Hopefully, this will finally lead to a shift in thinking so that security practices like those used in GrapheneOS become more widespread in the future. Most software developers simply patch security vulnerabilities as soon as they become aware of them rather than taking preventive measures where possible. Finding an exploit that works in Vanadium on GrapheneOS is significantly harder than on standard Android running…
Working in this space, I'm worried the future is even more reactive than today. Today I can get teams to review for security the architecture before implementing, and to review the implementation for security before shipping.
As teams move (more specifically, are forced to move) to vibe coding the whole thing, nobody knows what the design is or what the implementation looks like. Vibe all the way because the CEO says so or you're fired. This means the only place to catch vulnerabilities becomes after the fact, which is usually too late.