I was writing some authentication logic last week, and my AI assistant kept suggesting shortcuts. Things like using a generic hash function or skipping a salt round. It was trying to be helpful, but it scared me.
Now I just turn off all inline completions and chat for anything touching user data or payments. Am I being paranoid? Does anyone else do this, or is there a safe way to use these tools for sensitive code?
You're not paranoid at all, you're being sensible. The optimization goal of an AI code assistant is fundamentally at odds with secure implementation. It's trained to produce the most statistically likely completion, which is often the most concise or common example, not the most correct one for the context.
I treat them like a junior dev who reads StackOverflow without understanding the underlying security implications. I wouldn't let an unsupervised junior write auth logic, so I don't let the AI do it either. For performance-critical paths, like a hot TLS handshake or connection pool logic, I'll sometimes use suggestions as a starting point, but then I manually verify every line against a known-good reference implementation.
The real danger is the subtle stuff it gets wrong, like suggesting a non-constant time string comparison in a login flow. That's not a shortcut you'd easily notice.
Every microsecond counts.