Live data from Hacker News

A desktop made for one

isene.org

261–270 of 281 posts

Re: A desktop made for one

#261
post #155

Earlier quoted context omitted.

I'm in the second camp. Part of it's that the whole point of going into this industry is that I love coding and have been doing it since I was 8. Part of it is that I'm a control freak and it makes me uncomfortable to have to trust AI generated code. Sure, I already trust interpreters and compilers, but those are much more deterministic, and they don't generally do anything I have to be wary of. Part of it is that an…

I was in the second camp until last summer, having been hand-writing code since 1979.

Yeah I mean that's the point at which cognitive decline and retirement kind of change the calculus.

Re: A desktop made for one

#262
post #260

Earlier quoted context omitted.

Come on, bro. Why you gotta be like that? I mean, I'm a gwern fan, but...can't you just let people enjoy things?

I didn't enjoy it. It flunks my criteria for good AI images, because there is no there there: https://gwern.net/blog/2025/good-ai-samples It wasted my thoughts as I stared at it, trying to learn about the author and 'X uses this' and thinking about how moleskin notebooks related to personal computing etc... only to realize I had been lied to and my time wasted, as he took advantage of my good faith - the good faith I…

> I didn't enjoy it.

Then it wasn't for you. No big whoop.

> It wasted my thoughts as I stared at it,

I think we have arrived at the kernel of the problem. :-)

The rest of this comment is left as an exercise for the student.

Re: A desktop made for one

#263

Earlier quoted context omitted.

I am imagining some poor sod working for NSA TAO trying to hack a bespoke web microservice stack. He spends dozens of hours slaving away at the keyboard, skipping sleep and eating terrible meals at his desk, desperate to get RCE as quickly as possible, because he needs to traverse all the way to the DB layer and exfil data or his boss will pass him over for his next promotion. At day 9, right as he is getting ready t…

Moral of the story: A truly secure website would be a continuously morphing one where an LLM keeps rewriting and redeploying large parts of its code every minute, so that no attacker can keep up.

Hmm. Now that you mention it, wasn't that part of what was happening in Neuromancer? The "encryption" (or whatever it was) kept changing so the attack had to respond by "evolving" to get in.

Excuse me, I need to go solicit VC for my new evolving web security startup that is really just Claude rewriting 10% of the infra each day....

Re: A desktop made for one

#265
post #170

Earlier quoted context omitted.

Because its fun. And because your experience using a tool is fundamentally different if you made it yourself, compared to if its something someone else made for you. I don't think I can explain the difference, but it feels really different. Even if you used claude.

It never felt fun for me to write software fully with LLMs. It feels disorientating, it produces a lot of code that you have no familiarity with and no authorship. It feels like you’re a teenager again, copy pasting code from internet or journal and hoping it will work.

I promise you some professional developers mostly get better at figuring out what to copy before pasting. Those folks are going to be fine with having no authorship over the majority of the code they put into their applications. For others, there’s a tension between wanting to write and understand the code on one hand and wanting to be a product manager over the application and delegate some control to the LLM.

Re: A desktop made for one

#266

Earlier quoted context omitted.

Software made for one, made by LLMs which regurgitate the average of existing tools, are going to have more security issues, not less.

But how would you exploit them when every one of them is subtly different? With software that's deployed to millions of computers you have an abundance of targets, but trying to target some random LLM average todo list at scale is hard, isn't it?

Supply chain attacks will still work. Most people aren’t going to have a custom Node, a custom CPython, or all custom libraries. One can fuzz software without the source for common classes of vulnerabilities. With the same handful of models writing a bunch of that bespoke software new horizons open up. Maybe GPT tends to insert the same bug over and over, while Claude inserts another.

Maybe, in fact, some group somewhere combines supply chain attacks with models and/or agents. A model or agent that’s compromised upstream and becomes designed to insert a backdoor is not beyond possibility.

Re: A desktop made for one

#267

Earlier quoted context omitted.

But how would you exploit them when every one of them is subtly different? With software that's deployed to millions of computers you have an abundance of targets, but trying to target some random LLM average todo list at scale is hard, isn't it?

I am imagining some poor sod working for NSA TAO trying to hack a bespoke web microservice stack. He spends dozens of hours slaving away at the keyboard, skipping sleep and eating terrible meals at his desk, desperate to get RCE as quickly as possible, because he needs to traverse all the way to the DB layer and exfil data or his boss will pass him over for his next promotion. At day 9, right as he is getting ready t…

Why wouldn’t he use an agent to find the weakness? How would he know what language is on the backend of a web service without already having infiltrated the server? If he’s in the NSA, why wouldn’t he just sneak a vulnerability into common PHP, Nim, or Rust libraries the site is likely to use?

Re: A desktop made for one

#268
post #81

Earlier quoted context omitted.

Agreed I’ve already started writing software for myself using Claude. I would never have done this if it weren’t for AI - I simply don’t have the time otherwise . I now have tailor made apps with all kinds of bells and whistles that commercial products can’t offer easily ( I fall under non commercial usage which opens a lot of doors ), and that free software might offer, but later. I have also learnt a lot technicall…

I don't know how to tell you this, but people have been writing custom software for personal use for decades. I've been doing it since at least 2009! I find it hard to believe that there is a demographic of people that were yearning to write code, but simply could not because they lacked LLMs. Is it the price? Are people simply too cheap to buy books? Or have they simply "forgotten" how to patiently and thoughtfully…

> I find it hard to believe that there is a demographic of people that were yearning to write code, but simply could not because they lacked LLMs.

I am in that demographic. I have been hacking on other peoples' software as a necessity, to get it to work or to do things I wanted that it didn't yet do, all my career. LLMs came along and afforded me the opportunity to act like a full time programmer when I'm just a paranoid systems monkey who is normally obliged to treat programming as a barrier to be overcome, not a career or even primary hobby.

In my specific case, the reason I was yearning to write code but did not was simply because there weren't enough hours in the day, and I wasn't told that I should spend my on-the-clock hours doing it (unless it was for automating my job). So despite the fact that I have had hundreds of instructional hours of programming classes, learned the basics in half a dozen languages, and been "hacking" code for years, none of it stuck because I never had an employer say to me "right, you're going to be responsible for writing (or maintaining) this Perl app here..."

> Basically, I am prepared to accept that there is a friction that LLMs lubricate away, but what is the source of the friction, and why am I (and a bunch of other colleagues) not feeling that friction daily in our practice?

Learning a programming language and then not getting to use it more than a few days every 3 years means you don't actually learn the language. It's more like a pleasant evening playing a game.

You and your colleagues are, I presume, programmers. I'd wager what I just described is Greek to you. So try to imagine it this way: somebody comes out with a crazy new prototype CPU. It's got a radically different ISA, so it doesn't even have C on it yet -- you have to poke registers with a brand new language that's like Ada on mescaline and it's built on a flavor of assembly that's like nothing you've ever heard of. So your boss tells you to learn it, then 2 weeks later pulls you off the project to do something normal and takes the dev board away.

If you don't see that CPU again for 3 years, how long are you going to retain that bit of knowledge you acquired? Well, that's what it's like for us programmer-adjacent nerds who spend all our time building systems, replacing failed components, crimping cables, writing disaster recovery documents, adjusting backup schedules, and getting woken the hell up night after night because another filesystem filled up.

I have no data to share on how many of us there are out there in similar situations world-wide, but I have met numerous traditional sysadmin in my time who were competent at automating things with shell scripts, not competent at writing "software" in "real" programming languages, and are probably using LLMs now to remedy that lack of skill.

For every 10 DevOps guys there may be one trad sysadmin out there who knows enough Perl to glue the server farm together and keep it running but can't be bothered to learn Python. Or the ratio may be the opposite. But whichever it is, that demographic very much exists.

Re: A desktop made for one

#269
post #260

Earlier quoted context omitted.

I didn't enjoy it. It flunks my criteria for good AI images, because there is no there there: https://gwern.net/blog/2025/good-ai-samples It wasted my thoughts as I stared at it, trying to learn about the author and 'X uses this' and thinking about how moleskin notebooks related to personal computing etc... only to realize I had been lied to and my time wasted, as he took advantage of my good faith - the good faith I…

> I didn't enjoy it. Then it wasn't for you. No big whoop. > It wasted my thoughts as I stared at it, I think we have arrived at the kernel of the problem. :-) The rest of this comment is left as an exercise for the student.

> Then it wasn't for you. No big whoop.

Ah yes. I remember this in Penny Arcade: https://www.penny-arcade.com/comic/2004/03/24/the-adventures...

Re: A desktop made for one

#270

Earlier quoted context omitted.

I am imagining some poor sod working for NSA TAO trying to hack a bespoke web microservice stack. He spends dozens of hours slaving away at the keyboard, skipping sleep and eating terrible meals at his desk, desperate to get RCE as quickly as possible, because he needs to traverse all the way to the DB layer and exfil data or his boss will pass him over for his next promotion. At day 9, right as he is getting ready t…

Why wouldn’t he use an agent to find the weakness? How would he know what language is on the backend of a web service without already having infiltrated the server? If he’s in the NSA, why wouldn’t he just sneak a vulnerability into common PHP, Nim, or Rust libraries the site is likely to use?

Bro. Come on. Don't overthink it.

I wasn't trying to write a Great American [Cyber]Spy Novel. I banged out a silly short story over maybe 40 minutes while I was eating. Then I went back and cleaned up a bit of the text I didn't like and gave it to the world.

I smiled and chuckled a few times as I was writing, because that's what often happens when an author is making something he's happy with. I hoped a few others would get a chuckle out of it too. I gather that 2 people did, so far. That's good enough for me.

If you're applying to become my editor, please email me at bizinquiries@i_think_so.com during M-F so we can discuss your fee.

Post reply on HN