6 ms·
Engineers have been vibe coding a lot recently...
by NinjaTrance 8mo ago
Engineers have been vibe coding a lot recently...
- jsheard 8mo agoThe featured blog post where one of their senior engineering PMs presented an allegedly "production grade" Matrix implementation, in which authentication was stubbed out as a TODO, says it all really. I'm glad a quarter of the internet is in such responsible hands.
- dana321 8mo agoThats a classic claude move, even the new sonnet 4.6 still does this.
- brutalc 8mo ago[dead]
- bonesss 8mo agoIt’s almost as classic as just short circuiting tests in lightly obfuscated ways. I could be quite the kernel developer if making the test green was the only criteria.
- allovertheworld 8mo agoWait till you get AI to write unit tests and tell it the test must pass. After a few rounds it will make the test “assert(true)” when the code cant get the test to pass
- blibble 8mo agothere was also a post here where an engineer was parading around a vibe-coded oauth library he'd made as a demonstration of how great LLMs were at which point the CVEs started to fly in
- gtowey 8mo agoIt's spreading and only going to get worse. Management thinks AI tools should make everyone 10x as productive, so they're all trying to run lean teams and load up the remaining engineers with all the work. This will end about as well as the great offshoring of the early 2000s.
- ranger_danger 8mo agoMatrix doesn't actually define how one should do authentication though... every homeserver software is free to implement it however they want.
- Arathorn 8mo agothe main bit of auth which was left unimplemented on matrix-workers was the critical logic which authorizes traffic over federation: https://spec.matrix.org/latest/server-server-api/#authorization-rules https://spec.matrix.org/latest/server-server-api/#authorizat... Auth for clients is also specified in the spec - there is some scope for homeservers to freestyle, but nowadays they have to implement OIDC: https://spec.matrix.org/latest/client-server-api/#client-authentication https://spec.matrix.org/latest/client-server-api/#client-aut...
- dakiol 8mo agoNo joke. In my company we "sabotaged" the AI initiative led by the CTO. We used LLMs to deliver features as requested by the CTO, but we introduced a couple of bugs here and there (intentionally). As a result, the quarter ended up with more time allocated to fix bugs and tons of customer claims. The CTO is now undoing his initiative. We all have now some time more to keep our jobs.
- logicchains 8mo agoThat's not "sabotaged", that's sabotaged, if you intentionally introduced the bugs. Be very careful admitting something like that publicly unless you're absolutely completely sure nobody could map your HN username to your real identity.
- samrus 8mo agoThats actively malicious. I understand not going out of your way to catch the LLMs' bugs so as to show the folly of the initiative, but actively sabotaging it is legitimately dangerous behavior. Its acting in bad faith. And i say this as someone who would mostly oppose such an initiative myself I would go so far as to say that you shouldnt be employed in the industry. Malicious actors like you will contribute to an erosion of trust thatll make everything worse
- sp00chy 8mo agoMight be but sometimes you don’t have another choice when employers are enforcing AIs which have no „feeling“ for context of all business processes involved created by human workers in the years before. Those who spent a lot of love and energy for them mostly. And who are now forced to work against an inferior but overpowered workforce. Don’t stop sabotaging AI efforts.
- samrus 8mo agoHonestly i kinda like the aesthetic of cyberanarchism, but its not for me. It erodes trust
- 8mo ago