Artem Merets
guest · information security architect · Т-Банк
Артем Мерец развивает защиту Т-Банка в роли архитектора и имеет многолетний опыт в AppSec и offensive security.
host
guest · information security architect · Т-Банк
Артем Мерец развивает защиту Т-Банка в роли архитектора и имеет многолетний опыт в AppSec и offensive security.
Alexander Polomodov and information security architect Artem Merets review Secure by Design at Google. The paper sets a direction: security is following platform engineering and becoming a product property. Its limitation is that logical and integration vulnerabilities receive less attention than technical flaws.
Secure by design is distinguished from secure by default and protection added at the end. Rules cannot scale through training thousands of engineers; they must be embedded in the platform. Attacker goals, data invariants, and expected behavior are more useful than treating a list of attacks as complete.
The authors consider product users, C++ developers, and SREs. Safe settings, memory-safe stacks, IDE feedback, and automated checks reduce the room for error. Models can detect a vulnerability and suggest a fix, but logical defects still require domain knowledge.
The final picture is an ecosystem of archetypes, libraries, and golden paths. Infrastructure, application, and policy as code make change verifiable and manual production edits exceptional. Security and platform teams must provide early feedback and make the safe path easier without promising to remove every risk.