2026-02-08 22:02 UTC
@nolan@toot.cafe I mean, I definitely think it can do an awful lot of jobs... badly. :-) The question for me is whether companies are actually OK with that reduction of quality. I'm concerned that they will be, at least in the short to medium term.
I do think that LLMs can often find vulns, and *in the hands of an expert* can assist in securing software. Otherwise it's just a flood of crap, as the article notes.
But coming back to my original question:
Is that code you generated usable?
- Would you feel comfortable if your daily browser used this generated code instead of hand-written? Would you install it on your family's computers?
- If no, what would it take for your answer to change?
Replies (1)
-
@nolan@toot.cafe 2026-02-08 22:29
@varx@infosec.exchange If your question is "Can LLMs generate a production-ready browser that I would trust today?" then the answer is obviously no. However, the fact that it can get within spitting distance with a single prompt should give one pause. It's easy to see how this story ends. More important I think is your first point โ "good enough" or "worse is better" has been a defining trait of most software for a long time. I think we can both agree that we'll see a lot of crap software shipped this year. ๐