4 ms·
It’s interesting how AI may both raise and lower the quality of software. It’s very easy to send an AI agent on an open-ended bug hunt, and if it wastes a bunch
by dabinat 1mo ago
It’s interesting how AI may both raise and lower the quality of software. It’s very easy to send an AI agent on an open-ended bug hunt, and if it wastes a bunch of time and effort and finds nothing, no big deal. Time is much more important for a human developer with a salary.
- Supermancho 1mo agoI don't care if you call it an over-engineered looping machine or what, there are concrete benefits to using LLMs for this. They work faster than developing your own looping algorithm and more often produce useful results than not.
- saghm 1mo agoIt's not even like fuzzers are valuable because of the process they use specifically either; the value is that they produce a concrete input that you can use as a reproducible test case at that point. The value could be produced by gazing into a crystal ball for all I care, as long as I can use what it gives me to reproduce a bug.
- dmix 1mo agoFinding the bugs with LLMs is easy. Reviewing the output, cleaning it up, and making sure it doesn't break something else is the hard part.
- deleted 1mo ago[deleted]
- bewareofscams 1mo ago[flagged]
- shevy-java 1mo ago> LLMs do find bugs, do save time They find bugs but whether they save time is nowhere near as clear as you try to insinuate here.
- pixl97 1mo agoThey save time in finding bugs.
- lukan 1mo agoAnd for me they also save time in fixing bugs.
- owebmaster 1mo agoUnless it's finding a bug it added then it's time wasted x2
- hombre_fatal 1mo agoThe missing part of this is that verifying the bug with LLMs is also easy, and so is adversarially reviewing the proposed fix with LLMs. The only thing left for you to do should be directional decisions. The LLMs should pause and rope you in if the fix involves directional/invariant changes.
- deleted 1mo ago[deleted]
- nonethewiser 1mo agoNo one can keep up with the volume of code AI produces. We wont stop using AI. We will use AI to check AI. Of course this is crazy, but it will also unlock pretty insane scaling and productivity and ultimately we will manage it on either end via requirements and tests.
- krona 1mo agoYou're suggesting that LLMs get better at fixing bugs/vulnerabilities, but at the same time stop getting better at finding them? What if this difference is inherent and essential?
- TacticalCoder 1mo ago> You're suggesting that LLMs get better at fixing bugs/vulnerabilities, but at the same time stop getting better at finding them? Are you implying that all code writing by LLMs atm is bug-free?
- krona 1mo agoAbsolutely not. By most accounts they're terrible at fixing anything other than trivial bugs in complex codebases e.g. Linux kernel, but they're much better at finding them.
- black_knight 1mo agoThis is where I believe strong typing (like, Haskell-strong or stronger) and functional programming in general will be a win. The confidence I have that my fixes are localised when fixing Haskell code is infinitely stronger than fixing even Java, not speak about C, code.
- astrange 1mo agoHaskell's type system would not easily prevent this bug. It's not good at numeric/logic issues like that. When people say "Haskell makes it impossible to write bugs" they mean "Haskell has enums" (ADTs).
- black_knight 1mo agoI am not claiming you cant write buggy code in Haskell! But following good functional style, your bug will more likely be compartmentalised, and fixing it will not break some other part of your program.
- StilesCrisis 1mo agoYou can write good functional code in many languages. (Even C++!)
- black_knight 1mo agoSure! I have done my fair share of pretending Java and C++ support my functional style. But at the end of the day, you have better support for writing that style in a real functional programming language. And I wonder how well one can enforce a functional style in say Java or C++ upon the LLMs. Who knows, they might be great at it?
- _jackdk_ 1mo agoLiquid Haskell might require you to prove that the divisor is nonzero, but even in standard Haskell there's common idioms for ensuring that a list is non-empty (data NonEmpty a = a :| [a]) or that text is non-empty (newtype NonEmptyText = NonEmptyText Text, with non-exported constructor, helpers like make :: Text -> NonEmptyText, or more advanced tricks like https://exploring-better-ways.bellroy.com/haskell-koan-type-checked-non-empty-strings.html https://exploring-better-ways.bellroy.com/haskell-koan-type-... ). The big problem preventing this approach from working for numbers is that it's just so cumbersome there. Most of this is because all the arithmetic operators are bundled into a single Num typeclass, and `fromInteger :: Num a => Integer -> a` has a type that's impossible for a "non-zero number" wrapper to satisfy.
- macless 1mo ago[flagged]
- sadfgknerknksdf 1mo agoIf finding the bugs with LLMs is easy. Then making sure it doesn't break something else is just LLMs finding no bugs. Easy.
- BikiniPrince 1mo agoThat hasn’t been that bad. My real issue has been the time sink involved in following along with the maintainer and jumper through their hoops. Even after I demonstrate a flaw and a potential fix. My schedule is just so busy I need to pencil in time to deal with them.
- eviks 1mo agoBut what's your expectation of the net?
- shevy-java 1mo agoI dislike AI, but if AI finds real bugs then this is in my opinion objectively a positive thing. Of course the question is what constitutes a real bug.
- pixl97 1mo agoUnfiltered models will help build exploits for the bugs they find, so there is some means of measuring their efficacy.
- klipt 1mo agoIf you're just talking about security bugs. There are also non security bugs that don't have exploits but just make the user experience worse.
- hn_submit 1mo agoA.I. is useful for this. But it would be even more useful if all new code were written in Rust or some other memory-safe language. A.I. could also be used to port C/C++ codebases to Rust, which isn't economically feasible at the moment.
- senderista 1mo agoAI will have plenty of security bugs left to find in Rust codebases.
- Spivak 1mo agoI mean I get the sentiment but Rust won't save you against division by zero, it'll just panic at runtime like every other language.
- Gigachad 1mo agoFrom a security perspective, panic at runtime is not that bad for security. Much better than continuing to run with undefined behavior. If someone sends a malformed video in and it crashes the ffmpeg process you can just log it and restart it. Vs potentially exploiting the system.
- evenhash 1mo ago> It’s very easy to send an AI agent on an open-ended bug hunt, and if it wastes a bunch of time and effort and finds nothing, no big deal. No big deal? It’s not like it’s free… tokens cost money.
- rogerrogerr 1mo agoOften rounds to free compared to human costs.
- deleted 1mo ago[deleted]
- UltraSane 1mo agoWhen talking about LLM tokens the cost is almost always being implicitly compared to very expensive human developer time.
- simonjuk 1mo agoIn my experience, there are two ways to use AI: speed or quality. Speed is where you give the AI a task to do and you review it; quality is where you write the code yourself and you get AI to review it. Both are valid for different situations.
- merb 1mo agoMy plan for bigger things is mostly: Generate multiple solutions- they do not to work 100% correctly. And than I check which I would prefer. Which is more to our applications taste. And than I would take the vibe output as a kind of a ‚plan‘ which I use to implement but not follow 100% and at the end I take my solution and review it. I gain speed with that because I often can quickly see the pros and cons of a solution way better than when I would manually do it and hang on a major roadblock and also I even see such roadblocks in the vibe output - it’s mostly the part with an unnecessary amount of new code that looks nonsensical.
- UltraSane 1mo agoUsing a LLM whose output is slowed to the rate of a human programmer as a pair programming partner is a very interesting experience.
- DarmokTanagra 1mo agoHaving worked in a few vibe coded codebases over the last few years I can safely say that AI is not raising the quality of anything.
- tikotus 1mo agoI had the same knee-jerk reaction. "Did I read that correctly?" But yeah, I guess it can be used to increase certain aspects of quality by letting them go wild. But I think I mostly hear about security or crash issues. In my experience they don't outweigh the number of other issues they cause. Like UI bugs. I've seen more than one service constantly rolling out features that are completely broken, just to have a completely new, still broken, solution available the next day.