6 ms·
Claude Code defaulting to a certain set of recommended providers[0] and frameworks is making the web more homogenous and that lack of diversity is increasing th
by nikcub 6mo ago
Claude Code defaulting to a certain set of recommended providers[0] and frameworks is making the web more homogenous and that lack of diversity is increasing the blast radius of incidents
[0] https://amplifying.ai/research/claude-code-picks/report https://amplifying.ai/research/claude-code-picks/report
- nightski 6mo agoIt's a good point, but I don't think the problem here is Claude. It's how you use it. We need to be guiding developers to not let Claude make decisions for them. It can help guide decisions, but ultimately one must perform the critical thinking to make sure it is the right choice. This is no different than working with any other teammate for that matter.
- dennisy 6mo agoI think most people would agree. However it is less clear on how to do this, people mostly take the easiest path.
- fintler 6mo agoIts an eternal september moment. https://en.wikipedia.org/wiki/Eternal_September https://en.wikipedia.org/wiki/Eternal_September
- userbinator 6mo agoEternal Sloptember
- deleted 6mo ago[deleted]
- operatingthetan 6mo agoI guess engineers can differentiate their vibecoded projects by selecting an eccentric stack.
- alex7o 6mo agoChoosing an eccentric stack makes the llms do better even. Like Effect.ts or Elixir
- rpcope1 6mo agoI actually noticed the same. Having it work on Mithril.js instead of React seems (I know it's all just kind of hearsay) to generate a lot cleaner code. Maybe it's just because I know and like Mithril better, but also is likely because of the project ethos and it's being used by people who really want to use Mithril in the wild. I've seen the same for other slightly more exotic stacks like bottle vs flask, and telling it to generate Scala or Erlang.
- fragmede 6mo agoThat makes sense. There's less training data but it is better training data. LLMs were trained on really bad pandas code, so they're really really good at generating bad pandas. Elixer, there's less of it, but what there is, is higher quality, so then what it outputs is off higher quality too.
- gommm 6mo agoThat's been my experience as well. Claude code does better with Elixir (plus I enjoy working on the code better after :) )
- egeozcan 6mo ago> a. Actually do something sane but it will eat your session > b. (Recommended) Do something that works now, you can always make it better later
- duped 6mo agoNo, the problem is the people building and selling these tools. They are marketed as a way of outsourcing thinking.
- dennisy 6mo agoSo what are you suggesting do not allow companies to sell such tools?
- duped 6mo agoI'm suggesting people shouldn't lie to sell things because their customers will believe them and this causes measurable harm to society.
- liveoneggs 6mo agoAI does outsource thinking. It is not a lie.
- duped 6mo agoI think if you believe that you're either lying or experiencing psychosis. LLMs are the greatest innovation in information retrieval since PageRank but they are not capable of thought anymore than PageRank is.
- hansmayer 6mo agoIf you don't tend to think much in the first place or have low expectations, then yes
- pastel8739 6mo agoShouldn’t Claude just refuse to make decisions, then, if it is problematic for it to do so? We’re talking about a trillion dollar company here, not a new grad with stars in their eyes
- lionkor 6mo agoIt's just an LLM.
- gommm 6mo agoThat's not helped by a recent change to their system prompt "acting_vs_clarifying": > When a request leaves minor details unspecified, the person typically wants Claude to make a reasonable attempt now, not to be interviewed first. Claude only asks upfront when the request is genuinely unanswerable without the missing information (e.g., it references an attachment that isn’t there). > When a tool is available that could resolve the ambiguity or supply the missing information — searching, looking up the person’s location, checking a calendar, discovering available capabilities — Claude calls the tool to try and solve the ambiguity before asking the person. Acting with tools is preferred over asking the person to do the lookup themselves. > Once Claude starts on a task, Claude sees it through to a complete answer rather than stopping partway. [...] In my experience before this change. Claude would stop, give me a few options and 70% of the time I would give it an unlisted option that was better. It actually would genuinely identify parts of the specs that were ambiguous and needed to be better defined. With the new change, Claude plows ahead making a stupid decision and the result is much worse for it.
- operatingthetan 6mo agoIt's interesting how many of the low-effort vibecoded projects I see posted on reddit are on vercel. It's basically the default.
- fantasizr 6mo agonext, vercel, and supabase is basically the foundation of every vibecoded project by mere suggestion.
- deleted 6mo ago[deleted]
- MrDarcy 6mo agoThey’re all shit too. All three decided to do custom auth instead of OIDC and it’s a nightmare to integrate with any of them.
- 00deadbeef 6mo agoMaybe that's why all these vibe coded slop apps also use Clerk for auth alongside Supabase etc
- jongjong 6mo agoIf this kind of vulnerability exists at the platform level, imagine how vulnerable all the vibe-coded apps are to this kind of exploit. I don't doubt the competence of the Vercel team actually and that's the point. Imagine if this happens to a top company which has their pick of the best engineers, on a global scale. My experience with modern startups is that they're essentially all vulnerable to hacks. They just don't have the time to actually verify their infra. Also, almost all apps are over-engineered. It's impossibly difficult to secure an app with hundreds of thousands of lines of code and 20 or so engineers working on the backend code in parallel. Some people are like "Why they didn't encrypt all this?" This is a naive way to think about it. The platform has to decrypt the tokens at some point in order to use them. The best we can do is store the tokens and roll them over frequently. If you make the authentication system too complex, with too many layers of defense, you create a situation where users will struggle to access their own accounts... And you only get marginal security benefits anyway. Some might argue the complexity creates other kinds of vulnerabilities.
- andersmurphy 6mo agoThat's the irony of Mythos. It doesn't need to exist. LLM vibe slop has already eroded the security of your average site.
- wonnage 6mo agoConspiracy theory: they intentionally seeded the world with millions of slop PRs and now they’re “catching bugs” with Mythos
- egeozcan 6mo agoSelf fulfilling prophecy: You don't need to secure anything because it doesn't make a difference, as Mythos is not just a delicious Greek beer, but also a super-intelligent system that will penetrate any of your cyber-defenses anyway.
- andersmurphy 6mo agoIn some ways Mythos (like many AI things) can be used as the ultimate accountability sink. These libraries/frameworks are not insecure because of bad design and dependency bloat. No! It's because a mythical LLM is so powerful that it's impossible to defend against! There was nothing that could be done.
- antonvs 6mo agoMythos is the new DDoS or “state-level actors”.
- Something1234 6mo agoExplain more about this beer.
- egeozcan 6mo agohttps://en.wikipedia.org/wiki/Mythos_Beer https://en.wikipedia.org/wiki/Mythos_Beer I really like it. Recommended.
- btown 6mo ago"Nobody ever got fired for putting their band page on MySpace."
- stefan_ 6mo agoIt's so trivial to seed. LLMs are basically the idiots that have fallen for all the SEO slop on Google. Did some travel planning earlier and it was telling me all about extra insurances I need and why my normal insurance doesn't cover X or Y (it does of course).
- neal_jones 6mo agoThe thing I can’t stop thinking about is that Ai is accelerating convergence to the mean (I may be misusing that) The internet does that but it feels different with this
- themafia 6mo ago> convergence to the mean That's a funny way of saying "race to the bottom." > The internet does that but it feels different with this How does "the internet do that?" What force on the internet naturally brings about mediocrity? Or have we confused rapacious and monopolistic corporations with the internet at large?
- mentalgear 6mo agoIndeed 'race to the bottom' seems more like capitalism in general.
- walthamstow 6mo agoI'd call it race to the median, converging to mediocrity, or what the kids would call "mid"
- slashdave 6mo ago> How does "the internet do that?" Stack exchange. Google.
- neilv 6mo agoThe other day, I was forcing myself to use Claude Code for a new CRUD React app[1], and by default it excreted a pile of Node JS and NPM dependencies. So I told something like, "don't use anything node at all", and it immediately rewrote it as a Python backend, and it volunteered that it was minimizing dependencies in how it did that. [1] only vibe coding as an exercise for a throwaway artifact; I'm not endorsing vibe coding
- echelon 6mo agoIt emits Actix and Axum extremely well with solid support for fully AOT type checked Sqlx. Switch to vibe coding Rust backends and freeze your supply chain. Super strong types. Immaculate error handling. Clear and easy to read code. Rock solid performance. Minimal dependencies. Vibe code Rust for web work. You don't even need to know Rust. You'll osmose it over a few months using it. It's not hard at all. The "Rust is hard" memes are bullshit, and the "difficult to refactor" was (1) never true and (2) not even applicable with tools like Claude Code. Edit: people hate this (-3), but it's where the alpha is. Don't blindly dismiss this. Serializing business logic to Rust is a smart move. The language is very clean, easy to read, handles errors in a first class fashion, and fast. If the code compiles, then 50% of your error classes are already dealt with. Python, Typescript, and Go are less satisfactory on one or more of these dimensions. If you generate code, generate Rust.
- neilv 6mo agoHow are you getting low dependencies for Web backend with Rust? (All my manually-written Rust programs that use crates at all end up pulling in a large pile of transitive dependencies.)
- OptionOfT 6mo agoExcept with using Rust like this you're using it like C#. You don't get to enjoy the type system to express your invariants.
- slopinthebag 6mo agoOk I mean this is a little crazy, "minimal dependencies" and Rust? Brother I need dependencies to write async traits without tearing my hair out. But you're also correct in that Rust is actually possible to write in a more high level way, especially for web where you have very little shared state and the state that is shared can just be wrapped in Arc<> and put in the web frameworks context. It's actually dead easy to spin up web services in Rust, and they have a great set of ORM's if thats your vibe too. Rust is expressive enough to make schema-as-code work well. On the dependencies, if you're concerned about the possibility of future supply chain attacks (because Rust doesn't have a history like Node) you can vendor your deps and bypass future problems. `cargo vendor` and you're done, Node has no such ergonomic path to vendoring, which imo is a better solution than anything else besides maybe Go (another great option for web services!). Saying "don't use deps" doesn't work for any other language other than something like Go (and you can run `go vendor` as well). But yeah, in today's economy where compute and especially memory is becoming more constrained thanks to AI, I really like the peace of mind knowing my unoptimised high level Rust web services run with minimal memory and compute requirements, and further optimisation doesn't require a rewrite to a different language. Idk mate, I used to be a big Rust hater but once I gave the language a serious try I find it more pleasant to write compared to both Typescript and Go. And it's very amiable to AI if that's your vibe(coding), since the static guarantees of the type system make it easier for AI to generate correct code, and the diagnostics messages allow it to reroute it's course during the session.
- elric 6mo agoInterstingly, a recent conversation [1] between Hank Green and security researcher Sherri Davidoff argued the opposite. More GenAI generated code targeted at specific audiences should result in a more resilient ecosystem because of greater diversity. That obviously can't work if they end up using the same 3 frameworks in every application. [1] https://www.youtube.com/watch?v=V6pgZKVcKpw https://www.youtube.com/watch?v=V6pgZKVcKpw
- habinero 6mo agoI love Hank, but he has such a weird EA-shaped blind spot when it comes to AI. idgi It is true that "more diversity in code" probably means less turnkey spray-and-pray compromises, sure. Probably. It also means that the models themselves become targets. If your models start building the same generated code with the same vulnerability, how're you gonna patch that?
- kay_o 6mo ago> start building the same generated code with the same vulnerability This situation is pretty funny to me. Some of my friends who arent technical tried vibe coding and showed me what they built and asked for feedback I noticed they were using Supabase by default, pointed out that their database was completely open with no RLS So I told them not to use Supabase in that way, and they asked the AI (various diff LLMs) to fix it. One example prompt I saw was: please remove Supabase because of the insecure data access and make a proper secure way. Keep in mind, these ppl dont have a technical background and do not know what supabase or node or python is. They let the llm install docker, install node, etc and just hit approve on "Do you want to continue? bash(brew install ..)" Whats interesting is that this happened multiple times with different AI models. Instead of fixing the problem the way a developer normally would like moving the database logic to the server or creating proper API endpoints it tried to recreate an emulation of Supabase, specifically PostgREST in a much worse and less secure way. The result was an API endpoint that looked like: /api/query?q=SELECT * FROM table WHERE x In one example GLM later bolted on a huge "security" regular expression that blocked , admin, updateadmin, ^delete* lol
- 6mo ago
- mvkel 6mo agoThat's only looking at half of the equation. That lack of diversity also makes patches more universal, and the surface area more limited.
- betocmn 6mo agoYeah, I’ve been tracking what devtools different models choose: https://preseason.ai https://preseason.ai
- slashdave 6mo agoI'm not against making agents scapegoats, but this is a problem found among humans as well.
- lmm 6mo agoIs that bad? I would think having everyone on the same handful of platforms should make securing them easier (and means those platforms have more budget to to so), and with fewer but bigger incidents there's a safety-of-the-herd aspect - you're unlikely to be the juiciest target on Vercel during the vulnerability window, whereas if the world is scattered across dozens or hundreds of providers that's less so.
- leduyquang753 6mo agoWhen everyone uses the same handful of platforms, then everyone becomes the indirect target and victim of those big incidents. The recent AWS and Cloudflare outages are vivid examples. And then the owners of those platforms target everyone with their enshittification as well to milk more and more money.
- jongjong 6mo agoYes, this is a genuine problem with AI platforms. It does sometimes feel like they're suspiciously over-promoting certain solutions; to the point that it's not in the AI platform's interest. I know what it's like being on the opposite side of this as I maintain an open source project which I started almost 15 years ago and has over 6k GitHub stars. It's been thoroughly tested and battle-tested over long periods of time at scale with a variety of projects; but even if I try to use exact sentences from the website documentation in my AI prompt (e.g. Claude), my project will not surface! I have to mention my project directly by name and then it starts praising it and its architecture saying that it meets all the specific requirements I had mentioned earlier. Then I ask the AI why it didn't mention my project before if it's such a good fit. Then it hints at number of mentions in its training data. It's weird that clearly the LLM knows a LOT about my project and yet it never recommends it even when I design the question intentionally in such a way that it is the perfect fit. I feel like some companies have been paying people to upvote/like certain answers in AI-responses with the intent that those upvotes/likes would lead to inclusion in the training set for the next cutting-edge model. It's a hard problem to solve. I hope Anthropic finds a solution because they have a great product and it would be a shame for it to devolve into a free advertising tool for select few tech platforms. Their users (myself included) pay them good money and so they have no reason to pander to vested interests other than their own and that of their customers.
- lelanthran 6mo ago> It's weird that clearly the LLM knows a LOT about my project and yet it never recommends it even when I design the question intentionally in such a way that it is the perfect fit. That's literally what "weight" means - not all dependencies have the same %-multiplier to getting mentioned. Some have a larger multiplier and some have a smaller (or none) multiplier. That multiplier is literally a weight.
- deaux 6mo agoThat report greatly overrates the tendency to default for Vercel for web because among its 2 web projects it mandated one use Next.js and the other one to be a React SPA as well. Obviously those prime Claude towards Vercel. They shouldve had the second project be a non-React web project for diversity.
- neither_color 6mo agoThis is why Im glad I learned to code before vibecoding. I tell codex exactly what tools and platforms to use instead of letting it default to whatever is the most popular, and I guard my .env and api keys carefully. I still build things page by page or feature by feature instead of attempting to one shot everything. This should be vibe-coding 101.
- ethbr1 6mo ago$ Good idea! Let's add a Redis cache to that!