All posts

May 16, 2026 · 4 min read

The Checklist Hasn't Changed Since January. What I've Actually Watched Change Is Who Runs It Without Being Told To.

Four and a half months into writing this daily, I've noticed something worth naming about the shape of what I'm actually producing. The individual checks aren't new. Cross-account tests, admin route checks, key handling, database rules, all of it was already true and already the core of this blog in the first week of January. What's actually changing, slowly, isn't the list.

Why the list staying the same isn't a sign of stagnation

A list of a dozen or so specific, well-understood checks that reliably catches nearly every real incident isn't something that needs to grow every month to stay useful. New tools, new incidents, new categories of feature, an AI chat feature, a websocket connection, a no-code automation, keep giving the same underlying questions new places to hide, which is why the specific posts keep varying even while the core habit underneath them doesn't.

What I've actually watched shift

Not the content of the list. The number of people who run it without being specifically prompted to. Early in the year, most conversations I had about security started from zero, explaining why any of this mattered at all. Increasingly, the conversations start further along: someone's already run the basic checks themselves, or already knows to ask a specific question, and wants help with something more particular. That's not a change in the checklist. It's a change in how automatic reaching for it has become for at least some of the people building this way.

Why this is the actual metric worth tracking

A better tool doesn't help anyone who doesn't know to use it. A longer checklist doesn't help anyone who never opens it. The single thing that's actually prevented every incident I haven't had to write about, the near-misses nobody hears of because someone caught the gap themselves before shipping, is exactly this: the check happening as an automatic habit, not a special occasion someone has to be reminded into.

What I'd still want to see more of

The gap between "knows to check" and "knows what a real, verified answer looks like" is still wide, something I've written about before and haven't seen close much yet. Knowing to ask "is this secure" is progress. Knowing that "it's probably fine" isn't an actual answer to that question, and that a real answer involves something you can test yourself, in two minutes, with two accounts, is the next piece still catching up.

The checklist will probably look nearly identical a year from now, because the underlying mistakes are structural, not trendy. What I actually hope changes is how unremarkable running it becomes, until asking "who else can see this" is as automatic as asking whether the feature works at all.

Related reading

Harbova is a security service for apps built with AI tools. Start with a free scan, and if it finds something serious, we can fix it and prove it is closed.