Elektrine lite

← Feed

@Haste@mastodon.social

Post #730887

2026-03-16 19:09 UTC

I’ve been thinking a lot lately about the hollowing-out of software. Specifically, how do I protect myself from a formerly useful program auto-updating with vibe-coded (and potentially compromised) AI-slop? More and more development teams are getting axed. Their corpses are getting stuffed with cheap, rotten code that is at best unfit for purpose, and at worst actively dangerous. I can’t possibly track of it all. It seems a matter of time before something bites me.

Replies (4)

  • @Haste@mastodon.social 2026-03-16 19:13

    Obviously, turning auto-updates off is also extremely unsafe. But when you fire your engineering department, demand ten times the output from the survivors, and then outsource that output to the Lying Machine, how can I trust that in six months anyone at your company will know what your code does anymore? This isn’t a problem that can be solved with using open-source tools either. As we saw with the whole chardet incident, volunteer communities are equally vulnerable to this thinking.

    Open ##1439812

  • @ATLeagle@mastodon.online 2026-03-16 19:14

    @Haste I keep seeing the ai sales pitch where a product manager can quickly spin up a demo. They always skip the part where the demo becomes real and real developers don't have input because time to market

    Open ##1439827

  • @ErikJonker@mastodon.social 2026-03-17 12:08

    @Haste …it’s about quality control, regardless who wrote the code (AI or human, or more likely the combination) , it is fiction to think that there will be large code bases without AI input in the near future

    Open ##1439833

  • @Haste As a security engineer, Ive been doing research on how easily it is that an LLM model can be compromised into serving malicious code to a prompt. That becomes infinitely more dangerous than just generally NON functioning Slop Code (Vibe Coding right)? An LLM fed a constant diet of close to a petabyte of malicious data (over an estimated 1 year period) is LIKELY to start suggesting malicious code at a 15% likelyhood. That would make AI Slop coding EVEN worse.

    Open ##1439862