
Episode #147
#147 "Make It Secure" Isn't a Prompt: A L0pht Hacker on Securing AI-Written Code with Chris Wysopal // Chief Security Evangelist @ Veracode
Chris Wysopal was one of the first hackers to go public. As "Weld Pond" at the L0pht hacker collective in Boston, he testified before the US Senate in 1998, where the group delivered the soundbite that they could take down the internet in 30 minutes. He also wrote the Windows version of Netcat. In 2006 he co-founded Veracode, which by his account has now analysed trillions of lines of code. Today he's the company's Chief Security Evangelist. Tobi and Chris talk about what AI changes for attackers and defenders. Attacks are getting cheaper and faster, and a custom exploit no longer tells you a nation-state is behind it. Chris argues this follows a familiar cycle: attackers adopt a new class of tool first, defenders catch up, and parity returns. That only holds if defenders actually adopt the tools, especially underfunded organisations like hospitals, schools and utilities. They also cover the new attack surface created by agents, plugins and MCPs, why prompt injection may never be fully solvable, and how Chris would handle security debt when acquiring a small SaaS company. CTOs will leave with a concrete shortlist: avoid memory-unsafe languages, put a package firewall in front of open source, run AI-assisted static analysis with real architectural context, and give coding agents explicit security intent rather than hoping "make it secure" does the job. - From the L0pht and BBS culture to the professional security industry - The BGP flaw behind "30 minutes to take down the internet" - How AI changes the cost and speed of attacks - Prompt injection, agents, MCPs and least privilege - Security debt in B2B SaaS acquisitions - Secure on first write: security intent, context and pre-merge testing - How engineering and security roles change over the next two years






