A good account of one's own exhaustion but a remarkably poor argument about AI. This person spends 75% of their working life dealing with something he hates, reverse-engineers a worldview from the resulting burnout and concludes that everyone else has "brain worms."
There is one useful observation buried in it, which is that when vulnerability discovery becomes cheap while triage and remediation remain expensive, you create a larger queue rather than a safer system. Fine. I think that point has been raised in many of the other discussions on this site. But then he inflates that into "finding vulnerabilities has never been the bottleneck" which is demonstrably false. Discovery may not be the bottleneck in fleet-wide CVE management but it is plainly the bottleneck for every serious vulnerability that nobody has discovered yet. His own examples of flaws surviving decades of expert scrutiny shows this.
The Glasswing figures show a triage-capacity problem. They do not establish the essay's much stronger claim that "we aren't any safer." You simply cannot infer that from the ratio of findings to fixes! You would need to know which findings were exploitable, which fixes were accepted and deployed, whether attackers would otherwise have found them, how much review work was consumed, and whether the incidents were prevented. The essay measures literally none of that.
Its alternative history claim is also unsupported. Supposedly every participating organization diverted dozens of senior engineers, spent millions, and would have produced more security by assigning those same people to asset inventory and patch automation. Perhaps. Where are the staffing data, budgets, opportunity-cost estimates or comparative outcomes? Promotional model credits are not engineering expenditure and vulnerability researchers, at least to my layperson's knowledge, are not interchangeable with infrastructure engineers.
The broader essay repeatedly collapses distinct anchors and problems into a single villain called "AI." Grok's sexual-image scandal says something damning about xAI. Military targeting failures say something damning about the military, its contractors, its data and its command structure. Datacenter expansion creates genuine environmental and infrastructure costs requiring policy. But none of that establishes that someone using an LLM to understand an unfamiliar API or to write a PRD is morally participating in every one of those failures. That's just guilt by association.
The irony is that the author condemns anthropomorphic language for diffusing corporate responsibility (which is fine), then spends the rest of the essay treating "AI" as a unitary agent responsible for all sorts of things, from corporate procurement and military decisions to power generation, bad software, ugly prose and programmers becoming lazy. He recreates exactly the accountability blur he claims to oppose.
Overall it's a poorly thought out vent piece.
enraged_camel · · focus · HN ↗
There is one useful observation buried in it, which is that when vulnerability discovery becomes cheap while triage and remediation remain expensive, you create a larger queue rather than a safer system. Fine. I think that point has been raised in many of the other discussions on this site. But then he inflates that into "finding vulnerabilities has never been the bottleneck" which is demonstrably false. Discovery may not be the bottleneck in fleet-wide CVE management but it is plainly the bottleneck for every serious vulnerability that nobody has discovered yet. His own examples of flaws surviving decades of expert scrutiny shows this.
The Glasswing figures show a triage-capacity problem. They do not establish the essay's much stronger claim that "we aren't any safer." You simply cannot infer that from the ratio of findings to fixes! You would need to know which findings were exploitable, which fixes were accepted and deployed, whether attackers would otherwise have found them, how much review work was consumed, and whether the incidents were prevented. The essay measures literally none of that.
Its alternative history claim is also unsupported. Supposedly every participating organization diverted dozens of senior engineers, spent millions, and would have produced more security by assigning those same people to asset inventory and patch automation. Perhaps. Where are the staffing data, budgets, opportunity-cost estimates or comparative outcomes? Promotional model credits are not engineering expenditure and vulnerability researchers, at least to my layperson's knowledge, are not interchangeable with infrastructure engineers.
The broader essay repeatedly collapses distinct anchors and problems into a single villain called "AI." Grok's sexual-image scandal says something damning about xAI. Military targeting failures say something damning about the military, its contractors, its data and its command structure. Datacenter expansion creates genuine environmental and infrastructure costs requiring policy. But none of that establishes that someone using an LLM to understand an unfamiliar API or to write a PRD is morally participating in every one of those failures. That's just guilt by association.
The irony is that the author condemns anthropomorphic language for diffusing corporate responsibility (which is fine), then spends the rest of the essay treating "AI" as a unitary agent responsible for all sorts of things, from corporate procurement and military decisions to power generation, bad software, ugly prose and programmers becoming lazy. He recreates exactly the accountability blur he claims to oppose.
Overall it's a poorly thought out vent piece.