pull down to refresh
I was thinking maybe these bots are rubbing off and I hallucinated this. But I found it.
Image where I spotted it:
SN Source: #1539905
Tweeter source: https://x.com/callebtc/status/2084561246305542617
Nitter source: https://nitter.net/callebtc/status/2084561246305542617
This means: opti is not hallucinating. Opti is also not wrong at all that there are a million ways how your vuln can leak before you even get the email.
Note: one additional thing: there is another, later tweet (#1541457) where calle is additionally thanking wafer.ai as well as moonshot, meaning that perhaps there is now (also) US based infra, so now at least they can be frontran and your open source project can be attacked by US and CCP spooks... concurrently, before you even get the email.
so now at least they can be frontran and your open source project can be attacked by US and CCP spooks
all stinks
I'm mostly just worried about execution. The PR stunt surrounding this is a red flag. You still need the human verification of someone that either knows the code, or learns the code on the spot. And this is what is "outsourced", under pressure, to maintainers. With the message "just feed it to your AI", which is poor advice. 55k in tokens or GPU rental is not the real cost. The real cost is on the shoulders of 300+ maintainers that need to spend time, and if they have standards, a lot of it.
Last night I ran a diff of some upstream dependency through a bot. It was large (almost 700kB) and definitely vibe-coded but it is flagged by the security cartel (aka GitHub, aka Microsoft, which is fucking funny if you think about it) as a critical vuln. Reviewing slop code from 3rd parties is a waste of your time in general, so at scale you have no choice but to fight fire with fire. I have fine-tuned a toolset to make it not make the usual mistakes of assigning value statements and just flagging up odd things by reconstructing end-to-end integration paths and scanning for threats. Most of the time, it finds a nit here and there on security patches, but nothing substantial. Last night it came back with an actual list of perceived regressions and warnings and red flags. Now I have to review slop code from some asshole that couldn't just patch a vuln manually and test it, like we used to do since the beginning of software.
Maybe you didn’t kill my dream after all. After reading this comment it confirms that I would need extensive training to be good at this. Time I just don’t have at my age
I killed your future nightmare <3 and honestly am trying to look out, not just destroy something for the fun of it.
I don't know your age, but I've seen from people around me that retired and got some free time, that as long as the cognitive clockwork is still functioning okay, you're not too old to learn. So maybe it's more of a "not right now" thing. And if anything, AI can help you learn. The key concepts imho are "don't be lazy" and "don't hand off / publish things you don't understand", which is a matter of discipline, patience and attention to detail more than skill.
This means that vibe coding is essentially an optimized way to automate coding that you already master and can have an informed opinion about when it is proposed to you, or to get something quickly for yourself that you don't need to publish / share with others. If then your final product is poor because of your misguided tooling, it's the same fuckup you would have made when you were to not automate.
The enemy of security in this is that many devs/non-devs take already awful QA process and lessen it because they trust the bot's output - most often because it all sounds amazingly complicated so it must be smarter than me and thus be right. That's also what has been pushed by the labs and they failed to deliver on this "vision" all the way. It's simply marketing speak, trying to get max FOMO for max valuations. Like a ponzi: maybe with the next capital injection you can make it real. Fake till make. Zuck shit. Theranos shit.
Just don't fall for it. "Don't trust, verify" is awesome when diligently practiced.
Yeah that’s why vibe coding never sat well with me. Plus it’s daunting to learn the proper way to build something.
I saw Calle thanking Kimi for special unrestricted access in one of Scoresbys reports. Kimi = CCP