Live data from Hacker News

An AI Vibe Coding Horror Story

tobru.ch

121–130 of 224 posts

Re: An AI Vibe Coding Horror Story

#121

I did something similar to a local company here in Spain. Not medical, but a small insurance company. Believe it or not, yes, they vibecoded their CRM. I sent them an email and they threatened to sue me. I was a bit in shock from such dumb response, but I guess some people only learn the hard way, so I filed a report to the AEPD (Data protection agency in Spain) for starters, known to be brutal. I've also sent them a…

A similar thing happened to me back in the day when Wi-Fi was still new.

I joined an open network and it turned out to be a law firm. All their computers were on a Samba network with full C: drives shared. I wrote README.txt files on their drives telling them about the issue, but after some time it was still the same.

Then I went directly to the place to talk to them and also with the idea I could land my first job fixing that mess. But... They got incredibly angry with me, since they claimed they had some very good and expensive contractors taking care of their computers and network, and that I had basically broken in.

I left the place quickly...

Re: An AI Vibe Coding Horror Story

#123

Meanwhile on Linkedin… Every sales bozo with zero technical understanding is screaming top of their virtual lungs that evrything must be done with AI and it is solution to every layoff, economic problem, everything. It is just a matter of time when something really really bad happens.

[flagged]

Re: An AI Vibe Coding Horror Story

#124
post #64

Earlier quoted context omitted.

At least part of the negligence is about the people who knowingly promote AI without also promoting knowledge of the limitations. Those who post stories about vibe-coding XXX in a week and don't bother to point out that they have no idea if it's not a piece of crap, waiting to explode, because there's no way they could have tested it properly in a week let alone read the mountains of code produced. There's a hype mac…

That's what is meant by human negligence. There will always be a hype about something and that is not an excuse to have a devil may care attitude on any work being done

Negligence depends on what you believe to be true. If you're being told "this is possible and the AI will do it properly you don't have to worry" then it's not negligence really - on the part of the person who believes what they are told.

For the rest of us it is about being put under pressure by managers who don't understand whether to believe what you say or what they read about vibe coding on some linked-in post. As far as they are concerned you're not the authority and some hype-ster is.

Re: An AI Vibe Coding Horror Story

#125
Every other field that's figured out high stakes failure models eventually landed on the same solution - make sure two people that understand the details are looking at it - pilots have copilots surgeons with checklists and nuclear plants have independent verification. Software was always the exception, cause when it broke it mostly just broke for you, vibe coding is not going to change the equation, it barely removes one check that existed before is that the people who wrote the code understood what was going on, but now that's gone too

Re: An AI Vibe Coding Horror Story

#126

Earlier quoted context omitted.

I don't think you read the article very carefully, the timeline is that he met a person, and that person told him that they made vibe-coded an app after having seen a video. He then investigated the app.

Yeah because every medical practice I go to, I'm always able to investigate all of their systems.

Isn't that the whole point? That one should NOT be able to investigate all of their systems?

Re: An AI Vibe Coding Horror Story

#128
post #92

Earlier quoted context omitted.

I live in Switzerland. Sounds pretty normal. There are plenty of small medical practices with 1-2 doctors and a front desk. On my last visit i actually casually discussed their IT system with a doctor.

> On my last visit i actually casually discussed their IT system with a doctor. Oh right, cool. Did it have a public-facing web-portal that you were able to "investigate" and that "Thirty minutes in, I had full read and write access to all patient data". The level of credulity in these comments is immense.

No, they were complaining about using expensive, overly complicated third-party system that they need like only basic features like keeping text records about visits, and prescriptions and sending invoices to health insurers. And in some practices you get direct access to your data as a patient.

I mean the story might be fake obviously, but is definitely plausible.

Re: An AI Vibe Coding Horror Story

#129
post #42

Earlier quoted context omitted.

Professional bodies act as nothing more then gatekeepers and rent seekers for things of this nature. Anyone can write software, but not everyone writes security minded software. We already have laws in place, and certifications that help someone understand if a given organization adheres to given standards. We can argue over their validity, efficacy, or value. The infrastructure, laws, and framework exist for this. M…

There’s a reason why many professions have professional bodies and consolidated standards - from medicine to accountancy, actuarial work, civil engineering, aerospace, electronic and electrical engineering, law, surveying, and so many more. In most of those professions, it is a crime or a civil violation to offer services without the proper qualifications, experience and accreditation from one of the appropriate prof…

> There’s a reason why many professions have professional bodies and consolidated standards

imo this is sold as "keeping people safe" but in practice it's really a gatekeeping grift that increases friction and prevents growth

Re: An AI Vibe Coding Horror Story

#130
post #85

Earlier quoted context omitted.

Is really weird to me that this is your reception. It's a rarely updated personal blog, not a daily tabloid story.

It's pure bs. If you read that blog post and think "this definitely happened", let alone "wow - this is interesting" then I have a monorail to sell you. > Technical Background > The entire application was a single HTML file with all JavaScript, CSS, and structure written inline. The backend was a managed database service with zero access control configured, no row-level security, nothing. All "access control" logic l…

What do you want as proof? A link to the app?
Post reply on HN