Live data from Hacker News

The "Vibe Coding" Wall of Shame

crackr.dev

51–60 of 88 posts

Re: The "Vibe Coding" Wall of Shame

#51
post #45
post #12

Why is the LiteLLM incident on there? The linked article for that one is a 404. I didn't read any credible arguments suggesting that was caused by vibe coding. They had their PyPI publishing credentials stolen thanks to an attack against a CI tool they were using. Plus the linked article for the Amazon outage is https://d3security.com/blog/amazon-lost-6-million-orders-vib... which appears to be some other vendor prom…

> Why is the LiteLLM incident on there? The linked article for that one is a 404. -> [Endor Labs] https://www.endorlabs.com/learn/teampcp-isnt-done -> On March 24, 2026, Endor Labs identified that litellm versions 1.82.7 and 1.82.8 on PyPI contain malicious code not present in the upstream GitHub repository. litellm is a widely used open source library with over 95 million month downloads. It lets developers route re…

That doesn't answer how stolen credentials are related to AI-assisted coding.

Re: The "Vibe Coding" Wall of Shame

#52

“Vibe coded”? I doubt that there is the documentary evidence that the code in these systems was never touched by a human. At best this is a list of code where AI tools were used in development. To be honest if you just created a list of all outages in all companies and systems you’d probably have a better list since AI tools are ubiquitous.

> AI tools are ubiquitous. Only among people who don't value the quality of their output. There are, fortunately, many who do value quality and are not using AI tools until they get to the point where they can usefully contribute.

Isn't it odd that you wrote your comment with AI then!?

Ha, gotcha, AI slop poster!

I know you didn't, but this is where we'll end up if people just write off everything as 'bad because AI' instead of critically assessing the quality of something on its own merit rather than the (very ironic) 'vibe' that it was generated rather than written.

Re: The "Vibe Coding" Wall of Shame

#53
post #36

Earlier quoted context omitted.

> How much abysmal code and products have we all shipped? > We should be using it to fix all of the terrible software we’ve made over the past 20 years. Instead there are 2-3 camps. People building stuff, people hyping AI and people shaming the first 2. This seems like an odd take. The pro who are using and hyping AI are not fixing all of the crap we put out the last 20 years. They are putting the gas pedal on the am…

I don’t disagree. But what is the detractors’ goal? What will the shaming accomplish? The tools are here and can be used for good or ill. Think about the 90s PC revolution, opening up developer opportunities. There were commercial devs and open source devs. The open source devs decided to put the new resources and tools to use to evangelize computing . And in many ways won. We have new tools now, and can put them to…

> Think about the 90s PC revolution, opening up developer opportunities

I don't think the general arc of computing since the 90s has been good for humanity

As a detractor, that's my goal. I want to undermine this garbage technology that is actively making life worse for the majority of people while enriching a vanishingly small segment of humans at our expense

Re: The "Vibe Coding" Wall of Shame

#54
post #48

Earlier quoted context omitted.

The same reason some use crime committed by illegal immigrants to push action, while ignoring the fact that citizens are more likely percentage-wise to commit those same crimes. It's confirmation bias at the least, and intellectual dishonesty at the worst, but either way, they want their worldview to be validated.

I know this is extremely off topic, but illegal immigrants are far more likely to commit crimes than citizens, not that this has anything to do with software bugs...

You got that exactly the wrong way round.

Here's one set of numbers from the CATO institute: https://www.cato.org/policy-analysis/illegal-immigrant-murde...

The only way your statement holds up is if you treat the act of existing while undocumented as a crime for this comparison, in which case sure - it's a tautology.

Re: The "Vibe Coding" Wall of Shame

#55
post #48

Earlier quoted context omitted.

The same reason some use crime committed by illegal immigrants to push action, while ignoring the fact that citizens are more likely percentage-wise to commit those same crimes. It's confirmation bias at the least, and intellectual dishonesty at the worst, but either way, they want their worldview to be validated.

I know this is extremely off topic, but illegal immigrants are far more likely to commit crimes than citizens, not that this has anything to do with software bugs...

I probably won't comment further, since as you said this is very off-topic (I only meant to draw out an analogy as to why discussions about AI tend to be ideologically skewed), but every statistic I've seen shows far lower crime rates among illegal immigrants versus citizens (aside from the statutory crime of being in the country illegally).

Re: The "Vibe Coding" Wall of Shame

#56
post #12

Why is the LiteLLM incident on there? The linked article for that one is a 404. I didn't read any credible arguments suggesting that was caused by vibe coding. They had their PyPI publishing credentials stolen thanks to an attack against a CI tool they were using. Plus the linked article for the Amazon outage is https://d3security.com/blog/amazon-lost-6-million-orders-vib... which appears to be some other vendor prom…

It seems like blogspam. It's curated according to an author's comment, but it treats ones verified by a security organization like Vite's just the same as ones like the blog post about Claude calling a Terraform command. And this is on a site which appears to sell other AI generated content for a subscription.

Edit: it appears the traditional content is free. What is paid is an AI interview pack, which is basically content with some tokens in order to present the content. They could be cheap Haiku tokens. Also it isn't a subscription, it's one-time purchase of packs. My bad.

Re: The "Vibe Coding" Wall of Shame

#57

Is this meaningful at all, without a control? How often does software fail in production with human-written code? How many times has a production failure been avoided because an LLM didn't make a typo or mistake that a human would have? This is pushing an agenda. It's not measuring anything meaningful.

This is definitely the right question. A list of failures without any baseline won't tell you anything. You would need the same exercise for human-written code at a comparable scale before drawing any conclusions at all. Without it, it's just confirmation bias.

Re: The "Vibe Coding" Wall of Shame

#58
post #28
post #7

For CVE-2026-0755, that's a vulnerability in gemini-mcp-tool. gemini-mcp-tool's Github repo says "This is an unofficial, third-party tool and is not affiliated with, endorsed, or sponsored by Google." but this list shows the Google logo next to the vulnerability. Also, it's not entirely obvious to me that the vulnerability was introduced by vibe coding. https://github.com/jamubc/gemini-mcp-tool Disclosure: I work at…

The first link claims the 6-hour outage wiped 99% of order volume. I went to the "source" and found an (AI generated?) ad by a company that wants to sell a product, where I cannot find the 99% number. This whole website and everything around it are almost ironic.

This site, especially if you look at all the previous posts from this domain, is almost assuredly AI generated.

One of the "fun" hallmarks of many of these LLM assisted websites is that they seem to completely disregard basic accessibility (especially Web Content Accessibility Guidelines [1]). That small dark gray subtext on a black background is just horrific.

[1] - https://webaim.org/resources/contrastchecker

Re: The "Vibe Coding" Wall of Shame

#60
post #11

In my experience over the last couple years, lists like this won’t move the needle at all. The AI zealots reject anything that calls into question the AI stuff, usually appealing to “just wait, better models/agents/guardrails imminent” and claiming that anecdotal productivity gains are worth the risk. The people concerned about AI already are concerned and just fall back to “I told you so”. Unfortunately the decision…

If by 'zealots' you mean the vast majority of developers, who are using AI tools in one way or another. The AI is already substantially better than most humans for a huge spectrum of at least narrow tasks. Those 'skills' will expand in scope, the evidence is overwhelming and unequivocal. Within 12 months it will be considered a 'security concern' to not have AI at least to some degree of autonomous review. It's very…

Can you list a view tasks that AI is better at then other tools? Not humans mind you, because that is unimpressive, I mean other deterministic tools.

For example, I'd rather use a calculator to do calculations than ask an LLM to do it. I'd rather use LanguageTool for grammar than asking an LLM to do it. Id RTFM then have an LLM summarize it.

Post reply on HN