Software Engineering

Essays about building, operating, and understanding software systems in an AI-assisted engineering world.

  1. The Hugging Face Incident Is Not an AI Story

    A security engineer’s analysis of the OpenAI-Hugging Face incident, what failed in the architecture and incident response, and the lessons security teams can learn from it.

  2. Fundamental security principles

    This post is all about the “big ideas” behind secure systems, like least privilege and separation of duties. These principles are surprisingly simple but form the backbone of how we design systems to stay safe from attacks.

  3. You Are the Bottleneck Now

    AI can generate code faster than most developers can evaluate it. The risk isn't only bad output. It's losing the understanding you need to tell good code from plausible code.

  4. The Illusion of Building

    AI makes it dramatically cheaper to produce software that appears to work. But 'building an app' and 'engineering a system' are two different activities that people keep confusing, and the gap between them is where most of the actual work lives.

  5. Security Is Not a Code Problem

    Security is having a moment: new tools can read code, find bugs, and even suggest fixes. Some people took that to mean cybersecurity is basically over. This is my take from the inside: what’s actually changing, what isn’t, and why security was never just a code problem.

© 2026 Uphack.io

RSS Theme