‹ BackHN Continuity

Thread

One Month Without AI

188 points · 228 comments · saibotk

  1. austin-cheney · · focus · HN ↗
    Yeah, I have never understood the over reliance on AI. Writing the code is not the challenge. The time it takes to push a new feature and test it out is often trivial, maybe a few hours.

    The real challenge is forming the new ideas in the first place and most of those new ideas coming either from using the code as a product or time spent maintaining and refactoring large code.

    Anyways, if you want to continue on the path towards regaining control and take it to the next level I wrote something similar here: <a href="https:&#x2F;&#x2F;blog.sharefile.systems&#x2F;be-brave-go-low&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.sharefile.systems&#x2F;be-brave-go-low&#x2F;

    1. XCSme · · focus · HN ↗
      Wriring the code is not the challenge, but it&#x27;s what was taking up most of the time. Not the typing itself, but also because I had to think of how to implement it.

      Now I can just say &quot;add 2FA&quot; and in 5 minutes, while I test something else, it is done.

      It also made iterations a lot faster, you can try something out, see how it feels, if it doesn&#x27;t work, you can just trash all the code and start again.

      1. anygivnthursday · · focus · HN ↗
        But you still have to review that 2FA code and that involves thinking through the implementation, right?
        1. XCSme · · focus · HN ↗
          No.

          Haven&#x27;t typed a line of code or read any code for over 6 months now.

          And I used to love coding and be a competitive programmer, but this is how &quot;coding&quot; goes nowdays.

          I have a mental model of what it would do, and how it would work, and I ask questions to confirm things and tell it to watch for specific gotchas. Then simply test the feature myself a bit.

          Security-wise, I think the latest cyber models are better than me anyway at finding vulnerabilitates and pentesting such features.

          Plus 2FA is a very common pattern, so it likely has in the training dataset many really good implementations.

          1. anygivnthursday · · focus · HN ↗
            &gt; Security-wise, I think the latest cyber models are better than me anyway at finding vulnerabilitates and pentesting such features.

            I don&#x27;t doubt that, but they are equally good in making mistakes, over-engineering, or adding things you never asked for. They have all sorts of patterns in their training data from excellent to inadequate and I find them challenging to guide them consistently in one direction. Also with questions and tests, they can add something extra you didnt need and you dont know about, so your scrutinizing questions and test cases could miss that.

            At least for myself, I didnt find them reliable enough yet to do what you describe and just not look at the code at all.

            1. sarkarghya · · focus · HN ↗
              As someone who has an ide open with claude&#x2F;codex running, I can never imagine leaving security up to models.

              Models have found vulnerabilities that i wasnt aware of sure, but their fixes to the bugs they found often included &quot;overengineering&quot;. In this case by &quot;overengineering&quot; i mean optimizing for passing test cases related to said vulnerability they found. eventually i have to step in to make things coherent and make sure that future agent can look at this part of my code and copy it to not introduce that particular class of vulnerability. Otherwise if i dont do that similar vulnerability and codesmell keep appearing throughtout the codebase.

              I have increasingly automated encrypting and rotating secrets and setting permissions on them including better network level practices. Thanks to AI which helped me quickly implement those. So security wise i am better because of AI? But I also attribute it to my know how rather than the AI because I have never seen AI suggest robust but simple security postures.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.