7 ms·
From https://kristoff.it/blog/contributor-poker-and-ai/ https://kristoff.it/blog/contributor-poker-and-ai/: "Unfortunately the reality of LLM-based contributio
by branko_d 5mo ago
From https://kristoff.it/blog/contributor-poker-and-ai/ https://kristoff.it/blog/contributor-poker-and-ai/:
"Unfortunately the reality of LLM-based contributions has been mostly negative for us, from an increase in background noise due to worthless drive-by PRs full of hallucinations (that wouldn’t even compile, let alone pass CI), to insane 10 thousand line long first time PRs. In-between we also received plenty of PRs that looked fine on the surface, some of which explicitly claimed to not have made use of LLMs, but where follow-up discussions immediately made it clear that the author was sneakily consulting an LLM and regurgitating its mistake-filled replies to us."
- bvan 5mo agoFake it ‘till you make it. Seems like LLM’s have caught-on to that too.
- feverzsj 5mo agoPretty much sums up the LLM fanbase.
- discreteevent 5mo agoI don't think it's the complete fanbase. However, there are lots of people in the world who live their whole life by vibing. It's a viable way to live and sometimes it's the only way to live. But they have a very loose relationship with truth and reason. Programming was a domain that filtered out those people because they found it hard to succeed at it. LLM's have changed that and it's a huge problem. It's hard to know if LLMs will end up being a net win for the industry. They may speed up the good programmers a little, but those people were able to program anyway without LLMs. They will speed up the bad programmers a lot and that's where the balance sheet goes into the red.
- kay_o 5mo ago> However, there are lots of people in the world who live their whole life by vibing Why are they often so desperate to lie and non-consensually harass others with their vibing rather than be honest about it? Why do they think they are "helping" with hallucinated rubbish that can't even build? I use LLMs. It is not difficult to: ethically disclose your use, double check all of your work, ensure things compile without errors, not lie to others, not ask it to generate ten paragraphs of rubbish when the answer is one sentence, and respect the project's guidelines. But for so many people this seems like an impossible task.
- ramon156 5mo agoIt's the same as cheating in a game. You are given an """advantage""", so lying about it seems like the best option
- drchickensalad 5mo agoYou're asking why oil doesn't act like water. It's not really an impossible task, it's just not one they agree with.
- automatic6131 5mo ago> Why do they think they are "helping" with hallucinated rubbish that can't even build? Because they can't tell the difference between what the machine is outputting, and what people have built. All they see is the superficial resemblance (long lines of incomprehensbile code) and the reward that the people writing the code have got, and want that reward too.
- toofy 5mo agothe target audience of the cyber typer terminal [0] [0] https://hackertyper.net/ https://hackertyper.net/
- pjc50 5mo ago"Main character energy". What they're really doing is protecting their view of themselves as smart, and they're making a contribution for the sake of trying to perform being an OSS dev rather than out of need or altruism. AI is absolutely terrible for people like that, as it's the perfect enabler.
- jcgrillo 5mo agoLLMs are in this case enabling bad behavior, but open source software has always been vulnerable to this. Similarly, people who use LLMs to do this kind of thing are the kind of people who would have done it without LLMs but for the large effort it would have taken. We're just learning now how large that group is. This is a good thing, it's an opportunity to make open source development processes robust to this kind of sabotage.
- dakolli 5mo ago> there are lots of people in the world who live their whole life by vibing. It's a viable way to live and sometimes it's the only way to live. But they have a very loose relationship with truth and reason This response 1000% was crafted with input from an LLM, or the user spends too much time reading output from llms.
- discreteevent 5mo agoI have never used an LLM to write. Writing forces me to think (and I edited the comment a couple of times when writing it which helped me clear up my thinking). "It's a viable way to live and sometimes it's the only way to live" is a personal realization that has taken me some time to understand. You can go back through my comment history to the time before LLMs to check if my style was different then.
- vehemenz 5mo agoIf you run your writing through an LLM, it can poke holes in your argument, organize your ideas better, or point out that your tone is hostile/dismissive. It doesn’t need to be a replacement for writing or thinking, especially if you’re learning along the way.
- 3form 5mo agoAll of which are parts of the writing and thinking skillset, no?
- vehemenz 5mo agoRight. It can enhance that skillset. Are you suggesting it can’t? This wouldn’t be a plausible position.
- 3form 5mo agoRather that avoiding delegating it to LLM for these tasks helps you practice that skill. That said, I think it depends how you use it. You can learn from explanations, and you'd better avoid "rewrite this for me and do nothing else" kind of approach.
- LAC-Tech 5mo ago> It's hard to know if LLMs will end up being a net win for the industry. They may speed up the good programmers a little, but those people were able to program anyway without LLMs. They will speed up the bad programmers a lot and that's where the balance sheet goes into the red. If you will forgive an appeal to authority: The hard thing about building software is deciding what one wants to say, not saying it. No facilitation of expression can give more than marginal gains. - Fred Brooks, 1986
- pelasaco 5mo ago> It's hard to know if LLMs will end up being a net win for the industry. True, regardless of that, for sure with LLM we are borrowing Technical debt like never before.
- secondcoming 5mo ago"Claude, don't create any technical debt please"
- jbxntuehineoh 5mo agoi've been told that it's totally fine because once the codebase turns into spaghetti you can simply tell the agent to refactor it and then everything will be ok
- all2 5mo agoI know this is a tongue-in-cheek response, but this brings me great pain. The spaghetti begins quickly, and your unit/functional tests won't help you unless you hammered out your module API seams before you even began. Oh, your abstractions are leaking? Your modules know too much about each other? Multiply the spaghetti!
- pelasaco 5mo agothe multiple layers of vibe, makes the dozen of code bases even harder to maintain.
- esafak 5mo agoWhy are we not paying it off? I sure am. I refactor code left and right. It is up to you.
- pelasaco 5mo ago> Why are we not paying it off? I sure am. I refactor code left and right. It is up to you. Do you work alone i presume? Everyone now is engineer. In my department, even managers are "writing code". Producing thousand of lines of ansible code, that nobody can review, with multiple lines of doc that nobody will read. It is just a mess.
- Planktonne 5mo ago> Programming was a domain that filtered out those people because they found it hard to succeed at it. I think this is a very rosy view of programmers, not borne out by history. The people leading the vibe coding charge are programmers, rather than an external group. I know it's popular to divide the world into the technically-literate and the credulous, but in this case the technical camp is also the one going all in.
- LaGrange 5mo agoFor at least the last 3 decades programming was a field that rewarded utter mediocrity with (relatively to other fields) massive remuneration. It has been filled with opportunists for as long as I remember.
- jcgrillo 5mo agoThis is an excellent point. LLMs might merely be exposing and amplifying behaviors that were always there. This can be an opportunity, in that shining light on it may allow us to cleanse ourselves of it. It's fundamentally about integrity, and sadly it's becoming clearer how few possess it (if it ever wasn't!). But maybe we'll get better at measuring integrity, and make hiring/collaboration decisions based on it.
- brabel 5mo agoYou are talking about bad programmers who are at least able to fool their managers for at least several years. The people OP is talking about could not even do that and most likely would have dropped out in the first week trying to program full time since they just don’t have the aptitude and patience to get unblocked after their first compilation error. Now they can go very far with a LLM.
- LaGrange 5mo agoThing is, it's not how incompetent they are, but the opportunism itself. The property I mentioned pulls in opportunists regardless of their competence. So eventually if you work in a field like this, you end up surrounded by them. There's always _some_ around you, of course, everywhere - but across time different fields tended to pull so many of them they would become suffocating to anyone who isn't one. And if you think you can interview your way out of this - an opportunist will often have an easier time to pass a harsh interview process than someone who cares. IT isn't the only one - finance and law had the issue since forever, AFAIK - but now I'd rather be in a field that's _actively repellent_ to them.
- 3form 5mo agoI think worth noting that a more impactful and maybe even bigger proportion of those opportunists is in management. Regarding quality overall, I agree, it's truly a cursed field. It was bad before; and with LLMs, going against that tide seems more difficult than ever.
- JackC 5mo ago"They may speed up the good programmers a little, but those people were able to program anyway without LLMs." I don't think this is realistic. I'm a good programmer, and it speeds up my work a lot, from "make sense of this 10 repo project I haven't worked on recently" to "for this next step I need a vpn multiplexer written in a language I don't use" to, yeah, "this 10k line patch lets me see parts of design space we never could have explored before." I think it's all about understanding the blast radius. Sonetimes a lot of code is helpful, sometimes more like a lot of help proving a fact about one line of code. Like Simon says, if I'm driving by someone else's project, I don't send the generated pull request, I just file the bug report / repro that would generate it.
- PunchyHamster 5mo ago> to "for this next step I need a vpn multiplexer written in a language I don't use" but that acceleration is exactly because you're not good at that language
- renticulous 5mo agoCan't we reach a compromise where proven track record of good use of LLM by a contributor or a company (eg. Bun) be pre-approved or entertained? Blanket ban on a new technology shouldn't be the default option.
- ragall 5mo agoNo.
- em-bee 5mo agoif they had a good track record, the current submission that led to this article damaged it. i am reminded of this quote: it takes more cleverness to debug code than it takes to write it. if you write code as clever as you can, by definition you are not clever enough to debug it. using LLM makes your code many times more clever than what you could write yourself. which means by the same definition the code is to clever for you to understand or debug it.
- hirako2000 5mo agoBefore LLMs we could already see a growing abundance of half baked engineers only in for the good pay. Willing to work double time to pull things out. Management, unsurprisingly deemed those precious. They could email them out anytime, working weekend to fix problems their kind were the cause. Sure sir. They excel at communication. Perfecting the art. Now LLMs are there to accelerate the trend.
- aerhardt 5mo agoYou're at least describing someone who sounds hard-working... what's the problem? I'd be more concerned if I was someone who signed up to play ping pong two hours a day and do a bi-weekly commit. There was a time not so long ago where I was watching "a day in the life of a software engineer" videos on Youtube and I was wondering if some of these were parodies. I still remember one in particular which I'm pretty sure was a parody, but it was only marginally distinguishable from the others.
- ragall 5mo agoWorking long hours due to incompetence is not a good thing.
- hirako2000 5mo agoI do believe in hardship. As sacrifice. It yields long term benefits for oneself, and for society. But submissions into slavery for immediate gain accomplishes little, and costs society a lot more (physical and mental health issues are a huge burden). Those parodies you saw, they were caricature of elite engineers, who sacrificed decades of his life to become so competent. Can work from home, eat pasta while glancing over a PR and just hit approve. That you resent the luxury doesn't make it undeserved privilege.
- pdimitar 5mo agoI've met programmers who severely outclassed me. It was extremely uncomfortable and it took me months to accept that reality and reshape my hurt ego into curiosity and desire to learn from someone clearly superior in the craft. That being said, most people in the privileged positions you described are there by sheer luck and connections. In the very very best-case scenario that offends them the least: they stumbled upon an opportune position and were smart enough to make full use of it... in the first 6 months (when people pay the most attention and lasting impressions are formed). And then rode the reputation they made for years. Their value as engineers on the team after the initial honest burst of productivity becomes... very unclear from that point and on, shall we say. Again, I've met engineers who fully deserved their privileges. 2-3 times over 24 years of career though (a good chunk of it as a contractor so I've been around). My anecdotal evidence obviously means nothing but we all develop pattern-matching skills with time, making me think what I saw is generally the statistical curve that would apply almost everywhere. Maybe.
- dominotw 5mo agowouldnt llm do all the tasks that determistic programs are doing. like chatgpt files taxes for you instead of using turbotax.
- WarmWash 5mo agoTangential side story, but an interesting one none the less. I was a food delivery driver back in the mid 00's to the mid teens. Early on, GPS was rare and expensive, so to do deliveries and do them effectively, you had to be able to read a map and mentally plan out efficient routes from the stochastic flow of orders coming out. This acted as a natural filter, and "delivery driver" tended to be an interesting class of people, landing somewhere in the neighborhood of "lazy genius". Higher than average intelligence, lower than average motivation. Then when smartphones exploded in the early 10's, the bar for delivering fell through the floor, and the job became swamped with people who would be best identified as "lazy unintelligent". Anyone who had a smartphone and not much life motivation was now looking to drive around delivering food for easy money. Not saying the job was ever particularly glamorous, but it did have a natural mental barrier that tech tore down, and the result was exactly as one would predict. That being said, I'm not sure end users noticed much difference.
- bojo 5mo agoI love this anecdote. It highlights what our industry continues to forget: The end user doesn't care. Don't get me wrong, tech is why I am here. But if it works, Alice and Bob don't care one bit about how the product exists.
- jbxntuehineoh 5mo ago> The end user doesn't care. well, they think they don't. until their pii gets leaked all over the internet because whoops our s3 bucket was publicly accessible, or until the service goes down because whoops our llm deleted the prod db...
- chickensong 5mo agoPII leaks are normalized now. Most people aren't even aware, or just shrug "oh well" and head to the app store to download the latest gacha game or whatever.
- pjmlp 5mo agoThat is why Alice and Bob get Electron apps, Webviews on mobile, mostly coded by offshoring teams.
- andy_ppp 5mo agoNot really - I imagine as with almost everything in life there's a normal distribution, in this case of the quality with which people use AI tools.
- DonaldPShimoda 5mo agoThe normal distribution doesn't account for things like "huge megacorporations pour billions of dollars into accelerating product adoption" or "other companies force their employees to use AI whether they want to or not" though.
- ZaoLahma 5mo agoI'm firmly in the LLM fanbase. Not because I can't type code (was doing it for over 17 years, everywhere from low level hardware drivers in C to web frontend to robot development at home as a hobby - coding is fun!), but because in my profession it allows me to focus more on the abstraction layer where "it matters". I'm not saying that I'm no longer dealing with code at all though. The way I work is interactively with the LLM and pretty much tell it exactly what to do and how to do it. Sometimes all the way down to "don't copy the reference like that, grab a deep copy of the object instead". Just like with any other type of programming, the only way to achieve valuable and correct results is by knowing exactly what you want and express that exactly and without ambiguity. But I no longer need to remember most of the syntax for the language I happen to work with at the moment, and can instead spend time thinking about the high level architecture. To make sure each involved component does one thing and one thing well, with its complexities hidden behind clear interfaces. Engineers who refuse to, or can't, or won't utilize the benefits that LLMs bring will be left behind. It's just the way it is. I'm already seeing it happening.
- deleted 5mo ago[deleted]
- ap99 5mo agoThis mindset is fine (it's mine essentially too). But it absolutely has to be combined with verification/testing at the same speed as code production.
- dgellow 5mo agoI generally do have that mindset, but over the past 1y of Claude code I do notice that I’m clearly losing my understanding of the internals of projects. I do review LLM generated code, understand it, no problem reading/following through. But then someone asks me a question, and I’m like… wait, I actually don’t know. I remember the instructions I gave and reviewing the code but don’t actually have a fine-details model of the actual implementation crystallized in my mind, I need to check, was that thing implemented the way I thought it was or not? Wait, it’s actually wrong/not matching at all what I thought! It’s definitely becoming uncomfortable and makes me reconsider my use of Claude code pretty significantly
- wallst07 5mo agoFanbase, maybe. Software engineers using these projects? Probably forking and updating themselves. FWIW, I've opened a half dozen PRs from LLMs and had them approved. I have some prompts I use to make them very difficult to tell they are AI. However if it is a big anti-llm project I just fork and have agents rebase my changes.
- jcgrillo 5mo agoYour employer allows/encourages this? Do you run that stuff in production? Would you mind telling us where you work so we can avoid using their products? It is just not possible to trust the software that emerges from the process you've described.
- redsocksfan45 5mo ago[dead]
- ejpir 5mo agoso, they are approved, which means they were most likely reviewed. yet you still think the software cannot be trusted of that and even want to name and shame a company. utterly stupid.
- jcgrillo 5mo agoYes. If a company is running vibeslopped compilers to build their production artifacts I absolutely want to know which one it is, so I can protect myself from their software. > utterly stupid That's completely uncalled for. EDIT: What exactly do you mean by: > most likely reviewed. Let's say every line was actually reviewed. That's still nowhere near good enough. The changes are being reviewed by the wrong people. Not the maintainers of the project, just some random folks who have inherited a vibecoded fork.
- varispeed 5mo ago"I aM someWhAt oF a DeVelOpER MySelF"
- nurettin 5mo agoYou can curb an LLM into doing what you want. Unfortunately people don't have the patience or the skill.
- sesm 5mo agoPeople who have skill can do the same without LLMs, maybe slightly slower on average but on more predictable schedule.
- dannyw 5mo agoI wouldn’t say slightly slower; LLMs are massively useful for software engineering in the right hands. For some personal projects I still stick to the basics and write everything by hand though. It’s kinda nice and grounding; and almost feels like a detox. For any new software engineer, I’m a strong advocate of zero LLM use (except maybe as a stack overflow alternative) for your first few months.
- Bridged7756 5mo agoIt's significantly slower to use LLMs for some things. The only thing it excels at is generic, broad tasks. Getting the 90% done. I find that it's less cumbersome to get it mostly right and touch it up yourself than to prompt over details like syntax.
- dgellow 5mo agoThe chat UX with a fake-human lying to you and framing things emotionally really doesn’t help. And it is pretty much not possible to get away from it, or at least I haven’t found yet how. I would love to see a model trained to behave way more like a tool instead of auto-completing from Reddit language patterns…
- zeeveener 5mo agoI'm personally amazed that _Large_ OSS projects don't have the appropriate automation in place to prevent non-compiling or non-linter-passing submissions. - Hooks (although there's no clean way to enforce they be "installed" on a clone), GHA Workflows (or their equivalents on other forges). This might be my bias showing, but these are items I would consider table-stakes for a project of a certain size / level of popularity. It feels like a lot of the "AI is shit at contributing" problems could be addressed in part by better automated checks and balances.
- jmcqk6 5mo agoThose things cost resources, and now you're introducing a new attack vector: open up a bunch of shit PRs, burn a lot of cash for the target organization.
- all2 5mo agoCan't you prevent pushing from the client side with pre-commit hooks? I would expect a hook to fire on the developer's computer that prevents them from even committing/pushing (unless they nuke the hook in their local repo copy).
- 0xffff2 5mo agoYou have to manually install hooks in your local repository. They aren't propagated as part of the repo. Git has intentionally made hooks require a very explicit opt-in.
- all2 5mo agoOh, good to know. I haven't used them much, so I'm a bit ignorant as to how they work in larger projects.
- zeeveener 5mo agoYou're right. It doesn't solve for all scenarios and doesn't block malicious actors. I do believe, however, that it would have a meaningful impact on the "drive-by" PRs that keep being used as examples; the thoughtless, throw-spaghetti-at-the-wall PRs that do not have malignant intent behind them. Many large OSS projects would have the resources to eat that cost with Donors, Sponsors, and OSS hand-outs. That's why I clarified in my original post because I know this is not a general solution.
- api 5mo agoThis is a spam problem more than anything else. It's not really an AI problem except that it's AI that is enabling this new type of spam. Imagine there's no AI, but for some reason you have people hiring armies of cheap overseas devs and using them to produce mediocre quality drive-by PRs. The effect would be the same. AI can be used to make quality code, but that requires careful use of the tool... like any other tool. This isn't careful contributions made by someone who knows the project and its goals and is good at using the tool. This is spam.
- colordrops 5mo agoExactly, people could have "consulted Google" or "consulted stack overflow" and had the same issues. It's about the end result, not how the code got to that end result, and the submitter is responsible to make sure of the quality of the submission regardless of whether AI was used or not. To reject submissions where the dev "consulted ai" is like rejecting iron ore that was mined by a machine rather than a human. The quality of the ore is what should be measured, not how it was obtained.
- api 5mo agoI agree, but the problem comes back to how to evaluate quality at scale. That is very hard. It’s easier to just say no AI because that at least turns off the fire hose.
- colordrops 5mo agoIt sounds like they are even rejecting submissions where they even get a whiff of ai being "consulted" though. That's not quite the same as turning off the firehose.
- api 5mo agoNo that’s just reactionary. The discourse around AI in the arts, and other creative and craft fields, is utterly identical to the discourse around photography when it came out to the point that you could search and replace terms and have the same dialogue.