[object Object]

Autocorrect hates me, I am sorry.

  • 0 Posts
  • 239 Comments
Joined 10 months ago
cake
Cake day: July 20th, 2025

help-circle




  • [object Object]@lemmy.catoSelfhosted@lemmy.worldDegoog - 0.15.0 Stable Beta
    link
    fedilink
    English
    arrow-up
    47
    arrow-down
    12
    ·
    9 days ago

    I love that Claude.md file, fucking awesome.

    AI is great, I use it to get started quickly, and then I delete a bunch of it and replace it with human approved and purposeful code.

    The other day I used it to write a slugify method. I didn’t think I needed a full library imported for that, and with AI that was a 30 second task, including tests. Great.

    Then later that day the AI wrote an API for me. The AI design hid potentially async code in a synchronous block and it butchered the control flow, so I rewrote it to give the caller control over how the code was executed. The result is exactly what I needed, and easy to use plus maintain. Also great.

    The difference between that and slop where I never even review the file is massive! I like your power tool analogy. Yeah, I could use the spokeshave… or I could just use a router. But if you’re building a jig to turn your table saw into a jointer you might wanna take a step back and ask what you’re really doing here.


  • For posterity because I didn’t explain why/how it’s sketchy:

    • they just found a hardcoded key that skips all security that was in the wild for like two years
    • significant vibe coding means nobody actually understands the codebase. Hence not finding the backdoor key
    • some of the documentation is only in Chinese, which isn’t sketchy in itself, but given the backdoor key does seem fucking sketchy.
    • they have an X link you cannot remove from the admin console
    • the admin console has minor but stupid bugs: you can’t go from a bucket to the list of buckets, auth is janky, etc.

    Just because it’s good a good name doesn’t make it good pedigree (which is a bone I have with rustXYZ named projects). The fact nobody caught serious backdoors for years is damning.

    If you’re running this offline, it might be fine for you. I still run it inside my vpn behind auth but I’m looking to move off.