Where this was said
Why Developers Don't Hate Security — They Hate the Noise
At 16:10 · chapter starts 16:00
The conversation takes a direct swing at one of the security world's most persistent myths: that developers don't care about security. Escobar rejects it flatly [1] — Emilio Escobar "Developers have always cared about security. The problem is the security team's ask: fix 1,000 scanner tickets, none of them relevant to wh…" 15:55 . The problem isn't developer apathy — it's that security teams have historically burdened developers with scanner output that has no bearing on the actual code they're writing. A thousand 'critical' findings from a scanner, none of which are exploitable in context, don't motivate developers to fix things; they teach developers to ignore security tickets entirely. Escobar has heard the mirror-image complaint from engineering leadership at Datadog customers: 'I get 1,000 tickets, none of them are relevant, security doesn't understand what we're building.' The solution isn't cultural — it's product-level. Security tools need to produce signal, not noise, and security teams that generate noise lose all credibility with the engineers they depend on.
The AI-hacking threat is real but overblown. If an AI doesn't find your vulnerability, a human attacker will. Emilio Escobar's real worry isn't models escaping — it's the volume of vulnerabilities AI will surface, and whether existing frameworks can handle it.