
Security engineering is moving away from a model that depends on humans noticing every weakness in time. In a recent InfoQ podcast, Chris Swan of Atsign argued that the future of cybersecurity will be shaped by hardware memory safety, automated governance, post-quantum cryptography and tighter controls around AI agents that increasingly act on behalf of people and systems.
Chris Swan on the shifting security baseline
Swan, who is also security track host at QCon London, framed the discussion around a simple but consequential idea: modern systems are built on layers that are often treated as someone else’s problem. That includes dependencies, platform choices, hardware features and the supply chain evidence needed to prove software was built and maintained responsibly.
His message was that security can no longer rely on manual vigilance alone. “We need to systematize those things,” he said, so machines can continuously monitor the stack for weaknesses, missing safeguards and emerging exposure.
Hardware memory safety and the case for CHERI
One of the strongest themes in the conversation was hardware memory safety, especially the CHERI project. Swan described CHERI as a research-driven approach from Cambridge that catches out-of-bounds memory errors in hardware, rather than asking developers to rewrite vast codebases first.
That distinction matters because, as he noted, there are about 5.5 billion lines of open source C and C++ in the world versus roughly 70 million lines of Rust. In his view, a full rewrite of that scale is not realistic, even with AI assistance. CHERI offers another route: recompile existing C and C++ with CHERI awareness and let the hardware enforce memory safety.
Swan also pointed to a practical deployment opportunity. He said the latest iPhone system-on-chip and some flagship Android chips for Google Pixel and Samsung Galaxy devices already include some hardware memory safety features inspired by CHERI. The next important step, he argued, would be wider adoption through RISC-V, which remains flexible enough to incorporate CHERI instructions into future Android profiles.
Why hardware matters alongside Rust
The podcast did not dismiss memory-safe languages. Instead, Swan stressed that language rewrites can introduce their own logic bugs even if they eliminate an entire class of memory safety issues. His point was that hardware protections could reduce risk across the existing ecosystem much faster than waiting for a wholesale language migration.
- CHERI aims to stop out-of-bounds errors directly in hardware.
- It could protect legacy C and C++ software without a full rewrite.
- RISC-V is seen as a possible path to broader adoption.
Automated governance is becoming mandatory
The other major thread was governance, especially software bills of materials, or SBOMs. Swan tied that to the European Union’s Cyber Resilience Act, saying the CRA’s breach reporting requirements are already in force and that SBOM obligations take effect next December. For organizations selling software or software-enabled products in the EU, that means SBOMs are moving from a best practice to a practical necessity.
He said SBOMs do two things at once. First, they show that an organization is paying attention to security. Second, they provide the raw material for vulnerability exposure tracking, allowing teams to understand what is in their software and where the risks are.
Swan connected that to broader supply chain controls such as SLSA attestations and automated open source scorecards. In a continuous delivery pipeline, these tools can generate evidence that software was built with the right inputs, through the right process, in the right environment. His kitchen analogy was straightforward: customers want proof that the ingredients were right, the cooking was done properly and the kitchen was hygienic.
Post-quantum cryptography is moving from theory to operations
Another focus was post-quantum cryptography. Swan said he expects QCon next year to include at least one dedicated talk on the topic, because the timeline is tightening. The concern is “Q day,” the point at which quantum computing could become strong enough to break RSA and elliptic-curve cryptography using Shor’s algorithm.
According to Swan, the algorithms themselves are now settled through NIST’s standardization work, including ML-KEM and ML-DSA. The harder problem is implementation. Libraries are still immature, and the latest OpenSSL builds with post-quantum support are only available on bleeding-edge distributions.
That leaves enterprises with a difficult migration path. They may need to upgrade operating systems, backport libraries or inventory every place cryptography is used. Swan said this may look a lot like Y2K: first find every vulnerable instance, then work through the migration to crypto-agile systems.
- NIST has standardized the core post-quantum algorithms.
- Tooling and distro support are still catching up.
- Organizations need crypto agility, not hard-coded dependence on one algorithm set.
LLMs as both attackers’ tool and defenders’ assistant
The podcast also addressed large language models. Swan said they are simultaneously a threat and an opportunity. Attackers can use them to discover and weaponize vulnerabilities faster, but defenders can use the same technology for white-box testing, source analysis and automated evaluation.
He referenced projects such as Glasswing as examples of defensive use, where models help teams find weaknesses before adversaries do. Swan said he is seeing more organizations ask their programming tools to perform security evaluations as part of the normal delivery process, rather than waiting for a late-stage penetration test.
He expects that approach to become routine, especially as the pace of vulnerability discovery accelerates and the time between disclosure and exploitation continues to shrink.
AI agents raise identity and authorization problems
If LLMs are one side of the story, AI agents are the next. Swan warned that non-human identity management is now a central security issue, especially as autonomous agents gain access to files, services and credentials on behalf of users.
He and interviewer Olimpiu Pop discussed the risk of giving agents overly broad access. Swan said the right response is fine-grained, task-based permissioning with least privilege, plus auditing and oversight. He noted that many organizations already have far more non-human identities than human users, and that number is growing quickly.
His view is that this is not a new problem, but AI has made it harder to ignore. What changes now is scale, speed and the number of simultaneous actions an attacker or malicious agent can launch.
The bigger lesson: defend the whole stack
Toward the end of the conversation, Swan returned to the idea that security is not just about application code. It is about the entire ecosystem: governance, build systems, operating systems, hardware, identity and the trust anchors underneath everything else.
He said organizations that build security into their processes, use automation to maintain evidence and pay attention to lower-level foundations will be in a much better position than those still relying on ad hoc, ticket-driven work. In his words, the stack matters, and the best defense is one that works against human attackers, AI agents and hybrid threats alike.
Source: Original report
Was this helpful?
Explore more: Application Audit & Review More Cybersecurity Tech News
Last Modified: October 5, 2026 at 10:33 pm
0 views
