4 ms·
If you think vulnerability research simply doesn't matter, you have a lot of company in that opinion. It's something Bruce Schneier used to argue, and Marcus Ra
by tptacek 18d ago
If you think vulnerability research simply doesn't matter, you have a lot of company in that opinion. It's something Bruce Schneier used to argue, and Marcus Ranum, and a bunch of other people that used be on closed secret vulnerability-sharing mailing lists before Bugtraq blew those cliques up. These are very old arguments.
But if you do think vulnerability research matters, and you're trying to argue that frontier models aren't a seismic change for that discipline, you have almost no company. Vulnerability researchers are overwhelmingly leaning on automation to find vulnerabilities and, just as importantly, generate the tooling required to test hypotheses.
You can feel about that however you want to feel about it. I mostly don't care, except: you can watch people like this being negatively polarized back into the bad old days of the mid-1990s, content-free CERT advisories, and vendor-controlled "responsible disclosure" by a use case that frontier models unimpeachably excel at.
- jeremyjh 18d agoIt’s amazing how half the developers on earth live on a completely different planet now. There are plenty of new challenges, sure but we are far past the point where we can have a debate about “is it useful?” And yet we continue to do so. I understand the feeling of loss some people may be facing. And there are definitely some really bad practices - like nakedly spewing claudspeak at your colleagues instead of communicating. Or raising a PR you don’t understand. There are asymmetries we haven’t learned to navigate. But we aren’t returning to a world where it doesn’t dominate our discipline so it’s best to find opportunities.
- vermilingua 18d agoThe question most of us are asking isn’t “is it useful”, but “is it worth it”. Engaging with these tools involves no small amount of self-debasement and long term degradation of skills; do I want to sacrifice myself on the altar of productivity? For me the answer is still absolutely resolutely “no”.
- akerl_ 18d agoYou’re already using a computer to automate massive amounts of what used to be manual human effort. Why is using AI tools self-debasing or degrading?
- preg_match 18d agoBecause AI removes you from analytical thinking, and the brain is a muscle. The less you think, the less you are able to think. Programming is inherently analytical and logic-driven. It’s a great brain exercise, even if the code has no value. When you use AI, you lose that exercise. What replaces it isn’t the same. I mean, consider. I can solve a crossword, or I can ask AI to solve the crossword. AI will do it perfectly, and faster too. But which one is better for my brain? What was my goal with solving the crossword, anyway? On the surface it was to find a solution to the crossword. But, maybe, deeper down, the goal was to improve myself in some way. People conflate the improvement of products with the improvement of self. Maybe it’s a result of our consumerist mindset. But the truth is the product can improve greatly, and you can be making it, while you yourself degrade. We write better and better code, at a faster rate, but are we better programmers than before? Maybe, maybe not. I’m leaning maybe not. It’s not new or unique. The assembly line is the same. Sure, I can build better furniture faster at the factory than by hand. But what is the goal here? Is it to make the best furniture, or to become the best carpenter? If it’s to make the best furniture, the best product, then I’ve won. If it’s to become the best carpenter, then I’ve lost heavily.
- akerl_ 18d agoThe best carpenter obviously doesn't use any power tools. Are they allowed to use hand tools, or do they need to split the wood with their bare hands? It's not clear to me why programming is inherently analytical and logic-driven but prompting and iterating with an AI is not. What about Applescript, where it's programming but in something closer to natural language? The core of this seems to be that there are people who assume that users of AI turn their brains off the moment they open a Claude prompt. There are surely some people who are doing that, but there were also plenty of people who were shipping sloppy code before. There are far more people for whom this another tool in their toolbox.
- bigstrat2003 18d ago[dead]
- anon7000 18d agoThe bigger challenge is that the mechanics of the day to day work have entirely changed. Mechanically, using C is similar to using JS. You’re tying and compiling and checking results, whatever. With an Agent what you actually do is completely different. Even as technologies have changed in the past and people have learned more, your mechanical day to day work would look similar, just with different tools. Not so with AI. So it should be utterly unsurprising that many people are going through a bit of an existential crisis around this. Because what you actually sat down and enjoyed doing, what motivated you, may be entirely gone now. And on top of that, there’s an extreme amount of pressure to do more in less time, which is by definition stressful. And do much more context switching.
- jeremyjh 18d agoI’ve often spent more of my time reviewing code than writing code off and on for decades as my role and team size changes. So, none of this is new to me except that the loops are much tighter and I don’t have to debate the social cost of pointing out what is workable but not acceptable after the 4th review cycle when I suddenly notice something new in code that had been there all along. The truth is a lot of developers are terrible at reviewing design specifications and code. They rarely - if ever - find any real correctness issues and more than half believe it’s mostly a status / dominance game. Many can’t force themselves to deeply think about the code if they aren’t writing it.
- archagon 18d agoMaybe it’s worth actually listening to what these people are saying, or you may find yourself increasingly frustrated and confused as these debates intensify and AI becomes more politically and socially toxic.
- jeremyjh 18d agoI've heard what they are saying, and a lot of it is factually untrue and confused. I wasn't happy about all of this when it first began happening, yet wasn't working. But once it was actually working, I realized I wanted to build software more than I wanted to craft software. Some people want to continue practicing their craft, which is a fine thing to want. But don't pretend its anything else.
- archagon 18d agoAs I see it, "engineers" going all-in on AI are missing two fundamental truths of our profession: * Writing code is a form of communication, as well as a process through which complex systems are thought through, understood, and formalized. * Complexity is managed by building on top of robust, deterministic abstractions. Vibe-coders deny the need to understand complex systems and pretend that AI is a new layer of abstraction. I think that both of these perspectives are dead wrong. This remains the case even if LLMs are marvelously good at generating code. Put another way, software engineers who mostly deal with code through their agents have switched careers from engineering to some form of management, even if they deny it to themselves. In no way does this deprecate the field of software engineering. And then there are the externalities which have been discussed ad nauseam at this point, and remain as true as they ever were. (Economic, environmental, political — take your pick.)
- jeremyjh 18d agoNot everyone using coding agents is vibe coding. I still review code until I understand it, judge the tests cover it, and that it is the right way to do it. They constantly make mistakes like over building, handling contingencies that can't exist, duplicating code etc. Its still MUCH faster than the alternative. I've been working this way for decades. It is not different from reviewing human code and designs except the loops are much tighter, and refactoring is so much cheaper. There may be a lot of people who can't do this work effectively, but the thing about skill issues is they can be improved if they are recognized for what they are.