Playing whack-a-mole is losing
Summary
The piece contrasts 'Security as Identity' with 'Security as Robustness' in security engineering, arguing that a culture focused on discovering and patching clever vulnerabilities leads to ongoing insecurity and a whack-a-mole mindset. It advocates using vulnerability reward programs strategically, focusing on systemic invariants, architecture, and CI practices, and leveraging AI-enabled tooling to prevent vulnerabilities by construction rather than chasing them after they appear. The author also compares security to SRE principles and urges defenders to build robust systems rather than chase constant bug discovery.