Live data from Hacker News

An AI Vibe Coding Horror Story

tobru.ch

161–170 of 224 posts

Re: An AI Vibe Coding Horror Story

#161

This reads like internet fiction to me. Very vague and short.

yeah keeping it vague makes sense to protect the place if it's still online but the whole thing doesn't really make sense? The timelines mentioned are weird - he spoke to them before they built it? Or after? It's not that clear, he mentions they mentioned watching a video. > The entire application was a single HTML file with all JavaScript, CSS, and structure written inline. This is not my experience of how agents te…

I could bet 5 dollars that they used chat and not an agent, and that's also the reason why it's a single html file.

Copypasted and than dropped into hosting folder, sweet web 1.0 style

Re: An AI Vibe Coding Horror Story

#162

Earlier quoted context omitted.

There’s a reason why many professions have professional bodies and consolidated standards - from medicine to accountancy, actuarial work, civil engineering, aerospace, electronic and electrical engineering, law, surveying, and so many more. In most of those professions, it is a crime or a civil violation to offer services without the proper qualifications, experience and accreditation from one of the appropriate prof…

> There’s a reason why many professions have professional bodies and consolidated standards imo this is sold as "keeping people safe" but in practice it's really a gatekeeping grift that increases friction and prevents growth

Equating gatekeeping of professional bodies with grifting suggests you have no experience of why we have professional bodies in medicine or accountancy or civil engineering (to give just a few examples).

Re: An AI Vibe Coding Horror Story

#163
post #146

Earlier quoted context omitted.

> There’s a reason why many professions have professional bodies and consolidated standards imo this is sold as "keeping people safe" but in practice it's really a gatekeeping grift that increases friction and prevents growth

You don't want some gatekeeping on who will be doing surgery on you? You do obviously, and medical malpractice is a good thing if there is a problem. Why don't you want the software engineer building your pacemaker or your medical CRM (or any other job where your immediate security is engaged) to have the same kind of verification and consequences for their actions?

1. 99.999999% of software is not equivalent to "doing surgery" so doesn't need gatekeeping. I work on free, open-source PDF reader SumatraPDF. What kind of authorization should I get and from whom to ship this software to people?

2. pacemakers and other medical devices have to get approval from the government. So that's covered.

medical CRM software is covered by medical privacy laws which does what you say you want (criminalizes "bad" software) but in reality is a giant set of rules, many idiotic, that make health care more expensive for no benefit at all.

Re: An AI Vibe Coding Horror Story

#164

Earlier quoted context omitted.

There’s a reason why many professions have professional bodies and consolidated standards - from medicine to accountancy, actuarial work, civil engineering, aerospace, electronic and electrical engineering, law, surveying, and so many more. In most of those professions, it is a crime or a civil violation to offer services without the proper qualifications, experience and accreditation from one of the appropriate prof…

> There’s a reason why many professions have professional bodies and consolidated standards imo this is sold as "keeping people safe" but in practice it's really a gatekeeping grift that increases friction and prevents growth

Adulterated food products, shoddy construction that burns like paper or crumples in an earth quake, snake oil medicine, etc. are well attested in underdeveloped nations and in history at scales far above what we see in societies with the kinds of professional bodies we’re talking about.

That said, the reality is that this safety comes at a cost, both monetary and in terms of “gatekeeping.” And many people would be fine (on paper) increasing risk 0.05% in exchange for 20% cut in costs or allowing disruption of established entities. But those 0.05% degradations add up quickly and unexpectedly.

Re: An AI Vibe Coding Horror Story

#165

Software engineering is looking more and more like it needs a professional body in each country, and accreditation and standards. Ie it needs to grow up and become like every other strand of engineering. Gone should be the days of “I taught myself so now I can [design software in a professional setting / design a bridge in a professional setting].” I’m not advocating gatekeeping - if you want to build a small bridge…

Regulations are written in blood and it will take a bit for vibe coding to cause enough problems.

Sadly, probably true.

Re: An AI Vibe Coding Horror Story

#166
post #52

Earlier quoted context omitted.

As the sibling pointed out, there are already plenty of laws about, for example, handling of personally identifiable data. Somehow there is a lack of awareness, perhaps what is needed is a couple of high-profile convictions (which can't be too far off).

One of the key functions of a professional body is to ensure all members are aware of existing and new laws, standards and codes of practice. And to ensure different grades of engineer are aware of different levels of the standards. And that sector-specific laws and standards are accredited accordingly. High profile convictions are not a good way of dealing with this. Not in the short or long term. Sure they have an…

Nothing would be more effective at killing open source and commercial software business that requiring everyone that writes and ships software to users, directly or indirectly (e.g. an open-source library) to have License To Program from Software Licensing Organization.

> aware of existing and new laws, standards and codes of practice

Yeah, because software business is not at all ruled by fads.

1997: you have to follow Extreme Programming (XP) or you don't get your license

2000: you now have to use XML for everything in XML or you don't get your license

2002: you now have to follow Agile or you don't get your license

2025: you now have to write everything in Rust or you don't get your license

etc., etc.

Re: An AI Vibe Coding Horror Story

#167

Earlier quoted context omitted.

We require someone with a professional engineering designation from an accredited engineering body to sign off and approve before a building can be built. If it is found to have structural issues later, that person can be directly liable and can lose their license to operate. Why this is not the case with health software I cannot explain. Every time I propose this the only argument I recieve against it is people who…

Oh man, I have gone off on rants about software "engineering" here in the past. My first office job was as an AutoCAD/network admin at a large Civil and Structural engineering firm. I saw how seriously real engineering is taken. When I brought up your argument to my FAANG employed sibling, he said "well, what would it take to be a real software engineer in your mind!??" My response was, and always will be: "When ther…

People like to make this point, but traditional engineering has the opposite problem: insanely overwrought processes and box-checking that exists for no reason and slows everything down to a snail's pace. Yes there are safety-critical parts, but they surrounded by a ton of bullshit.

It's also absurd to think that there is no company which does genuine software "engineering". If you break ads at Google/Meta, streaming at Netflix, etc there are massive consequences. They are heavily incentivized to properly engineer their systems.

The main thing that governs whether time is spent to well-engineer something is if there is incentive to do it. In traditional engineering that incentive is the law (Getting council approval, not getting sued, etc). In software engineering that incentive is revenue.

Re: An AI Vibe Coding Horror Story

#168
post #146

Earlier quoted context omitted.

> There’s a reason why many professions have professional bodies and consolidated standards imo this is sold as "keeping people safe" but in practice it's really a gatekeeping grift that increases friction and prevents growth

You don't want some gatekeeping on who will be doing surgery on you? You do obviously, and medical malpractice is a good thing if there is a problem. Why don't you want the software engineer building your pacemaker or your medical CRM (or any other job where your immediate security is engaged) to have the same kind of verification and consequences for their actions?

It's mostly the problem of required regulations, so no we don't want mandatory gatekeeeping on surgeons as this is for example leading to doctor shortages

It's fine to set up voluntary standards and choose surgeons you think live up to those

So we want to enable more people to be able to create for example pacemakers because of things like Linus's law, "Given enough eyeballs, all bugs are shallow". If we exclude "non-professionals" from the process of creating "professional" products, we tend to have less participation in the process of innovation and therefore get less innovation

Re: An AI Vibe Coding Horror Story

#169

This reads like internet fiction to me. Very vague and short.

yeah keeping it vague makes sense to protect the place if it's still online but the whole thing doesn't really make sense? The timelines mentioned are weird - he spoke to them before they built it? Or after? It's not that clear, he mentions they mentioned watching a video. > The entire application was a single HTML file with all JavaScript, CSS, and structure written inline. This is not my experience of how agents te…

Having experience working with medical software, I call BS on this article as presented, unless it was some minimal support app. When you deal with patient records, there's so much of local law, communication, billing rules and other things baked in that you CANNOT vibe code an app to handle even 1% of that. Your staff would rebel and your records would completely fall apart. Even basic things like appointment bookings have a HISTORY and it's a full blown room scheduling system that multiple people with different roles have to deal with (reception and providers). It takes serious time to even reverse engineer the database of existing apps, and you first have to know how to access the database itself. Then you'll see many magic IDs and will have to reverse engineer what they mean. (yes, LLMs are good at reverse engineering too, but you need some reference data and you can't easily automate that)

I have decompiled database updaters to get the root password for the local SQL Server instance with extremely restricted access rules. (can't tell you which one...) I have also written many applications auto-clicking through medical apps, because there's no other way to achieve some batch changes in reasonable time. I have a lot of collateral knowledge in this area.

Now for the "unless it was some minimal support app" - you'll see lots of them and they existed before LLMs as well. They're definitely not protecting patient data as much as other systems. If the story is true in any way, it's probably this kind of helper that solves one specific usecase that other systems cannot. For example I'm working on an app which handles some large vaccination events and runs on a side of the main clinic management application. But accidentally putting that online, accessible to everyone, and having actual patient data imported would be hard-to-impossible to achieve for a non-dev.

For the recording and transcription, there are many companies doing that at the moment and it would be so much easier to go with any of them. They're really good quality these days.

Re: An AI Vibe Coding Horror Story

#170

Earlier quoted context omitted.

No, they were complaining about using expensive, overly complicated third-party system that they need like only basic features like keeping text records about visits, and prescriptions and sending invoices to health insurers. And in some practices you get direct access to your data as a patient. I mean the story might be fake obviously, but is definitely plausible.

Yeah sure, as a matter of rule, every time I visit any health provider I am always discussing with the medical receptionist: the software they use, the challenges the business as a whole faces, the tensions between insurers and third parties. Things that absolutely 100% happen everytime I - a tech guy - experiences when I go to the doctor/phyiso-therapist etc... etc... These are discussions that are happening.

Ok. So can I conclude that your point boils down to:

"Your claimed experience is different than my experience so you are lying"?

Post reply on HN