grim place, and if you're building software here, you better think about how it can be abused, because odds are that it will

    ↗Thinking about HEY World's potential for abuseworld.hey.com