‹ BackHN Continuity

Thread

Everybody's Lost Their Minds

373 points · 348 comments · ibobev

  1. tptacek · · focus · HN ↗
    If you think vulnerability research simply doesn't matter, you have a lot of company in that opinion. It's something Bruce Schneier used to argue, and Marcus Ranum, and a bunch of other people that used be on closed secret vulnerability-sharing mailing lists before Bugtraq blew those cliques up. These are very old arguments.

    But if you do think vulnerability research matters, and you're trying to argue that frontier models aren't a seismic change for that discipline, you have almost no company. Vulnerability researchers are overwhelmingly leaning on automation to find vulnerabilities and, just as importantly, generate the tooling required to test hypotheses.

    You can feel about that however you want to feel about it. I mostly don't care, except: you can watch people like this being negatively polarized back into the bad old days of the mid-1990s, content-free CERT advisories, and vendor-controlled "responsible disclosure" by a use case that frontier models unimpeachably excel at.

    1. jeremyjh · · focus · HN ↗
      It’s amazing how half the developers on earth live on a completely different planet now. There are plenty of new challenges, sure but we are far past the point where we can have a debate about “is it useful?”

      And yet we continue to do so. I understand the feeling of loss some people may be facing. And there are definitely some really bad practices - like nakedly spewing claudspeak at your colleagues instead of communicating. Or raising a PR you don’t understand. There are asymmetries we haven’t learned to navigate. But we aren’t returning to a world where it doesn’t dominate our discipline so it’s best to find opportunities.

      1. vermilingua · · focus · HN ↗
        The question most of us are asking isn’t “is it useful”, but “is it worth it”. Engaging with these tools involves no small amount of self-debasement and long term degradation of skills; do I want to sacrifice myself on the altar of productivity?

        For me the answer is still absolutely resolutely “no”.

        1. akerl_ · · focus · HN ↗
          You’re already using a computer to automate massive amounts of what used to be manual human effort.

          Why is using AI tools self-debasing or degrading?

          1. timacles · · focus · HN ↗
            I dont know how you can work in this discipline, use AI, and also ask that question.

            almost every developer i know is fully aware, we are degrading every aspect of our skills.

            The code writing, code reviewing, code understanding.

            The more "time" passes and the more the code base grows, the more disconnected we become.

            1. jeremyjh · · focus · HN ↗
              Our horse riding skills have degraded even more.
              1. akerl_ · · focus · HN ↗
                Jokes aside, I think this gets at the core of it.

                If you really loved horseback riding, or you really loved breeding and training horses, or you were really good at it, I'm sure that cars fucked up your day, and that it sucked to see cars replace horses.

                I'm sure there were plenty of people who said that cars were horrible and that we should stick with horses. I'm equally sure there have been C programmers looking derisively at Python programmers, Python programmers looking derisively at Node programmers, etc etc.

                But there's a pretty big gap between the feeling of unhappiness that something you liked is no longer as in-demand / profitable / common / whatever, and saying that cars aren't useful and we're all worse off for letting our horse-riding skills degrade.

                1. timacles · · focus · HN ↗
                  This does not get to the core of it, LLMs are not equivalent to cars.

                  All of your analogies (in other posts) discount that: - LLMs are not deterministic - they do not produce high quality/expert level output. - They are not easy to control consistently.

                  Once again, and i mean this in the nicest way possible. You do not sound like you understand how things operate at an expert level of engineering. I do not know of any senior engineer who thinks LLMs can consistently produce quality output.

                  You are way too invested in your argument and refusing to see other perspectives

                  1. akerl_ · · focus · HN ↗
                    It seems really convenient for you to speculate about my level of expertise so that then you can make claims that no senior engineers think something.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.