• ragas@lemmy.ml
    link
    fedilink
    English
    arrow-up
    19
    ·
    14 hours ago

    This whole software bug spiel is to convince everyone that it is unsafe to code without using an LLM. Effectively forcing companies to use LLMs.

    • MangoCats@feddit.it
      link
      fedilink
      English
      arrow-up
      6
      ·
      12 hours ago

      It it is unsafe to code, full stop.

      The things we’re expecting our code to handle, with the lack of formal verification testing we’re expecting our code to ship with, there’s no such thing as safe. It took 50 years to “build the stack” to where we’re at, and we did it fast and cheap. There’s so many bugs hiding in the lasagna it’s amazing it doesn’t eat itself.

      If you re-build your system from first principles, open source silicon with peer review and constant scrutiny, then the BIOS, then the OS, then the application compilers, and the libraries, all open AND reviewed by multiple concerned parties with formal demonstration of correctness all the way up - the entrenched bug filled lasagna stack owners will smother you, they can’t withstand that kind of competition on an open playing field, your project will die of financial starvation, regulation, buyouts and treachery.

      • lordbritishbusiness@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 hours ago

        All the shortcut technical debt is coming due, especially now that there’s a tool able to undertake mass analysis with fairly general rules.

        It’s getting bad out there, and it’s not visible on the surface but a tsunami of bug reports and patches has been sweeping the internet and drowning anything unable to swim.

        For anything that sinks underwater, metaphorically, they’re getting grabbed by automated sharks that are now actively on the attack. If you’re not rapidly fixing everything and monitoring everything closely you’re probably being eaten alive without knowing.

        • MangoCats@feddit.it
          link
          fedilink
          English
          arrow-up
          2
          ·
          9 hours ago

          My approach: I don’t expose anything (that can’t handle it) to the internet. So so many things are “out there” that don’t need to be, shouldn’t be…

    • curiousaur@reddthat.com
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      8 hours ago

      I’ve said this a million times. The llms are not better, than us they are infinatly faster. It’s like putting 1000 engineers full time on looking for vulnerabilities for 10 years. Sure you can do that. Or pay for the tokens instead and do the same effort overnight.

    • Kaligalis@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      12 hours ago

      Bragging about how product is at doing something is the easiest way to advertise product. No conspiracy theories needed.

      They want you to use their LLM to screen your code for bugs. When you do that, you see how surprisingly well it works now and that leads to you wanting to also use it for generating code. That is when you realize that the 20 bucks starter subscription isn’t enough to actually use it professionally… which means, you upgrade and they get moar money.