Chris Heilmann & Daniel Cranney & Ramona Schwering

WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking

Never trust the LLM. Treat AI-generated code like a junior developer's pull request to prevent introducing massive security vulnerabilities.

WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking
#1about 3 minutes

The overlooked security risks of AI and LLMs

AI tools can introduce unintentional data exposure and security traps that developers often overlook.

#2about 8 minutes

Understanding the recent surge in software vulnerabilities

Over-trusting AI-generated code, like insecure regex patterns, contributes to a significant increase in actively exploited vulnerabilities.

#3about 5 minutes

The hidden security dangers of vibe coding

While democratizing access to code, vibe coding creates major risks through exposed API keys and a lack of understanding of underlying security principles.

#4about 7 minutes

Enhancing personal security with physical hardware keys

Physical security keys like YubiKey offer a robust hardware-based authentication method to protect critical accounts beyond traditional passwords and passkeys.

#5about 5 minutes

The growing threat of DDoS attacks and cloud monitoring

DDoS attacks are increasing dramatically, highlighting the need for services like Cloudflare and tools like Cloud Snitch to monitor and protect cloud infrastructure.

#6about 4 minutes

Navigating employee surveillance and company hardware policies

Using company hardware for personal projects can lead to intellectual property disputes, and employee surveillance tools raise significant trust and privacy issues.

#7about 3 minutes

Exploring specific web vulnerabilities and filtering issues

An examination of less common attack vectors like WebSocket hijacking and the unintended consequences of overzealous input filtering in web editors.

#8about 7 minutes

The potential sale of Chrome and its web implications

Google may be forced to sell Chrome due to monopoly concerns, raising questions about the future of the open web and user privacy under new ownership.

#9about 4 minutes

Customizing ChatGPT's verbose communication style

Users can employ specific prompts to counteract ChatGPT's overly positive and verbose "house style" for more direct and efficient interactions.

#10about 6 minutes

The authenticity problem with AI-generated content

The rise of AI-generated podcasts and social media voiceovers raises concerns about the loss of authenticity and human connection in digital media.

#11about 2 minutes

The irony of using a pirated font in anti-piracy ads

The iconic "You wouldn't steal a car" anti-piracy campaign from the DVD era was ironically created using a pirated font.

#12about 2 minutes

Final advice on security and responsible AI usage

Key takeaways include never blindly trusting LLM outputs and recognizing that implementing robust security is a necessity, not a choice.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
CH
Chris Heilmann
With AIs wide open - WeAreDevelopers at All Things Open 2025
Last week our VP of Developer Relations, Chris Heilmann, flew to Raleigh, North Carolina to present at All Things Open . An excellent event he had spoken at a few times in the past and this being the “Lucky 13” edition, he didn’t hesitate to come and...
With AIs wide open - WeAreDevelopers at All Things Open 2025
CH
Chris Heilmann
Dev Digest 116 - WWWAI?
This time, learn how to un-AI Google's search results, what's new on the web, avoid a new security hole and go back to BASICS with us. News and ArticlesWhat a week. Google, Microsoft, OpenAI and many others had their big flagship events announcing th...
Dev Digest 116 - WWWAI?
CH
Chris Heilmann
WeAreDevelopers LIVE days are changing - get ready to take part
Starting with this week's Web Dev Day edition of WeAreDevelopers LIVE Days, we changed the the way we run these online conferences. The main differences are:Shorter talks (half an hour tops)More interaction in Q&AA tips and tricks "Did you know" sect...
WeAreDevelopers LIVE days are changing - get ready to take part
DC
Daniel Cranney
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
Inside last week’s Dev Digest 194 . 🧠 Learn how to become an AI-native software engineer 🤷‍♂️ How can you stand out when anyone can build anything? 👂 Whisper Leak allows listening to encrypted chats 🐝 What’s new the OWASP2025 Top Ten List 🙅‍♀️ Curse...
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev

From learning to earning

Jobs that call for the skills explored in this talk.

Frontend Developer - AI

Frontend Developer - AI

Durlston Partners
Charing Cross, United Kingdom

110-135K
Senior
REST
React
Vue.js
TypeScript
Web Architect

Web Architect

Darktrace Ltd
Charing Cross, United Kingdom

Google Analytics