-
33 votes
-
Microsoft patches a record 570 security flaws
17 votes -
Control the ideas, not the code
20 votes -
The coming loop
13 votes -
Zig creator weighs in on the Bun Rust rewrite
49 votes -
Mesh LLM: distributed AI computing on iroh
17 votes -
Agentic test processes, LLM benchmarks, and other notes on agentic coding
25 votes -
A global workspace in language models
5 votes -
What AI does to the minds of novice coders
26 votes -
A theory of prompt injection (and why you should study roles)
27 votes -
Does generative AI have a natural limit without a major innovation?
I was musing about this recently with the recent models becoming more capable. The core of gen AI is the model, which is trained on a massive dataset. To date, gen AI has improved because the...
I was musing about this recently with the recent models becoming more capable. The core of gen AI is the model, which is trained on a massive dataset. To date, gen AI has improved because the models have become larger, more efficient, the data they are trained on has become better and the software/harnesses around them has improved to help query them.
As I see it, surely the bottleneck will soon become the data they are trained on? If we imagine a scenario where a models could consume an infinite amount of training data, and there is no limit to the training time or quality. The sum of human skill/knowledge is the limiting factor. Gen AI should (in theory) never be able to out preform or push the boundary of the sum of humanity at time of training.
Or, counterpoint, is there enough randomness and speed to iterate that gen AI can actually step change and improve if training times/cost were less prohibitive? Most companies/models today will save good output and feed it back into the next iteration, but right now that's taking months. What if that took minutes?
What do you think?
Is gen AI going to take us to general intelligence?
Will gen AI get to a place where it's "intelligence" and reasoning is actually better than the sum of Humanity?28 votes -
Hacking Google with AI for $500,000
12 votes -
AI is bringing my friend out of retirement
I have a friend that is lucky enough to have retired at 40. A year ago he was adamant he'd never work again, having been burnt out from his time at big tech. Back then he was also an absolute AI...
I have a friend that is lucky enough to have retired at 40. A year ago he was adamant he'd never work again, having been burnt out from his time at big tech. Back then he was also an absolute AI hater and wouldn't listen to anyone who claimed LLMs were useful for programming.
He finally tried LLMs when Claude Opus 4.6 released and immediately changed his mind in the face of the overwhelming evidence that LLMs can in fact program pretty well. And now with the release of Fable 5 he's giddily creating all sorts of things that would have taken far too long to make prior to AI-accelerated software development. He actually plans to try and found his own business now. He's a very smart guy, so I hope he can make something interesting that people want.
There are a lot of AI doomers and haters. In person I mostly see people doing the same thing they've always done, but now saving time on various tasks. But this is the first time I've seen someone go from grumpy and checked out to giddy and optimistic thanks to LLMs.
38 votes -
If you are asking for human attention, demonstrate human effort
41 votes -
Hacking Google with AI for $500,000
26 votes -
What about having an LLM teach you to code?
My daughter (11) is doing a week long Python class, which is not using LLMs. It got me thinking about how I learned to program in the pre-internet days (laboriously, from books), and then what a...
My daughter (11) is doing a week long Python class, which is not using LLMs.
It got me thinking about how I learned to program in the pre-internet days (laboriously, from books), and then what a marvel it was when you could just search for information, especially for troubleshooting. But for her, the first answer in the Google search is going to be the AI summary, and most of her search tools are going to be AI tools.
I wonder if it would be possible to make an LLM that has a didactic/socratic mode. So if you said, "help me write a program to do madlibs" maybe it would give you a skeleton of a function, then prompt you to come to with a plan, then critique that plan. Or if you said, "I'm getting this error", it wouldn't just fix it, it would explain what the error means and nudge you towards the answer.
Thinking in a larger sense, it could have a rubric of important concepts, even tiers of understanding. It could be using the interactions to track the user's understanding, which could let it then tune how it answers future questions, or even be used to customize assignments.
I recognize that this is potentially replacing a teacher with a machine, which wouldn't be my goal. Good teachers are more holistic in their teaching than a machine is ever likely to be. But for people who don't have access to good teachers, or need more directed support than is available from a teacher, or just want to self study, it seems like it could be a valuable addition.
Until they solve the obsequiousness problem, it would be vulnerable to prompt hacking, so really more of a tool for someone who recognizes the value of learning over just being given the answer.
What do folks think about using such a tool? What would you want it to do, or not do?
Aside: I forgot until I reached the end of this post, but this is also (somewhat) the plot of The Diamond Age, or A Young Lady's Illustrates Primer by Neal Stephenson.
25 votes -
Will you be left behind if you don't use LLMs to code?
17 votes -
Any fellow software engineers using paid GitHub copilot?
Much to my chagrin, the company I work for has done a lot in terms of steering/ pushing all software development be done through AI for some time now. And what gives me much grin, GitHub changed...
Much to my chagrin, the company I work for has done a lot in terms of steering/ pushing all software development be done through AI for some time now.
And what gives me much grin, GitHub changed their pricing structure for copilot. I'll skip the details the key fact is what used to be about $30/month per person + maybe few bucks in overages is now resulting in us hitting our usage cap on the 2nd day of the month. Overage costs this month will be hundreds of dollars per developer. I know this is an unexpected expense as I mentioned it casually to our CTO who had no idea.
I'm curious if this is going to force them to rethink the AI strategy. The incessant pushing to use more and more AI maybe will finally bite them on the ass so much they have to ask us to stop or pull back? Or maybe they'll just plunder our salaries, who knows.
I'm curious if anyone else is in the same situation.
23 votes -
Fine-tuning an LLM to write docs like it's 1995
11 votes -
Code is cheap(er)
23 votes -
rsync and outrage
32 votes -
Did Claude increase bugs in rsync?
21 votes -
Actually useful MCPs
I'm a web developer and find the playwright MCP to be genuinely useful. My LLM is able to navigate my site, measure the size of elements, see console errors, network requests, etc. This is the...
I'm a web developer and find the playwright MCP to be genuinely useful. My LLM is able to navigate my site, measure the size of elements, see console errors, network requests, etc. This is the only MCP I've ever installed and haven't yet had any cause to use others. But I'm interested in hearing what other professionals are using.
28 votes -
Language models are weird for the same reason human cultures are weird
26 votes -
The silent critic
3 votes -
The pressure
12 votes -
AI is killing the cheap smartphone
22 votes -
Project Glasswing: what Mythos showed us
31 votes -
The boy that cried Mythos
33 votes -
Aurora: A leverage-aware optimizer for rectangular matrices
14 votes -
Bun has been rewritten in Rust
27 votes -
Multiple security bugs in Dnsmasq
10 votes -
Mythos finds a curl vulnerability
31 votes -
Curl will end its bug bounty program by the end of January due to excessive AI generated reports
63 votes -
Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access
5 votes -
Multi-Token Prediction (MTP) with Gemma 4
20 votes -
OpenAI's WebRTC problem
10 votes -
Teaching Claude why
17 votes -
AI is breaking two vulnerability cultures
19 votes -
Behind the scenes hardening Firefox with Claude Mythos Preview
20 votes -
Synthesizing multi-agent harnesses for vulnerability discovery
9 votes -
AI: Where in the loop should humans go?
18 votes -
Vibe coding is just the return of Excel/Access, with more danger
I probably triggered some PTSD right there. Was just in a meeting at work, where we listed off everything that makes software development hard and slow. An excersize for the thread would be to...
I probably triggered some PTSD right there.
Was just in a meeting at work, where we listed off everything that makes software development hard and slow. An excersize for the thread would be to replicate that list. It turned out that Claude helps with like 1/5th or less of it....especially in a collaborative environment.
So, the situation we're now encountering is that random business areas can vibe code out something, tell nobody, throw it in AWS, have it become a critical part of a business process that fails when they quit, and nobody even has access to look at what was made.
It gives me comfort that in about 5 years there will be a new surge in demand for programmers to reign in all the rogue applications that need shutdown because of the immense risk to continual operation of a company, from data leaks to broken payroll.
It'll be Y2K all over again.
45 votes -
Static analysis, dynamic analysis, and stochastic analysis
For a long time programmers have had two types of program verification tools, static analysis (like a compiler's checks) and dynamic analysis (running a test suite). I find myself using LLMs to...
For a long time programmers have had two types of program verification tools, static analysis (like a compiler's checks) and dynamic analysis (running a test suite). I find myself using LLMs to analyze newly written code more and more. Even when they spit out a lot of false positives, I still find them to be a massive help. My workflow is something like this:
- Commit my changes
- Ask Claude Opus "Find problems with my latest commit"
- Look though its list and skip over false positives.
- Fix the true positives.
git add -A && git commit --amend --no-edit- Clear Claude's context
- Back to step 2.
I repeat this loop until all of the issues Claude raises are dismissable. I know there are a lot of startups building a SaaS for things like this (CodeRabbit is one I've seen before, I didn't like it too much) but I feel just doing the above procedure is plenty good enough and catches a lot of issues that could take more time to uncover if raised by manual testing.
It's also been productive to ask for any problems in an entire repo. It will of course never be able to perform a completely thorough review of even a modestly sized application, but highlighting any problem at all is still useful.
Someone recently mentioned to me that they use vision-capable LLMs to perform "aesthetic tests" in their CI. The model takes screenshots of each page before and after a code change and throws an error if it thinks something is wrong.
10 votes -
Sovereign Cloud stats every CIO needs before their next board meeting
7 votes -
AI Coding agents are the opposite of what I want
I've been thinking a lot about LLM assisted development, and in particular why I keep dropping the available tools after a few attempts at using them. I realized recently that it's taking away the...
I've been thinking a lot about LLM assisted development, and in particular why I keep dropping the available tools after a few attempts at using them.
I realized recently that it's taking away the part of software development I enjoy: the creative problem solving that comes with writing code. What's left is code review tasks, testing, security checks, etc. Important tasks, but they all primarily involve heavy concentration, and much less creativity.
Why aren't agents focused on handling the mundane tasks instead? Tell me if I've just introduced a security vulnerability or a runtime bug. Generate realistic test data and give me info on what the likely output would be. Tell me that the algorithm I just wrote is O(n^2).
Those tasks are so much more applicable to matching against existing data, something LLMs should be extremely good at, rather than trying to get them to write something novel, which so far they've been mostly bad at, at least in my experience.
46 votes -
Gemma needs help
31 votes -
Designing an agent reading test
10 votes -
Google releases Gemma 4
28 votes -
Linux kernel czar says AI bug reports aren't slop anymore
30 votes