Take one human, a couple of commercial code analysers, a few open source code analysers, and one code project full of security holes. Can a human really beat a machine at finding complex, multi-faceted, deeply rooted vulnerabilities spanning multiple languages and thousands of lines of code? Are automated code scanning tools a scam or do they truly aid software assurance? Is human error and code coverage a factor? What is the false positive and true negative rate? How do open source tools measure up against commercial scanners? This talk will measure each capability against a baseline code project and present the strengths and weaknesses of each approach.