Security as Identity vs. Security as Robustness: Why Whack-a-Mole Is Losing
A security engineer argues that the industry's obsession with finding and patching bugs—whack-a-mole—is a losing strategy. The real goal should be building systems that are robust by design, using bug bounties as a diagnostic, not a cure.

In a recent blog post, security engineer David Adrian draws a sharp line between two mindsets in product security: Security as Identity and Security as Robustness. The former is the hacker ethos—glamorized by pop culture, driven by the thrill of finding unexpected vulnerabilities. The latter is about building systems that preserve their properties even under attack, where security is just good engineering.
Adrian argues that the identity mindset, while valuable for discovery, can become a trap. When your self-worth is tied to being the clever detective who finds the surprising bug, you start to reject solutions that don't fit that narrative. He draws a parallel to the environmental movement's early rejection of technological fixes like cheap solar and high-yield agriculture—solutions that didn't look 'environmental' enough, even though they ultimately did more to cut emissions than the preferred policies.
In security, this manifests as an over-reliance on vulnerability rewards programs (VRPs) as the end goal. Yes, VRPs are useful—they provide a channel for external reports and a steady stream of data. But Adrian insists that the real value of a VRP is not to enumerate every bug, but to inform a broader strategy that reduces the incidence of bugs over time. If the same types of issues keep appearing, you're not making progress; you're just getting faster at patching.
He contrasts this with the SRE model: when a service violates its SLO, the SRE team is empowered to halt feature work and fix the systemic issue. That's not whack-a-mole; that's addressing root causes. Security teams should have similar authority to intervene when they see recurring vulnerability classes.
Adrian's punchline: 'Playing whack-a-mole is losing.' If your security metrics are just 'resolved incidents going up and to the right,' you're not securing anything—you're just keeping busy. The hard work is making those bugs rare in the first place.
Playing whack-a-mole is losing. The point of a VRP is to grapple with the insecurity, not to enumerate all bugs.
Source: David Adrian
Discussion
0 Comments
Be the first to start the discussion.