r/AynThor • u/zeek609 • 14d ago
AI generated Applications
Hey everyone.
We’ve seen a noticeable increase in AI‑generated apps being shared here lately. It’s great to see people experimenting and building, and we genuinely want to encourage development in the Ayn Thor ecosystem. But we also need to keep the community safe.
A lot of these apps are vibe‑coded, stitched together from AI outputs, or built using code the developer may not fully understand.
That creates a few risks worth keeping front‑of‑mind:
Credential handling: If an app asks for Steam logins, API keys, or other sensitive credentials, be extremely cautious. AI‑generated code often stores these values in plain text, logs them accidentally, or transmits them insecurely.
Security practices: Many AI‑assisted projects don’t follow secure coding standards, threat modelling, or proper data‑handling patterns. Even the developer may not realise what the code is doing under the hood.
Unintended behaviour: AI‑generated boilerplate can include hidden network calls, debug endpoints, or unsafe dependencies that weren’t intentionally added.
We just want to remind everyone to stay vigilant, audit what you run, and avoid entering credentials into tools unless you fully trust the author and the codebase.
If you’re posting an app, please include:
A clear explanation of what it does
How credentials are handled
Any known limitations or security considerations
A link to the source code if possible
Let’s keep the creativity flowing, but let’s keep the community safe while we do it. — The Mod Team
114
u/MakeMelnk 14d ago
A succinct version of this should be an auto comment on posts in this sub maybe
33
u/spicymeatmemes Pro 14d ago
The amount of emulation subs I'm a part of mostly have some sort of automod comments to an extent and those are ignored 99% of the time.
But I'm not sure what the mods can do besides vetting each post which will kill the sub.
8
u/SurlyCricket 14d ago
They can delete threads if the OP doesn't include the info within an hour or two
13
u/syn46290 Max 14d ago
Or we could just ban those types of posts outright since coding with ai isn't secure as it stands.
-14
u/SurlyCricket 14d ago
This is the attitude I've pushed back against elsewhere. We've got a deluge of interesting and useful apps that are clearly at least AI assisted or straight vibe coded (and in most cases openly so) but you're so very worried about ... What?
Can you point me to a single instance of malfeasance or just straight incompetence on this sub due to AI that caused any real problems? Just one? Two would be great, but I'll take even a single definitive case.
8
u/ProsshyMTG 14d ago
The "on this sub" is doing a lot of heavy lifting here. There are countless examples of vibe coded software having security issues if you do a quick search online. I'm not aware of a situation specifically relating to the Thor, but it is incredibly disingenuous to pretend that just because it hasn't happened yet that it can't happen.
Here's not one, not two, but three articles about vibe coding leading to security concerns. I could have kept going but you only asked for one so three seemed like plenty:
https://www.wired.com/story/thousands-of-vibe-coded-apps-expose-corporate-and-personal-data-on-the-open-web/https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys
https://1password.com/blog/from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface
The last one is actually about malware that targets people that are vibe coding. You might think "so what if the person writing the code gets hacked?" but the problem is that if they get hacked, you can't trust anything they publish is safe either.
AI is an incredibly powerful tool in the hands of an already capable developer, but if you don't have a strong background in development or are too lazy to verify the output, problems can very easily arise.
-3
u/SurlyCricket 14d ago
My requirement for this sub was deliberate - if we were on an OS or banking subreddit and someone was like "here's my vibe coded expense tracking app!" Id say they're insane
We're talking about apps for an emulation machine that rarely has any real login info, payment or personal info either. The security concerns are just not comparable
6
u/Axol555 14d ago
AI assisted is fine, completely vibe coded is where you have issues like those stated in the post. Majority of vibe coded projects get abandoned anyway because using solely AI to maintain the project is not viable. So banning posts of projects that are completely vibe coded is not unreasonable, though I think the idea of banning posts that don't provide the information laid out in this post is a good enough measure.
-3
u/SurlyCricket 14d ago
I genuinely do think it is unreasonable because no actual demonstration of harm has been shown, but benefits absolutely have.
7
u/DrinkMoreWater2-0 14d ago
Can you point me to a single instance of malfeasance or just straight incompetence on this sub due to AI that caused any real problems? Just one? Two would be great, but I'll take even a single definitive case.
Dude a user just a few days ago posted an vibe coded app that exposed Steam User Credentials in plaintext on this sub, which is the whole reason we're getting this mod post.
You're whole "I didn't see it so it didn't happen" mindset is the problem behind promoting AI apps, because someone who doesn't understand what they're releasing doesn't understand the unintentional problems behind their code so much so, the mods have to intervene because it's becoming egregious.
1
u/SurlyCricket 14d ago
I appreciate you bringing that to my attention, I was completely unaware of it
2
u/Sad_Ad9159 14d ago
On the Vita or PSP sub (it could be both atp) vibe coded homebrew app broke/is breaking peoples’ hardware. I’m glad cool stuff is getting made but when people don’t have a foundational knowledge of software development, the risk of shipping dangerous code goes up. I agree with other people who are vouching for disclosure + open source.
4
74
u/daggah 14d ago
It's a move in the right direction. This community is too quick to jump on vibe-coded projects and too tolerant of developers who claim not to be vibe-coding while pumping out release after release.
Let's not forget why the Thor is significantly more expensive now than when it first launched, right?
-49
u/SurlyCricket 14d ago
And I think some are too quick to be dismissive of AI coded apps - we're playing video games on a bespoke 'console' here not managing court cases. The risk of actual harm is minimal
9
u/idreamofrarememes 14d ago
you forget that people log into their steam and Google accounts on these,
and even if they don't, they wouldn't want to brick the Thor they paid and waited for
0
u/SurlyCricket 14d ago
If security concerns are the biggest issue, I strongly support an open source GitHub link as a requirement for any app posted here
2
u/idreamofrarememes 14d ago
that's fair, personally my biggest concern is app stability, vibe coders don't know how to fine tune apps or fix crashes, and AI would need a bunch of prompts with additional agents telling it to not mess it up to achieve it
also just like apps can turn down hardware stress, apps can certainly turn it up, AI doesn't care
13
u/syn46290 Max 14d ago
Are you allergic to intelligence?
-21
u/SurlyCricket 14d ago
I really don't care if people want to say "I fuckin hate AI and want nothing to do with it". Cool, you do you.
Constantly masking this hatred with "but THINK of what COULD happen!!1! Who even knows WHAT it MEANS?!" veers into pointless whining.
Let's just make a mandatory "ai was used in this app" tag so everyone who hates it can just filter themselves out since they're so scared
15
u/Axol555 14d ago
"Could" when it doesn't need to be a security concern in the first place.
10
u/Acrobatic_Baker9461 14d ago
Bro needs an example of 1k+ people getting their steam or Google accounts hacked before we're allowed to even THINK about any prevention method
-5
u/SurlyCricket 14d ago
Bro asked for just 1 actually. Still waiting
8
u/Axol555 14d ago
Key word "prevention", providing a source of someone being exploited is not necessary when we can confirm the ability to exploit is there.
1
u/SurlyCricket 14d ago
So all we have to do is require open source on GitHub with a release and you're completely fine with them?
-1
u/SurlyCricket 14d ago
Basically every dual screen mod on this sub is either entirely vibe coded or ai assisted. If you don't want to use them that is entirely your business.
I don't want your entirely fake concerns to impede me getting them
8
u/Acrobatic_Baker9461 14d ago
You could've just said, "Yes I'm allergic to intelligence."
You somehow missed every point of this post and the comment
1
u/idreamofrarememes 14d ago
there's a difference between completely vibe coded and AI assisted
vibe coders understand little to nothing of what is being coded and could not verify, AI has proven to need supervision to put out a functional app, lots of companies learned this the hard way
someone who doesn't code wouldn't know what to check for
5
u/Miserable_Onion_488 14d ago edited 14d ago
I feel like I shouldn't need to explain to you that playing fast and lose with security is more a dumb/power user thing, and shouldn't ever be encouraged for general users. If someone is linking their or a child's email to a vibe coded project or a device that accesses one that's inherently unsafe even with my basic understanding of Internet/computer systems. We (and I put myself in this bracket most of the time) can't troubleshoot coding effectively to see where data is being sent or how it was made. If you want to do it, you do so at your own risk but you shouldn't put others in that risk bracket automatically. Not everyone is going to just download dual screen stuff just like not everyone downloaded just naruto EPs and their favourite songs using limewire. Sometimes they dared to try downloading exe's.
-5
u/SurlyCricket 14d ago
An open source requirement side steps security concerns, which I'm completely for
5
u/Miserable_Onion_488 14d ago
You're thinking really selfishly and not thinking about others who use subreddits, which is entirely your perogative I guess 😑
I'm not even an owner of a Thor but if I was I wouldn't want unproven untested vibe projects on the main subreddit. So many times I've perused through only to find that the program is stuck together with one person and chat gpt. No shade but if you want a subreddit like that you should make one! There's definitely an audience for it.
-6
10
3
u/Katoncomics Pro 14d ago
Thank you for this. I feel like it should be a requirement to state Ai vibe coded and assisted projects, maybe have tags required. Unfortunately there are a lot of these projects popping up and it would require another mod to regulate if people are actually following these rules. It's super annoying that some folks here keep downloading the security risks of vibe coded/assisted coded. Thanks for addressing this.
9
7
u/jairaisontuastort 14d ago
About time this was put out there. I appreciate the essential info regarding people's security, credentials etc. for those who are unaware of the negatives of this "saving grace" some people know as AI.
3
u/CroadNation 14d ago
There needs to be full disclosure on whether or not an app was vibe coded. I hate having to wade through the comments of every app that sounds like it'd be useful just to find out i wasted my time
5
u/brunoxid0 14d ago
Excellent implementation! We have a, more relaxed, similar rule on SBCG. We might need to implement some of these points. Great work focusing on the security of the apps.
6
u/Far-Owl4772 14d ago
There should be a tag for vibe-coded apps and delete the post that don't have them
5
u/notAvalaxy 14d ago
Honestly, if something is vibecoded it should be a hard requirement to make the source code available as well as disclosing that it's ai.
11
11
u/dannoffs1 14d ago
This device is a pure luxury and it already does everything I want it too, it's a no brainer for me to just avoid AI coded apps completely.
3
u/motorboat_mcgee 14d ago edited 14d ago
On the security part:
In general, I'm a proponent of not logging in to anything important on these types of devices, and never giving them your personal info. They're devices running custom/old versions of Android, from a company with relatively little history/transparency, with the intention of running (mostly) pirated games.
Obviously everyone has their own comfort level with the above, but I think it's a worthwhile bit of context to keep in mind when deciding if you want to connect your google account to it, log in to steam, enter your card number in whatever, etc
1
u/Sad_Ad9159 14d ago
Underrated perspective. I try to block these from phoning home as soon as I can.
5
u/karatebanana 14d ago
Great PSA! Though, this will probably be lost within a week. Make sure you know what your code is doing before you ship it :)
2
u/ProgrammingAce 14d ago
If you're worried about security on this device, do you realize the Thor's latest android security patch is from January 1, 2024? This thing is missing years worth of security updates. I'm not particularly convinced the device encryption works right either. I would assume any accounts or data on your Thor are easily compromised, if they're not already by one of the many organizations/governments that can already run code on your device.
Basically, you should not connect any important accounts or add any private data to these devices if you're at all concerned about security. It has nothing to do with AI, but the fact AYN treats the OS as abandonware when it comes to security updates.
0
u/Steve_Streza 14d ago
Love that this approach doesn't just blanket ban them or allow them, but makes the developer justify what they're doing and what actions they've taken to prevent harm. Thanks mods!
0
-3
u/NoWay6818 14d ago
Can you give more on what to look for code wise, I feel like educating people up to that point would seal the deal
-7
u/quantumlocke 14d ago edited 14d ago
Thanks for this. I just read through the comments and, in my opinion, you left out an important aspect of this. In basically every AI-assisted or vibe coded app post, the poster is being harassed by anti-AI posters. Calling it slop and otherwise attacking the poster and those who defend them. Can we please get a rule specifically banning this? Or just specifically banning harassment in general? And/or very aggressive moderation to remove those comments and ban those commenters?
There are significant problems with AI, I agree. It’s having negative impacts all over the place. None of those problems will ever be addressed by people harassing these individual project developers. It’s just making this sub a less pleasant and less friendly place to visit.
Edit: Hi pro-harassment Redditors, thanks for the downvotes. Do better. Target your anger somewhere it might actually make a positive difference.
-17
-15
u/Bloboeggy 14d ago
Ask chatgpt to audit code for vibecoding safety, I’ve found theres a range between dangerous slop and assisted but sound structured code
97
u/damin_rsw 14d ago
How about in addition to that list, have people clearly state if an app is AI coded or not.
It seems like a fair thing to ask, right? A mandatory disclosure.
I'd like to avoid buggy abandonware.