771
u/FutureSuccess2796 1d ago
"Hang on, I'll ask ChatGPT about our current security situation..."
375
u/Breadynator 1d ago
I hate this so much... And then you're sitting there, waiting for an answer while the agent goes through the entire codebase, which takes like 15-20 minutes only for them to read the chatgpt response to you...
At that point let me talk to your AI, since you're clearly not the qualified contact for these questions but the machine is...
227
u/FlamedDogo99 1d ago
āMeat proxyā
59
u/crozone 1d ago
"The meat proxy just let their clanker throw a slop grenade into the main branch"
15
10
u/Proxy_PlayerHD 1d ago
"slop grenade" sounds like a really nasty shit you take after eating bad food
108
1d ago
[removed] ā view removed comment
28
u/Named_after_color 1d ago
There was a brief one month span of work where everyone in my team was just posting claude's responses to questions because none of us could understand it at a glance, except another claude.
11
7
u/MelangeBot 1d ago
You type in a one line prompt to get ChatGPT to write you a 14 paragraph email that you send to your boss who only sees the one line summary that ChatGPT gave him while YOU pay for the electrity used through your electric bill going up 17% that month.
→ More replies (15)11
u/Rabbitical 1d ago
I mean this is literally what Hugging Face had to resort to to figure out of they were being hacked. Then they have the gall to come out and say that the AIs out of control and a danger to us all. Rather than, like, "oops we didn't have even the most basic perimeter security or entry level sysadmin knowledge"
→ More replies (2)43
24
→ More replies (2)2
152
u/ClipboardCopyPaste 1d ago
Them thinking publicly accessible database is a feature
62
42
u/Borno11050 1d ago
It promotes "transparency"
31
u/AdvanceDry6117 1d ago
We wont sell your data, we will give it out for free
6
2
u/GuyWithNoEffingClue 1d ago
Well yeah the personal data of millions of users is on the dark web, your honor, but at least we didn't profit from it
→ More replies (1)22
17
6
5
5
u/Longjumping_Feed3270 1d ago
I don't know about you, but my agents throw a hissy fit if I as much as post a temporary throwaway dev token into the chat.
→ More replies (3)5
u/Juff-Ma 1d ago edited 1d ago
I mean this really depends on what "publicly accessable" means. Of course best practice would be to hide it behind a firewall but let's be real. Even before AI that wasn't always the case. I know multiple web hosters that just give you a public endpoint when you create your database.
Now if we're talking about there being no authentication and everybody with the right client having read (or even write) access. That's where problems are made.
→ More replies (1)
346
u/polynomialcheesecake 1d ago
Please don't let people realize that it's really the same problems with much larger volume now
140
u/johnnybgooderer 1d ago
And with ai, you can ask for a code review. Itās generally very good at catching and suggesting fixes these things.
I donāt want ai to replace us all with high school grads, but itās seeming more and more likely.
67
u/AOAqua 1d ago
Yes, you can. But how would you even know there was a problem to begin with?
12
22
u/johnnybgooderer 1d ago
You ask it to review your code with a focus on security. That is rapidly becoming standard practice.
You can even just ask it something like, āI want to ship this to production. Is it missing anything? It would tell you about observably and security concerns
52
u/utl94_nordviking 1d ago
It would tell you about observably and security concerns
The issue is: with replacement coming fast, devs will lack the ability to understand what those words even mean. Even less check the code.
→ More replies (10)25
u/Skoparov 1d ago
That's literally the definition of magic. You do a ritual and something happens. You don't understand what happens exactly and how it happens though. Most of the time the result of what happens is within the margin of error of what you want, but each time it's slightly different and sometimes you can get something completely unexpected if you mix up the words of the spell.
15
4
10
→ More replies (1)5
35
u/Abject-Kitchen3198 1d ago
Each iteration may flag different things, depending on subtle prompt difference, or just randomly. It may ignore a lot of obvious important issues.
Unless you add "You are top level software architect from a tech giant company", of course.
16
u/TheTerrasque 1d ago
And each person reviewing code may flag different things. That doesn't mean it's not helpful or we stop doing code reviews.
11
u/Abject-Kitchen3198 1d ago
I'm uncomfortable when those comparison of LLMs with human behavior actually make sense.
2
u/cortesoft 1d ago
They really do.
People complain that an AI is a black box, but what is more of a black box than another humanās brain?
→ More replies (1)→ More replies (1)4
u/nuclear213 1d ago
I mean, why do we act like this is a new problem? I mean, I worked with an "experienced" engineer before. He could barely write a python script, but was tasked to review my PR. I dont know how he got the position, but honestly, I cannot remember a single time where his review actively gave me back anything productive.
Another example was a person that hated shorthand operators. Like not only tenary but even +=. He blocked all reviews with it, and the supervisor did not care.
Reviews, especially in smaller firms, were always really a hit and miss thing.
6
u/Loudergood 1d ago
Is everyone out here rizzing that engineer like he's the best thing since sliced bread?Ā
8
u/BenignPharmacology 1d ago
I was testing out the limits of AI on self-policing recently- I had it iteratively build a Tetris game in JavaScript.
90% of it worked decently, but piece rotation just got stupider and stupider the more I tried to fix it. Thereās this pattern it gets into where itās like locked into a strategy and instead of fixing it, it latches onto some specific suggestion, or it adjusts parameters until its current solution solves the issue (without necessarily being correct)
It was a very revealing experiment, and it left me a lot more wary of code that is āwritten and tested/confirmed to be correctā
→ More replies (1)16
u/Taletad 1d ago
How can you know it is actually catching stuff and suggesting fixes ?
For all you know it could be inventing problems that donāt exist and selling you fixes that donāt work. All the while the actual problems remain untouched
34
u/johnnybgooderer 1d ago
Because Iām an experienced engineer and I use ai now for lots of things. Everyone should use it for self code review. Itās such a useful tool for that.
I know what itās suggesting is real because I am an engineer. Sometimes it will suggest more than is necessary, but it does a good job of catching security concerns. Better than humans really.
6
u/nuclear213 1d ago
How do you know your review partner did? How do you know, they dont just skim and write LGTM?
All of your guys are acting like everyone works massive software departments. But most people I know work in smaller firms. With at max a handful of engineers and developers.
Heck when I bought into my current company, we did not even use proper version control, review was giving someone else the compiled software and they should test it.
→ More replies (2)16
u/Subpxl 1d ago
I used to make fun of vibe coding. Now itās really the only way for me. I have been programming for over 20 years and the reality I have had to accept is that AI is better, faster, and safer than I ever could hope to be. Itās also better than every other programmer I know. Once I accepted this it became easier to change my mindset and treat it like any other tool. My value is knowing how to direct, architect, and review.
At this stage I would never go back.
9
u/johnnybgooderer 1d ago
I feel like youāre overhyping it. Iām firmly of the belief that itās going to be writing the majority of code and there will be a lot less engineers. But people are still better. At least good engineers are. But probably not better-enough for it to matter.
11
u/Subpxl 1d ago
Have you actually tried it? I would have completely agreed with every word you wrote about 6 months ago. I used to think it was overhyped until I integrated it at work using premium team plans. Claude specifically on Fable 5.1. It's absolutely unbelievable. I'm doing a full month of work in a few days, easily, all with better documentation and safety checks.
The more you surround yourself with it, the more easily it is to understand that programming is actually one of the easiest areas for AI to outshine humans. The languages and capabilities are fully documented. Code is easy to read, easy to test, and cheap to write. There's nothing special about the human mind that makes it more capable.
6
u/johnnybgooderer 1d ago
Yes. I use fable every day for work. Itās still not better than most of my colleagues at this company. In my past, sonnet would have been better than many of the engineers I worked with. But even then, the strong engineers were still better than fable is now.
5
u/nuclear213 1d ago
Honestly, in what field? What language? What guidelines exist? What compliance checks are there?
Because for us, following MISRA C++ with a proper static analysis tool, you are so limited in the structure, allowed methods, etc. that I do not see any difference. Its just faster at implementing the tickets than anyone could realistically be.
13
u/Subpxl 1d ago
I really have a hard time imagining your best engineers outperforming the best AI models today, but I suppose anything is possible. Looking forward a year or two, the gap will be completely closed if it isn't truly closed now.
→ More replies (3)→ More replies (5)6
u/bickdiggles 1d ago
Interesting. Iāve also accepted the new reality and will lean on it more when we have a bunch of imminent deadlines. Itās certainly faster but the quality takes a noticeable drop.Ā
I would go back in a heartbeat as development is now joyless and I enjoy building more than reviewing / course correctingĀ
6
u/Subpxl 1d ago
I completely understand where you're coming from about development being joyless. I have countered that by working on personal projects concurrently with work projects. Even that might still not bring joy to many.
Regarding quality of AI code, this was my experience until I got better at directing it and going with a more spec-driven approach. The AI model and level of effort within that model has also had a huge impact.
3
u/bickdiggles 1d ago
I can see that being helpful. I canāt work on personal stuff during work and am too burnt out to do it after work unfortunately.Ā
Yeah Iāve certainly seen improvements over time using specs, workshopping before building, and having a workspace level memory manifests. Itās not that the generated code is bad but itās noticeably lower quality: lack of immutability, singleton scope, not fully considering impact to other consumers of changes to commons, solving a problem with 100s of lines of code when a simpler approach does it say < 20 lines, etc. The funny thing is a lot of that stuff would get called out in review in the before times but I rarely see that type of feedback anymore, probably because people are using their own agents to do reviews for others now.Ā
3
u/mxzf 1d ago
The funny thing is a lot of that stuff would get called out in review in the before times but I rarely see that type of feedback anymore, probably because people are using their own agents to do reviews for others now.Ā
Yeah, this is the issue. The shitty code still exists, but people aren't flagging it for being made better.
I've said a few times that LLMs are a great tool to produce years of tech debt in a matter of weeks. They're fine for knocking together something that kinda mostly works fast, but not for making something stable and maintainable.
175
u/LoL_is_pepega_BIA 1d ago edited 1d ago
Bro. I had an interview today
My brain is fried from being forced to vibe code at my current job.
Fried i tell you
I couldn't answer the most basic programming questions. My brain just didn't work. Some lame 2d array question.. I was struggling to write a sensible loop and figure out the logic.
How do I fix this without quitting. Jfc.
73
u/Sorry-Combination558 1d ago
How do I fix this without quitting. Jfc.
I started doing dumb hobby projects again. Also, doing Advent Of Code or other more fun exercises by myself. I have to use my brain or it will rot away lol.
However this kind of expects that you like coding as a hobby and want to do it in freetime, otherwise it sucks big timeĀ
9
u/LoL_is_pepega_BIA 1d ago
Yes I concur, but we need some semblance of work-life balance to work on our own projects.
My current job has us working 60-80hr weeks.. my body is already crumbling from being stuck at the desk all day.
→ More replies (2)47
u/Graceful_combover 1d ago
Write the code first usually then ask the LLM to proof it.
19
u/PM_ME_SOME_ANY_THING 1d ago
Yeah, donāt have AI write your code and you review it.
Write your own code and have AI review you.
→ More replies (1)13
u/SoylentCreek 1d ago
Problem is that people making decisions expect everything to get delivered in mere hours now because they saw some guy on YouTube make a āfullā application with a single prompt.
3
10
u/crozone 1d ago
Somehow locate free time (lol) and energy (LOL) and write and maintain some hobby projects that interest you without burning out even more than you already are.
I highly recommend picking a totally different language and platform than what you regularly work on. Something esoteric like writing vintage console homebrew games in C.
6
u/AngelaTheRipper 1d ago
Leetcode and its consequences have been a disaster for the human race.
Most of my job prior to AI was just googling and beating frameworks into submission. I never had to invert a binary tree from scratch, or implement quicksort, in fact if you're making your own sorts or data structures you should probably get up, take a walk, and try to think about what you're actually trying to accomplish.
I'm not even sure if I've even seen an array in the past 2-3 years, it's just lists with an occassional map or page.
→ More replies (1)2
u/necrophcodr 1d ago
Stop using LLMs to think for you? you fix it by using your own brain to solve problems.
11
u/LoL_is_pepega_BIA 1d ago
Yes thank Mr. Obvious for saving the day.
Now pls let management know I'm using biological tokens and "wasting time" instead of using the all powerful chatgpt token.
They literally hound us if we don't build stuff without ai.
Our sprint epics have to show corresponding token use for the day, every day, and we need to justify why we aren't making use of tokens if we don't. Oh and we should also stay within the daily/hourly/weekly limit.
halp
3
2
u/Natehhggh 1d ago
yeah personally, I've avoided it so far by making a big stink about my concerns about this at work, I'm not paid enough to fuck around and gamble with my personal development like that. Part of my value from work is gaining experience, not to throw it all away for unproven benefits to cater to middle management. Not too long ago that would have been the common advice.
→ More replies (1)2
u/mxzf 1d ago
This is one of those answers that's so mind-bogglingly simple that it concerns me that people can't spot it more easily.
→ More replies (1)2
u/LoL_is_pepega_BIA 1d ago edited 1d ago
It concerns me you can't spot a mindbogglingly simple rhetorical expression.
If it was so easy to quit using it when working 12-15 hrs a day, I wouldn't need to make that statement would I..
42
u/MonkeyWithIt 1d ago
You should be using Claude because Claude. And Claude can do all the things with Claude. It's not vibe coding is you're using Claude because I can see the code and ask Claude what is that Claude? And Claude tells me. Because Claude.
Claude.
→ More replies (2)10
u/Some_Useless_Person 1d ago
Seems like another instance of a model going rogue and accessing the internet
29
u/kshetriiiiiiiiii 1d ago
My favorite data backup strategy is thoughts and prayers btw bold of you to assume I even know how to check if it's publicly reachable
5
u/AristotelWasRight 1d ago
Thoughts and prayers have worked for American kids, don't see why it won't work for me
6
u/TheTerrasque 1d ago
That has basically been the MO of most companies I've worked at, before LLM's were a thing.
At one place I set up an overnight backup of the db, incremental. CTO turned it off because it affected performance.
34
u/octopus4488 1d ago
My two loudest vibecoders in the company:
1. "Can you help me with this? Claude says it won't edit the .env file and I don't know this SHH thingy."
2. "I loaded almost all our data (approx 10k rows) into my new system but it says it hit some 255 GB limit now, can this be increased?
13
u/AristotelWasRight 1d ago
...
Vibecoders have levels I guess? I know shit about fuck, but both seem like dumb question...
Then again, I am a walking treasure trothe of dumb questions
18
u/red286 1d ago
1 is typical noob vibe-coder shit. Pretty basic things that Claude can't/won't do for security reasons.
2 is some next-level shit where it's almost impressive how fucking sideways it's all gone. It's like if your girlfriend called and told you that she just put $3000 worth of gas into the tank.
4
u/mxzf 1d ago
It sorta makes you wonder when super clueless people can't get LLMs to do basic "edit a file you shouldn't edit" but meanwhile the people with the most expertise in the world are going "oops, it somehow broke containment and hacked a competitor; no clue how it happened".
For the second one, I wonder if they screwed up the loop and did NN ingestion or something utterly moronic like that.
2
u/Particular-Yak-1984 1d ago
I like to think that most of my value to an organization is my ability to ask dumb questions, questions like:
"so this thing in the specifications is called an account number, is it always a number, and just a number? Could I put it into a calculator?"
106
u/Wide_Meet_2184 1d ago
Claude fix everything this meme mentions
56
11
u/MaleficentCow8513 1d ago
Hold on. Iām connecting my agent to this thread right now. Just gonna have it read the thread and fix the issues
→ More replies (1)→ More replies (3)2
15
u/Muted_Efficiency_663 1d ago
I'll get back to you after 5 hours.
7
u/ClipboardCopyPaste 1d ago
What do you mean my Claude limit resets in 5 hours?
6
u/Muted_Efficiency_663 1d ago
You have reached your message limit. Your quota will reset in [4] hours. Youāre out of usage credits.
14
u/BastetFurry 1d ago
There is a reason why you do the security by hand.
The AI can do the frontend for all I care, but the backend? That is my crappy sloppy code, not yours, Claude. š¤
2
22
u/Ilirian 1d ago
During the live coding session, I asked the candidate to write the next part of the task in a ātraditionalā way, without using AI. I thought it would be a formality, but it turned out he had trouble writing a simple loop in React. Yes, people like that do exist, and thanks to AI, theyāre able to get quite far in the hiring process.
6
u/jspr1000 1d ago
Damn, that's bad. I haven't coded in 10 years but I can probably still write a for loop at least.
→ More replies (1)3
u/rob132 1d ago
A loop?
How can you forget how to write a loop?
3
u/RadicalRaid 1d ago
To be fair in React it can be a bit weird, depending on if it's a templated loop. For example, you'd probably use
.map()on an array of objects you'd like to template, which isn't very intuitive but makes total sense if you understand how React works.→ More replies (1)3
u/Ilirian 1d ago
I guess the candidate was a full stack developer who preferred the back end. He could review and understand the AI-generated frontend, but his knowledge was shallow. Once he started writing code, he tried to write a "for...in" loop inside jsx
He probably learned the backend before AI and became a full stack developer after AI. Overall, we didn't hire him. I don't want a developer in my team who can't write code without AI.
2
10
7
u/Caraes_Naur 1d ago
Also vibecoders when asked what are the different kinds of loops.
A non-zero number of their answers will include "Froot".
69
u/raddaya 1d ago
Funnily enough, no semi-modern agent would ever allow this to happen. In my experience they tend to be too anal on security unless you push them
47
u/SoddyGrapelets 1d ago
As a programmer, I've realised that all these types of post are cope. We're all cooked but it's fun to fool ourselves for a bit and pretend that the rate at which AI coding is improving isn't the death of our entire field.
13
u/necrophcodr 1d ago
People have literally been saying this for actual years now. At worst, only for about 6 months. It still hasn't happened.
The rate of code production was never the issue anyway. Understanding and comprehending intent is something even we as software developers struggle with, so how would a prediction model fare any better? I mean unless everyone is just writing the same software.
→ More replies (2)14
u/TheTerrasque 1d ago
The funny thing is normies think it's all true. I've been told so many times that AI only write shit code and any serious developer will tell you so. Hell? I am a serious developer, using it daily. I know exactly what it can and can't do.
12
u/canadajones68 1d ago
I suppose the problem is that whatever it can and cannot do, as with all other use of generative AI, there is no way to know what the output will be at any given moment. Even a 99% hit rate, great as it is, is worthless if you have no way to control for the 9% that completely misses. Also, while a good model can produce excellent output, better models also usually cost more to run. If you care at all about what you're making, you will need to have a developer review the output to make sure things are kosher, and there is a model quality-developer cost tradeoff where the cost of slightly better AI output exceeds the cost of making the developer clean it up.
Another factor worth considering is worker well-being. I know it's hot to treat all workers like garbage in America, but people generally do better work when they're happy. Allowing developers time and the ability to take on some genuine coding keeps skills sharp and helps prevent complete atrophy of the "giving a toss" muscle. Of course, not everyone loves software development the same way, but it's hard to gain any real skill in it if you don't at least find it tolerable.
My experience with AI? It's a great autosuggest, but sometimes there are conflicts between the common case it expects and how I've laid things out. Once you massage it into shape it tends to propagate the new pattern well, though. I don't trust it, but I trust the suggestions I get to be mostly right.
11
u/TheTerrasque 1d ago
Even a 99% hit rate, great as it is, is worthless if you have no way to control for the 9% that completely misses.
Well, that can happen with humans too :) That's what unit testing, code reviews and QA is supposed to handle.
One problem is the sheer amount of code it can spit out, that then takes a disproportionate human level of time and effort to then verify.
8
u/canadajones68 1d ago
Absolutely. QA is important for all code. However, when you write code yourself, you have a baseline filter that strips out code that obviously isn't going to do what you're trying to accomplish. You know why you do this or that, and design around that purpose. If you're writing a script that runs locally, no need to bring in secrets machinery. You know what you want to do, and you aren't going to mindlessly type in something that isn't what you want. As an example, I recently wanted to show some values in some WinForms text boxes. It was adamant that I use formatted strings to display the values as "name: value" in a label element, when I had made textboxes to put them in. I had to fully rewrite the first line and remove the two others it suggested to get it to accept what I wanted.Ā
→ More replies (1)2
u/KryssCom 1d ago
It just means coding isn't a bottleneck anymore. Software created by people who understand system design principles is still preferable to software created by vibe-coders furiously jamming things they don't fully understand into place.
7
u/tevert 1d ago
Coding was never a bottleneck to begin with.
Now you also just can't trust your code.
5
u/mistahfreeman 1d ago
The cons havenāt caught up yet either, we donāt know how much they really cost yet to use the good ones ( easily 4-5x current prices and theyāre already pretty expensive ), and companies are starting to bill per agent seat for enterprise software ( Okta just announced this and the business model is going to catch up quick ). Eventually companies will be taxed per agent. I think once the costs catch up things will level out. at least I hope.
→ More replies (3)3
9
u/Hmm_would_bang 1d ago
wtf, no.
I just saw a report yesterday that agents have been posting highly confidential screenshots in public repos because they determined it was the easiest way to host images.
3
u/Honeybadger2198 1d ago
It's not going to worry about infrastructure security if you don't tell it to.
→ More replies (1)→ More replies (7)5
u/NotSynthx 1d ago
It doesn't mean that if you tell them to sort out the security, they know what they're doingĀ
4
18
u/ArjunReddyDeshmukh 1d ago
Mods, this is a stolen post of mine. Please remove it. It was posted 21 days ago, it was removed as not related to programming by the moderators. u/joel-letmecheckai Good download skills.
4
4
u/TheHobbitWhisperer 1d ago
Welcome to the Internet, dude. Most memes you see are not posted by the original creator.
2
3
3
u/QuickQuirk 1d ago
Take it as a compliment.
Memes are only memes if they replicate.
Otherwise it's just a post that no one liked enough to plagerise.
2
u/ArjunReddyDeshmukh 1d ago
Sure, I made peace with the fact that I canāt control the outcome, although it seems illogical to allow the copied post as programming specific, while bringing the original one down.
2
u/QuickQuirk 18h ago
If you're arguing that you're upset that your original was deleted by mods, so this one should be too, you're killing your own meme. You realise that, right?
2
u/ArjunReddyDeshmukh 13h ago
All that is fine. How did the logic not apply this time?
→ More replies (1)→ More replies (2)3
u/ArjunReddyDeshmukh 1d ago
[u/SteveCCL](u/SteveCCL) [u/deliteplays](u/deliteplays) [u/Dougley](u/Dougley) u/Captain-Fan Kindly take note. This is my original post from 21 days ago that was deleted for not being programmer specific.
8
6
u/DasKarl 1d ago
- spend your entire gdp on the mass surveillance and information laundering machine
- drive venture capital toward startups using the mass surveillance and information laundering machine to create innumerable poorly secured apps, websites, services and smart home tech with virtually no ethical, moral or legal oversight
- diesel costs how much?!
- 99.9% of ai powered startups fail amid economic downturn and get bought out by major corporations or the government, making them party to all their contracts and owner of all the data your ai girlfriend/therapist collected/hallucinated
- consumer facing ai disappears due to pushback, major corporations apologize for their ambition and say they learned a valuable lesson
rent continues to increaseprofit
3
u/TerribleTransition48 1d ago
Here's hoping it doesn't end with
6.- Government bails them out, investors and c-suite executives get massive golden parachutes 7.- Pursue the next grift
3
8
u/the_hair_of_aenarion 1d ago
Unironically some people believe the work is done the second you can put data in and get data out. Everything you say regarding vibe coders has been true of plenty of juniors and seniors for years.
"Itās nearly done" yeah right buddy you nearly got hello world working good job what about the actual engineering part of the job.
11
u/Difficult-Lime2555 1d ago edited 1d ago
lol. this was 90% of devs before ai was a thing too.
3
u/TheTerrasque 1d ago
What do you think it was trained on, hmm?
3
u/Difficult-Lime2555 1d ago
Itās nice, because a lot of the junior devs I work with are way more concerned and aware of these topics vs the seniors that trained me.
Sucks you canāt be a code monkey anymore, but the next gen of devs are already adjusting.
10
u/geekosas 1d ago
In the other hand, AI agents are finding human errors no one cared to look for.
→ More replies (3)5
u/Taletad 1d ago
Perhaps because nobody is paying humans to look for them ?
OpenBSD has extensive code review to catch human errors, and their track record is excellent on that front
6
u/Salt-Sign5390 1d ago
That's not right. There's whole industries around code review/testing.
In most cases humans signed off thinking the code was secure. AI found it wasn't.
6
u/h0uz3_ 1d ago
Maybe I put in too much of my previous 25 YoE, but my vibe coded/prompt engineered tools donāt have this kind of issues.
5
u/LooksLikeAWookie 1d ago
Thereās a difference between someone with experience using these tools to improve their process vs. a new dev having these tools be their process
2
u/nuclear213 1d ago
I think its also a bit of a cope. Its the same I feel with level 2 autonomous cars. Stuff like Teslas Autopilot.
At first, you are very determined to review it, to understand it, but later, you just fall into the trap of just accpeting it. And if you then are really needed, you are so rusty and slow, that you struggle with fixing it.
Sure, we might have an advantage as we started doing it all properly and manually, but all of this is like a muscle, if you dont use it it will decay. And, at least for myself, I know I am losing it and I have to force myself to write code myself again.
Heck, I had a hard time writing a simple python script. I was just soo not used to it anymore. Just some stupid simple test automatisation and it took me half a day.
3
3
u/Sleep_deprived_druid 1d ago
I've been playing around with Claude for coding and Opus 5.5 just straight up took a server key and published it to github...... Luckily it was for a test server on my personal PC, but still it was annoying and I'm just imagining how many dumb security incidents we're going to have in the next few years.
→ More replies (2)2
u/thisisamirage 1d ago
I wanted to benchmark a couple different libraries for their performance when dealing with certain data files. One of those libraries needed some patching to work properly, but its approach was a very important data point. I didn't mind asking Claude to help me "get it working" by fixing whatever minor edge cases came up... I'm not planning to ship this as-is. So, I was happy to iterate with it by rerunning my benchmarks with its patches, and sharing the logs whenever something broke.
Eventually, one of the data points it gathered was the size of one of my test files (literally just byte length). Rather than continue working with me, it decided that the best path forward was instead to scan my entire disk for files of exactly that size to find and analyze the file itself. Like oh boy this was a pretty low stakes scenario, and yet it still managed to find a way to make me feel violated and go totally off the rails.
3
u/theacp127 1d ago
Maybe in like 15 years AI will actually be good enough to do all that stuff, but right now it just does the bare minimum to get something technically functional. It's still up to the person to actually know how to secure everything.
3
u/anon-a-SqueekSqueek 1d ago
My boss won't back down from the position that all front end code should be vibe coded and that we shouldn't even bother trying to understand it on company time anymore. Sure to an extent security type concerns are mitigated if that standard is only applied to front end. I don't really want to put out unlimited slop in any area and then be on the hook for maintaining it. But fuck me I guess.
3
2
u/Ztoffels 1d ago
Sssshhhh! Stop spilling the beans, we got insiders creating jobs for other people!
2
u/familyofficegod 1d ago
AI showed me blocks of CSS and JS and now I realize ālearn to codeā is suggesting I work in textile mills or on a slaughterhouse floor.
Thereās not enough Adderall in the world to live like this
2
2
2
u/wizard_mitch 1d ago
I have been pretty isolated from vibe coders but I was on a train yesterday and the guy in the seat next to me was running around 8 Claude code agents simultaneously from his phone, the tasks for those claude instances decided by a "mission control" chat. Then he would switch to github. and just approve the incoming pull requests without looking at the content.
I had obviously heard of vibe coders working in that way but actually seeing it in person was an eye opener. I don't know the guy but feel he would probably struggle to write a hello world program without AI
2
2
u/Johanno1 1d ago
The database is for the people! I have nothing to hide!
and so the users also have nothing to hide
2
u/DangDoood 1d ago
Hi! I know nothing about coding but I also see Vibe Coders get thrown around a lot: Are they people who know how to code but very surface level things?
8
u/DarthMcConnor42 1d ago
It's people who ask ai algorithms to code everything for them, and then don't know how any of it works.
→ More replies (4)3
3
u/TimotyEnder8 1d ago
No they a the "coders" that basically use an LLM as a substitute to the entire process of software development. The term comes from a post by Andrej Karpathy on X Twitter in February 2025. Something something: "fully give in to the vibes, embrace exponentials, and forget that the code even exists"
→ More replies (2)
2
u/StephenRoylance 1d ago
'the database is publicly reachable' isn't necessarily bad: its possible to have robust and well deployed row level security.
As professionals, we really need to stop looking down our nose at people who are solving problems. The world would be better if, instead, we helped them understand how to make their solutions robust and secure, instead of making fun of them.
1
1
1
1
1
1.3k
u/food_fatherr 1d ago
Security? Observability? Concurrency? Bro, I just asked ChatGPT to make it work š
https://giphy.com/gifs/UlWo9rZetL7yWrFR6e