Hacker News new | ask | show | jobs
by 827a 188 days ago
Yeah, its bad out there. At my company, we have a team of security professionals that focus on keeping our systems (and others') secure. AI for them has gone from "using it for scripting together nmap" to "we really need the platform your team is working on to do X, Y, and Z, so we vibed up this PR". On the engineering side, I don't have the political power to tell them no, because we don't really have senior leadership and we're behind schedule on everything. Why? Well, I spent two hours today resolving dozens of vulnerabilities our code scanners found in some vibed security team PR. The scanners that they set up, and demanded we use. Half the stuff they vibe we literally have to feature flag off immediately after release, because they didn't QA it, but they rarely revisit the feature because to them its always either "on to the next big idea" or, more often, "we're just security, platform isn't our responsibility".

The thing is: I know you might read that and think I'm anti-AI. In this specific situation, at my company: We gave nuclear technology to a bunch of teenagers, then act surprised when they blow up the garage. This is a political/leadership problem; because everything, nine times out of ten, is a political/leadership problem. But the incentives just aren't there yet for generalized understanding of the responsibility it requires to leverage these tools in a product environment that's expected to last years-to-decades. I think it will get there, but along that road will be gallons of blood from products killed, ironically, by their inability to be dynamic and reliable under the weight of the additive-biased purple-tailwind-drenched world of LLM vibeput. But, there's probably an end to that road, and I hope when we get there I can still have an LLM, because its pretty nice to be able to be like "heyo, i copy pasted this JSON but it has javascript single quotes instead of double quotes so its not technically JSON, can you fix that thanks"

1 comments

AI is trash.

The people who think FizzBuzz is a leetcode programmer question are now vibecoding the same trash as always, except now they think they are smart x10 developers for forcing you to review and clean up their trash.