@securedbycasco: Cybersecurity expert reacts to viral security prompt. Rate limiting on all public endpoints — true, but if it’s a public endpoint, the user might not be authenticated yet. User-based rate limiting is limited. Strict input validation and sanitization — yes. Always make sure users are restricted in what they can enter. Secure API key handling — advice is accurate, but the most important thing is that whenever you’re making a call with an API key, that key should be on your server. Or even better, use short-lived credentials. #cybersecurity #buildinpublic #vibecoding
this vid just made me realize degrees are not that useless yet because they literally teach these concepts in college, in basic courses too
2026-05-20 13:18:37
704
Kvitka🇺🇦🏳️⚧️ :
We are so back, vibecoders gonna keep us in business for ages
2026-05-20 10:24:33
353
oldnote0 :
Nah, just type “no mistake”, “zero cost”✌️
2026-05-20 11:49:43
204
Farah 💅 :
As a platform engineer it’s so funny that last week people were saying I was gonna be out of a job and this week everyone is talking about platform engineering fundamentals. 🤣😭 what a rollercoaster. Like yea it doesn’t matter how cool an app is or how quickly it shipped if nobody actually considered the cost of the infrastructure required to host it at scale. So strange when I see people recommending things like “just use for backend”…. As if it’s free.
2026-06-05 04:29:59
4
່່ :
or probably learn about securing your code
2026-05-20 08:01:27
66
mandnru :
I really expected the prompt to be “don’t get hacked. Make no mistakes”
2026-05-21 22:11:52
3
KingHalik :
because human coded apps are known to be so secure.
2026-07-24 16:17:02
3
JC :
I’m getting through regardless of what you tell that AI 😛
2026-05-21 19:28:10
0
Catwomaniya | Building Fenn :
Will you vibecoders pay for security audits? Happy to provide that service but honestly most folks dont even care about security
2026-05-21 13:44:22
6
Jay :
Linux is getting hacked nearly daily by AI. AFAIK, all the exploits rely on code not vibe coded and peer reviewed. 😬
2026-05-20 13:19:38
0
RYHDRY🔥 :
I’ll just pay the 20K. Why not a 40K bill though
2026-05-21 15:41:40
2
user9999451649034 :
Is this AI?
2026-06-24 08:38:22
2
McTheo :
I stopped updating ALL software when it all started... old software is more secure
2026-05-22 11:57:14
0
sekrd :
rate limiting catches the obvious — the harder gap is when the endpoint is authenticated but the action isn't scoped. an authed user hitting /api/export?tenant=other_id if object-level auth isn't enforced at the query layer
2026-05-21 10:59:06
2
ModestYahu :
thats why I make private apps for me only
2026-05-21 00:21:11
4
Clue :
what if you made the app only for yourself???
2026-05-22 12:49:04
1
Alex Nord :
Not using AWS. Using hetzner. Max bill is like 25€ a month. Never will get fucked
2026-05-24 13:27:17
2
Nexus mods :
casco
2026-05-20 12:56:44
2
kats :
CASCO
2026-06-04 15:59:53
1
kris nolan :
AI is looking more and more like nerd bs that isn’t really viable.
2026-05-22 02:21:24
1
The Tunisian Cat :
can you avoid all that if your app doesn’t ask any info or any login?
2026-05-20 20:24:44
3
Czar Payne :
casco
2026-08-02 02:02:22
0
enigma1337 :
Its funny its like they forget vibe coding is working with ai, as if the ai itself dont flag these things.
2026-07-29 14:54:05
0
T :
casco
2026-07-27 14:39:52
0
dillonnagar :
casco
2026-08-02 22:53:39
0
To see more videos from user @securedbycasco, please go to the Tikwm
homepage.