alexpotato
3 days ago
Many years ago I was working at a firm that investigated stock pump and dump schemes on Yahoo Finance message boards.
We had to scrape the boards and then analyze messages to see if we could identify the identity of the people running the schemes.
This was 2002 and I wasn't aware that the LWP::Simple existed in Perl (aka the requests library in Python).
I ended up using basic TCP socket libraries to connect to port 80 and do http requests. It was, to put it mildly, a major pain in the ass.
That being said, I learned a TON about how http, tcp, html, etc all work together. 20+ years later, I still use some of that knowledge when analyzing network protocols at work.
I mention this b/c nothing is stopping people from doing similar projects now. e.g. Linux from scratch [0] is one great example of learning fundamentals even though we now have 1 click "launch me a Linux VPS" options.
Joel Spolsky make this point too. Even if you are using Java, it's still helpful to understand how CPUs interact with cache because the highest performance comes from optimizing the whole stack.
sebastiansm7
3 days ago
My work is more data science related, but remember those same struggles where I spent hours, days, weeks, months, even years crashing my head against a problem. A lot of daily hours researching, talking to colleagues, implementing tangential papers that lead to nothing. Most of the time I arrived to a satisfactory solution, but others just have to gave up.
Maybe because I experienced all those struggles I'm confident to delegate a relevant portion of my work to some LLM, being able to validate the results, knowing what to ask and detect easily when something was bad implemented or where I gave ambiguous instructions.
The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions. It doesn't makes me feel comfortable shipping things I don't really understand, but also is nice to be able to do things that previously required years of studying and practice.
We are on strange times.
yourapostasy
2 days ago
> I'm just vibing, don't know the implications of some decisions.
I think the blast radius of the surface area of what we don't know is correlated to the determinism around those decisions. I don't care about how compilers these days pack data structures or arrange the assembler to avoid pipeline stalls, unless the domain demands I must really care about that level of performance. When we get to that maturity level with the decisions we make upon LLM outputs, then this concern dissipates. It is early days yet. Even debugging with LLM's is now materially improving year-over-year, one of my earlier concerns.
alexpotato
2 days ago
> The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions
The great part about LLMs is that you can chat with them about the design, ask them to compare it best practices, come up with a different approach etc.
> We are on strange times.
Agreed!
mcv
3 days ago
I have a tendency to prefer writing my own library for something instead of relying on someone else's. Not always, obviously, but quite often existing libraries fall short or are too complex to use. And solving the problem myself is almost always an educational experience.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
Akronymus
3 days ago
Also, your own library, at this point, is much less of an attack vector than some dependency from a package manager
dotancohen
3 days ago
From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
yomismoaqui
3 days ago
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
michaelchisari
3 days ago
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
dotancohen
2 days ago
One could disable updates of dependencies - especially near-real-time updates. Just updating a week after everybody else will have a lot of potential harm with libraries that have a large user base.
foobarian
3 days ago
If I could have a dollar for every casual strcpy in my DIY libraries I would be a rich man. And would never dare to put them in the line of fire of unwashed Internet :-)
Akronymus
3 days ago
I was more concerned about supply chain attacks, along with the idea of stripping down all dependencies to truly just what you need.
Need a few math operations? pull those in, instead of an entire math lib, for example.
dotancohen
2 days ago
This is an excellent strategy. Don't the front end guys do this already?
ipsod
3 days ago
Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
bluGill
2 days ago
I've gone back and forth on this. I've been burned with third party libraries, but I've also been burned spending so much time/effort maintaining my own library that I can't get the real job done.
ipsod
2 days ago
Same, for sure. I'm not actually sure I've come out ahead. I've probably wasted at least a year of work in each direction.
In spite of my above-stated preference, I used Django for my most-recent project, and don't regret that decision a bit.
v3ss0n
3 days ago
LLMs will easily exploit it these days.
askonomm
3 days ago
For personal projects that's fine, but I'd absolutely hate to work with someone who is rolling their own libs for everything, and then when they leave the company puts an enormous amount of tech debt into our hands. It also really doesn't make for good team-work if a developer always forces their own opinion on everything.
sebastiansm7
3 days ago
In a team environment, those libraries also should be team developed, at least, assure a minimal understanding from other team member.
SJMG
3 days ago
+1 if they litter their own macros on it too
mlsu
2 days ago
Nobody would pay you to do something like this today. You'd be expected to punch that ticket in a couple days and move on.
You would not have time because you'd be fired before you finished. That's what's stopping people from doing projects like this today.
michaelchisari
3 days ago
My side projects are all hand coded for this reason. There's no pressure to ship fast, so why not take the time?
sublinear
2 days ago
Most of the dev work out there in the broader corporate world (not startups) doesn't care about "shipping fast". Writing code is not the bottleneck.
When your day consists of lots of meetings with humans who have technically vague requirements, nobody ever meets you halfway. Your primary job becomes bridging those knowledge gaps mostly by yourself. You have to buckle down and make independent decisions that neither the stakeholders, nor the LLMs, can help you with. You get paid because the organization trusts you with lots of information that only lives inside people's heads.
In that situation, the LLMs are only really useful for familiarizing yourself with the existing code. They are completely irrelevant to writing code. You'll have entire two-week sprints to make very precise changes to only about a dozen lines of code, but the coding is not even 10% of what you're paid to do with that time.
In my opinion, this is what senior software engineering always was. Everyone raving about LLMs are basically code monkeys working in sweatshops.
foobarian
3 days ago
Terry Tao has a term for this I liked quite a bit, "productive struggle"
danny_codes
2 days ago
A luxury for the wealthy now, unless you want struggling to be your hobby. But not that many people have 60+ hours of cognitive work in them indefinitely
a96
2 days ago
The foundation of all learning and intelligence being a luxury for the wealthy is such a fantastically American sounding idea.
lioeters
2 days ago
Reminds me of "creative discontent".