Live data from Hacker News

The Coming Loop

lucumr.pocoo.org

281–290 of 322 posts

Re: The Coming Loop

#281

Earlier quoted context omitted.

Ensure you check every PR with opens4.8 or fable - they catch every security issue upfront.

This isn't going to work because the LLM doesn't have enough context. Many security issues involve a failure mode which cuts across multiple parts of the code. A PR which seems perfectly valid on its own may be the missing piece which opens up a vulnerability. Each component may be fine on its own, but brought together, the system is vulnerable. Think of a machine with interlocking gears; each gear may itself be perf…

Of course you don't just check the diff. Rather in your CI infra, it's important as part of every PR, it needs to be given the full repo to check if it introduces any issues. This works wonderfully on github, even with non SOTA tools like gemini-code-assist.

why do you think it's not possible to have full context of codebase? modern harnesses excel at finding all the right codepaths, even in a large codebase.

Re: The Coming Loop

#282

Earlier quoted context omitted.

And this code is often full of security vulnerabilities. It's just hacks on top of hacks on top of hacks. You end up with 100K lines of code full of weird fallbacks, doing something which could have been done more reliably with just 1K lines of code. I think author's comment about preferring systems which make invalid edge cases impossible rather than implementing fallbacks is hugely important. With the fallback appr…

Ensure you check every PR with opens4.8 or fable - they catch every security issue upfront.

> they catch every security issue

No they don't! They catch a lot but certainly not all of them. I can't explain why but it 100% happens.

Re: The Coming Loop

#283

Show me the billion dollar solopreneur startup, or the profit increase for companies and at that point I’ll start thinking that this tasteless high level wanking might make sense in some way

This company got valued at $250M https://polsia.com/ and is a one person startup. Lots of people think its more or less a hype job but given "ai agents" have only really existed for a year or two now it's sitll early days.

The website is unclear about what it does, but the about page is rad. Took me a minute to get the reference. :)

Re: The Coming Loop

#284
post #49

>Yet even with a lot of manual steering, that type of code does not come out of LLMs naturally, and even if the code comes out naturally like that, they will still attempt to handle now impossible errors. This is something I’ve struggled to fight against in many PR reviews. Especially once already written, convincing someone that their excessive null checking is harmful is an uphill battle. Short of better modeling (…

> convincing someone that their excessive null checking is harmful is an uphill battle.

The argument that seems to hit home more often than not is that optionals effectively “fork” the state space, the possible states your program can be in. And the larger the state space is, the harder it is to reason about the code and maintain it. That’s actually part of what make undesirable states un-representable means.

Re: The Coming Loop

#285

My experience is that I am bottle-necked on specs. The agent loop is less of a thing for me now. If I can get a clear understanding of what I want to build, communicate that to Claude Code in planning mode with the goal to write an actionable spec (not code, plan to write the spec) then I tend to get very good results once the agent goes to implement. But this strategy, while effective, puts a big load on me to write…

This is exactly the way it should be! This is great! This is the most important part of engineering of systems that has been minimized over the past two decades in the rush to build. Now that the building is more automated, the specifications and system design can take the important lead again. Engineering and quality might be back!

Do you really believe that? If I would be employer or manager of developers saying that they need to carefully design whole system for the agent to implement, so not a technical person, it would look like their are buying their time.

I believe that it will be the case. 'What design?! Just feed Jira ticket and business documentation to Claude and quit stalling!!'

Re: The Coming Loop

#286
post #248

> We may create codebases that are not merely hard to maintain by humans, but that assume machine participation as part of their maintenance model... People more and more merge code they cannot fully explain. People lose their ability to create issue reports or discuss things in chat, without augmenting or rephrasing their messages with the context provided by a clanker. Too many people increasingly rely on a machine…

What's your product? I'm dying to see how the product developed to 100x human standards by agent swarms is. Must be amazing.

/s

Re: The Coming Loop

#287
post #273
post #238

Earlier quoted context omitted.

> Note that maintainability and code quality aren't synonymous, code quality is just a means to an end, and that end is maintainability. Many orgs are quickly moving to a world where code quality and maintainability are not a priority, at all. If claude is just going to write the code, does it matter "maintainable" or "quality" it is? No. It just matters if it works, and if its fast, is how the perspective goes.

The irony is that coding agents are, if anything, more affected by technical debt than human maintainers (who at least occasionally have the taste to rise above the level of the current codebase they're working in). The impact on productivity may be initially delayed, but it's going to compound faster.

Not unless agent increases in capability faster than it compiles debt in the codebase!

There has to be some kind of theorem in here, since agent actions (including debt generating ones), are training data for future agents.

Re: The Coming Loop

#288

Earlier quoted context omitted.

This sums up the dynamic: https://x.com/danhockenmaier/status/2021617680525172840

What a smug, dickish way to try to make a point. (But he’s still on Twitter, so I guess that makes sense.)

I detest Elon Musk but I still use Twitter because there just is no alternative to it if you want decent tech discussion.

And I don't think it's smug or dickish. I like AI and I encourage even inexperienced software developers to use it. There's just no denying that the slop cannon phenomenon is still a very real phenomenon.

Re: The Coming Loop

#289

Earlier quoted context omitted.

Would you have a breakdown of costs/benefit? Can you say with certainty that this workflow has increased productivity so much that you are seeing profit increases that you wouldn't have otherwise noticed just by hiring more people? Asking with no ill intention, I just crave for actual business cases that make sense, and yet no-one seems to be able to reliably produce that.

> Can you say with certainty that this workflow has increased productivity so much that you are seeing profit increases that you wouldn't have otherwise noticed just by hiring more people? Has the bar raised so much that coding agents need to be even better than any human could do? If the coding agent lets you get done with 1 person what would've required a team of three and you are not going crazy "token maxxing" sp…

First of all, I don't accept a discussion where humans are placed on the same level as bots or agents. Even if the cost is the same, humans MUST be the choice. They have emotions, families, sons and daughters, they are a what makes society a society. And yet we've been already instructed and hypnotized by the Altmans and Musks and Bezos to only see it through the lens of profit and revenue.

That said, is what you're suggesting even happening? Because certainly that is not what we're hearing from companies that fucked up their budgets with AI tools. Also, trillion dollars valuations are really justified by random solo-devs creating automatic companies of one that could be companies of four? Because what I hear from the AI-accelerationist is "this technology creates productivity gains for each and every company by enabling automation at scale that would make replacing human profitable". Where is THAT?

Re: The Coming Loop

#290

Earlier quoted context omitted.

TL;DR of this and many other comments: Oh, AI is so good but it is so bad! You guys got some severe personality split you'd better hurry up fixing.

I think that the problem basically arises due to the fact that the technology is recent and the opinions on it are hard to make and even if we do end up making opinions, then my opinion is of the fact that I am more than happy for AI to suddenly vanish but clearly that can't be the case and there have been some long term discussions that I can point out to. We can however change our opinions on AI and the culture sur…

Thanks for the detailed answer, which pretty contrasts with harsh brevity of my comment (sorry if it offended you), I wish you well too of course, me myself being a half-techie/half-artist torn about this double-edgedness of things, I know why there's that split, we all adore the figurative hammer that helps driving nails into walls, but hate it when someone starts using it to drive nails into their or their neighbor’s heads.

But I think everyone, sooner or later, must draw one's personal red line in the way of a hammer that is set to replace humans or turn them into reverse centaurs who forget how to use their own brains - be it by its nature or by the pressure of someone's trillions of dollars.

I, for one, have already drawn one and refused a promotion (which would mean a 2x higher salary) at my work from testing to backend development, because everyone in our development team rushed into using AI agents, which is something I don't want to touch with a 10' pole. That wasn't even the team's decision, it was the company owner's, who decided it's the way of future.

The results were not long in coming, I already hear their complaints about getting lost in the codebase they themselves created, and getting dumber.

Post reply on HN