What is vibe coding? How creators are building software with no coding knowledge
alitu.com
alitu.com
My only concern of this type of programming is when it starts involving end users, specifically around privacy and security. It is not that AI written software is less or more secure. It is just about the whole live-cycle of software development and maintenance. Vibe-coders might not visit this forum for example and might not be aware of a security exploit that must be fixed asap... or even be aware that they need to perform basic level of software support to avoid costly intervention in the future. It is not going to happen - not today.
I am thinking that this type of coding is only going to increase the demand for professional services. The closest analogy I can provide is that almost anyone can perform basic level of DYI and many do - but when it comes to more serious work you rely on contractors to get the job done.
This is true of "regular" coders too, i've worked with/for extremely experienced programmers who, while knowing the security risks, implemented (or even worse, asked me to implement) flakey authentication systems, exposed databases, etc. I don't think this is an AI issue, it's a "care about your users" issue.
> is only going to increase the demand for professional services
Then shouldn't we be happy that more people are embracing vibe coding?
I don’t know about you, but I’m not looking forward to reverse engineering and maintaining someone else’s vibe coded mess.
It’s like when someone makes a quick and dirty proof of concept to impress management and then hands it off to another team to make it usable in production. They did 20% of the work but took 80% of the credit. Now you have to to the remaining 80% of the work to make it into what it needs to be, but management is only going to be disappointed because you’re moving so slowly relative to the proof of concept creator.
Java is a language designed to make it possible. Java style classes make it possible for someone to design the overall structure and pass it to someone who just vomits something inside it.
They have teams where maybe 1 in 3 consultants have programming knowledge and the rest just vibe something into the Java API that is given to them. Back and forth until it passes and then to the customers. LLMs make this just faster and maybe even better.
The code will be bloated, slow, and hard to maintain.
Having worked in a few codebases/projects by these companies (and some other "big name" consultancy companies in this same "space"), I cannot imagine copypasta from Claude/Copilot would be anything other than a massive improvement.
What companies have paid these firms to do is nothing short of appalling, and I'm not even referring to the notorious Hertz lawsuit, just the average run of the mill junk.
Java classes are no more enabling of shit code than any other language. Idiots can and do “vomit” code into pre-canned structures built for them in any language.
Java classes and types are strict and "save" enough that it make it possible to put straight jacked to coder, but loose enough that they can make it compile. You can't do that with C++, Python because they are too loose and you can't do it with Rust or strict functional programming language because vibe programmer can't make the code compile.
It's perfect when you have software architect who does the intelligent work and code monkeys who fill the blanks.
I’m not sure about that, it may be true, but you can also build a ecom store without coding knowledge using wordpress and shopify but you still face a lot of limitations.
We're talking about building useful tools. Small things, that work in a way that makes sense to the individual.
Something that could be churned out in a day or two by a competent dev, but is completely out of reach for Joe public.
That's where we're at.
Tools to build web apps and web pages without coding knowledge have been around for over 2 decades. Microsoft Frontpage allowed uses to build a website using a WYSIWYG editor.
Even Wix and Squarespace are "building block" tools when you start to layer functionality on top of the designs.. What you can do is limited by what the developers of those tools put in them.
AI lets people build much more bespoke things, and build things that others haven't necessarily thought of (or haven't built tools to build)..
And that can definitely be a double-edged sword of course, because a non-developer might not know when they're wading into dangerous waters...
Tools and visualizations for debugging that I might need only for a week, local dev automations, linters, etc.
As long as I can eye-ball correctness, it's a huge time-saver and help.
This is unlike no-code/low-code, where the “coder” still has full control and visibility over the specification and can tinker with it. With LLM-generated code, an increasing part of the “specification” is constituted by the code that has been generated so far, into which the “coder” has no insight. The “coder” can only try to run it to see how it behaves, but cannot reason about it like a no-code/low-code coder can about their specification.
The whole point about the article is that reasoning about the code isn't always required any more, reasoning about the output is enough.
When it's not, fuck it, go ahead and produce that flight sim without researching quaternions. MOST code does not need to be provably correct, or we'd all use Ada.
I just want a free script or addon that will do its job instead of paying someone on upwork to do it for me. simple as.
Additionally it's only up from here. The agents will be able to do maintainable code and safety critical code at some point in the future. It's not all gonna happen overnight.
That’s what AI code tends to do. It looks fine to the outsiders, it might even function correctly MOST of the time. Programmers are trained, mostly through experience but also classically, to think through every exceptional case and figure out how to handle it (or return an error so a human can handle it).
That isn’t to say this is ALWAYS the case with AI code, but rather it TENDS to be the case. YMMV, which is where these warnings are coming from.
Isn't that the definition of gatekeeping? and even so, who cares? the new guy coming in creating/doing something in a way that "shouldn't be done" will eventually fail and notice the shortcomings of what they did. Then they will either drop their project or learn the way "it should be done" (like we all did, except now with AI).
I write really bad Haskell code sometimes without any AI assistance. Am I doing a Bad Thing when I create my own tools?
What are you intending to regulate here?
It appears to be happening right now in the US federal government.
Do you have an example?
Consider that the world is full of programmers who are objectively shit (I live in India, and have personal experience). The only difference is that they’ll be copy pasting from ChatGPT instead of StackOverflow, and honestly I’d rather have ChatGPT.
Most code (even written by good programmers) rarely functions correctly most of the time. Most code is broken. This is not the problem with AI. Unless I am using the tools wrong, LLMs can generate fully functioning scripts (and some of them are good) but they break after the 50k token context and start doing insane things that not even juniors will do (like randomly removing code).
If you want to see a shit-show, go to Bolt Discord channel. Some users are able to get a very simple and rough kinda single script app running. Everything else breaks once they start making simple amendments. This is not fixed by Claude 3.7 or O1 Pro or whatever. This is a fundamental issue in all of the LLM and a local maxima of the current tech.
Not that the current tech is not amazing. It is and there is a lot of value to be extracted from it. But everyone and his investor think they are about to reach nirvana and want to replace everything with "AI" where "AI" is a 100k context LLM.
When a post is a "warning" about user's credit cards etc. and it was in none of the "vibe coding" examples, that feels like someone deflecting (but with a gate keeping mindset).
As others have said here, I too have knocked out little apps and sites vibin'. At first (1) it was to see if what everyone was saying about LLMs was true. Then (2) I wanted to see if LLMs could help in languages I was not familiar with. Then, even for languages I knew well enough, I (3) wanted to see an LLM's code to get the modern method of modularization for the language (JavaScript is one that has gone through phases). Finally I came to trust the machine and (4) have vibed code just for my own small projects.
Gatekeeping is restricting access to the trade with arbitrary precedence, like "real coders use emacs." It's not expecting safety. If someone wants to build a bridge out of cotton the city won't let them. That isn't what most people consider gatekeeping.
Vibe coders as described in the OP can just copy/paste exactly what the LLM spits out with much less knowledge. It’s not the same thing at all IMO.
If you only take exactly what the LLM spits out you can only verify by running. If it is broken in edge cases you can only prompt the LLM to fix. You then have to run the code again to verify the fix, and with zero understanding it may have broken some other edge case (LLMs do this all the time especially overly eager reasoning models).
It might be, it might not. My colleagues and I are also guilty of introducing unrelated edge cases, but again, we do fine.
The case you're describing is also fairly pathological. There's nothing stopping a vibe coder from digging into their code and becoming a 20% monster like me.
Unfortunately, vibe coding is seen as acceptable to many specifically because what you say here hasn't been the norm for like 15 years now.
The rise of bootcamps, dependency-driven-development, and "move fast and break things" culture convinced a whole generation of programmers that all that matters is the happy path, and even then, only within the context of today's specific task. The ocean of garbage they produced during that time is both one of the reasons why LLM's can produce code in the first place and one of the reasons why that code is so consistently and irrecoverably poor by traditional standards. Aspiring vibe coders see their peers earning absurd six-figure salaries to produce the exact same sort of unstable, short-sighted noise that they see their LLM literally reproduce for pennies now.
In many ways, we should be gatekeeping by asserting a higher standard of foresight and quality for redistributed code, but we completely lost that battle many, many years ago already.
The benefit and excitement is most felt by people with little to no experience writing code themselves. The fear seems to come from building.. what, code for critical infrastructure? That's just not what we're talking about here.
Then hopefully they run on a computer without network access, otherwise everything is safety critical.
But to build something which could handle a customer’s credit card, password, or other PII and charge them for it, you better know what you’re doing.
It’s all fun and games until you’re the cause of someone’s identity or password getting stolen.
Anyone can use CAD software, but if you’re designing a public space, you better know something about safety.
AI is just another vector for this, not something entirely new.
When you have your amazing idea, instead of hiring an inexpensive low-skill developer (whose work you are also incapable of evaluating) to build and ship your idea in a low quality way, you're just paying AI to do it.
It's just putting they money into different (centralized) pockets.
When a non-technical person hires an incompetent developer (that they likely don't know is incompetent at the time of hiring) to build something that turns out to be insecure - because the developer didn't know any better and the non-technical person doesn't have the skills to evaluate the output - no one was trying to do a bad thing, but they didn't know what they didn't know.
The non-technical person got something that did what they asked, without understanding all the underlying deficiencies.
It's the same with AI, I don't think non-technical people using AI are thinking "I don't care that this is building garbage code full of problems"..
Just like the first scenario, they don't know what they don't know, and they end up with something that does what they want, and that's a good outcome based on their limited knowledge.
To be clear, I don't think either of these scenarios is excusable or acceptable if you're working with PII or other security-sensitive things, I was just pointing out that this isn't new.
Anyone can play the violin. Anyone can run a marathon. Anyone can …
People who spent their lifetime never quite able to sit down and write programs, for whatever reasons (time, focus, foundational knowledge, available mentors), have in the last year shipped working apps/scripts, by just saying in plain english what they wanted. That's exciting.
So, you pay the billionaires to rent their graphics cards so you can avoid paying a normal person? -_-
Don't hold your breath. If the AI was good enough to do all that, "maintainability" would look very different from what it does today. What does it mean to be maintainable when an AI can completely rewrite the software in every iteration? If AI ever gets good enough to do all this, for safety-critical applications no less, probably 95% of the white collar jobs that exist today will be gone. There may also be robots to do 90% of all other work too.
The vibe coding style translates to trying a lot of different prompts and small adjustments until it looks like it works. In the past these people copied from StackOverflow and poked at lines until it compiled and appeared to work, but that only gets you so far. Now those same people can bang away at an LLM assistant all day long and produce volumes of code that appear to kind of work.
I’m in another forum dedicated to programming careers. Every day there’s a new thread from someone asking how to deal with all of their junior employees spamming code review with obvious LLM generated code that they don’t even understand.
A lot of the defenses of vibe coding rely on the assumption that it’s in the hands of someone knowledgeable who only wants to save a little time for something inconsequential. That’s fine. What’s worrying is that vibe coding is being used as a replacement for understanding code for many juniors and lazy seniors across the industry as long as they think they can get away with it.
worried? we're going to make a goddamned fortune
The people tasked with cleaning up the mess and making it usable in production do the remaining 80% of the work, but management is always disappointed that it’s going so slow relative to how quickly the proof of concept was created.
At one company it was widely known that the key to taking credit for technical work was to be the team presenting the GUI pieces to management. If you were working on something that couldn’t be shown to management with a “wow” factor, you were not valued. I see the same thing happening here, with vibe coders capturing the wow factor and the people who actually make it production stable being viewed as the slow and expendable ones.
Another potential alternative is that these things progress quickly and soon can code and review code at or above the level of most SWEs. I suspect that's driving a non-zero amount of anxiety in the comments.
I'm not an SWE, and frankly, they're above my level today. Saying "plz don't code if you can't understand it" applies to my code today without AI assistance. Are you suggesting I shouldn't release anything because others might need to read it? The way to prevent this within an organization is smart hiring practices, not restrictions on tool use.
I wrote a lot of spaghetti and I confused myself a lot. And it was a lot of fun.
I think the doomsayers ITT are wrong. I think you’ve forgotten what it was like to go from “how do you even make a program” to “I put something on the screen and it’s amazing that I did that”.
I think AI will help a lot of people get over the bump from not even comprehending how software works, to putting something on their screen and evolving their skills from there.
Who cares if they make some spaghetti along the way. That’s necessary for learning. AI or not.
You call learning, making mistakes and fixing them, and improving "a bump"? That's the whole point.
> That’s necessary for learning
You haven't learned anything in the end. I read a lot of programming books in the past thinking I would be a computer god at the end, and I realized I learned nothing because "I did nothing" exactly like what we have with ChatGPT.
What skills? If you are just asking a computer for what you want you're not developing any skills, apart from maybe how to describe your requirements better†.
If you take the code the LLM outputs and use that as a basis to be able to write your own code I would call that "learning to program" and I applaud it whether you learn from adapting LLM code or by reading K&R cover-to-cover before you even touch a keyboard. But that's not what this article describes—what this article describes is the very deliberate act of not learning anything.
†Technically just describing your requirements in a way the particular LLM you're using responds best to, which is not necessarily "better" in an objective sense.
Cursor is that, but prompted by you instead of a stackoverflow question.
About software, it works, fine, but do you ever deal with maintenance, security patches and so on?
Security patches though, yeah, that's tougher. My position is that if security is a concern, you need to hire someone. As much as many of these tools can integrate with databases and set up auth, I'm not sure how much I trust it personally. Especially if the actual code is hidden.
Or do you think a customer who describes his requirements to a programmer who writes the actual program is a programmer too?
Did you use AI to program something you couldn’t do yourself? Did you get the same satisfaction because you solved the challenges or did you feel some kind estranged from the result because or wasn’t really your achievement.
- the end results usually suck: they either feel incomplete, have a major flaw, or just don't work.
- sometimes, the AI just won't understand what the request was, or it will get stuck on a loop while trying to troubleshoot one bug and causing even more.
I believe that code written by actual reasoning people will be miles better than what a machine can. AI should be used for "au-to-ma-tion", and tasks that one doesn't want to or doesn't like to do, like writing documentation.
Here's one instance where this "vibe coding" went right and I got a mostly functional program (game): https://chatgpt.com/share/67a125b3-15cc-8001-9863-13372338e3...
This reaction hasn't happened for AI programming. People just assume it will work because AI is made by programmers.
If you think vibe coding is as easy as this article makes it sound, try deploying a simple website.
Deployment is literally a button. Granted, to a replit subdomain. But following some documentation to add your own domain is not out of reach.
There's been big efforts to simplify this stuff for years. Lots of good tooling out there (which the right questions to an LLM will yield for you).
I think LLMs help with stuff like deploying a website, but they aren't a requirement. You still need to know what you are doing if you want to do something complex.
Though I feel this only works well for tech that are widely used.
This comment thread and this author are mostly experienced devs. Obviously, Automating the first 80% of development this way, you get less happy accidents and less rabbitholing on minutiae which make you a stronger programmer, and give joy. But dang, you get a lot of joy from finishing something too.
And also obvious is the cost of deploying and maintaining. All the SDLC things that come with releasing a product are out of scope here, but that’s likely temporary. It would be great to have assisted deploy build pipeline development I can trust in a product that has a complex blend of old, new, in-house and proprietary service development.
Coffee’s still kicking in. These are my thoughts.
That's not coding at all - if is taken out
(the best user inter interface is that one that doesn't stop you and doesn't exist between you and that thing you interact with - it's about the thing, not about how).
It's magic (and magical thinking, wishes) - things have to happen, doesn't matter how (that how was the coding):
> The magic is always real, but once you understand magic it simply becomes knowledge. That makes it no less magical ( https://news.ycombinator.com/item?id=43216041 ).
BTW Why we calling it AI - not AK - Artificial Knowledge as it is indeed ? ( isn't the intelligence something you supposed to have ?)
I guess this is even more vibe based, the AI’s vibe that is.
codeaway.ai
But to be honest I do take the time to read some code both to clean things up a bit and to learn something new, killing the vibe entirely. So unchill.
I doubt this time around, the AI-flavoured variant is going to change much, except perhaps the volume.
The world ended not with a bang and not with a whimper… in the end, it was the sound of someone double clicking on a file written in a language the person “vibing” it couldn’t read and didn’t understand.
I prefer to think about the ways it could go right. To empower people to create is the very purpose of computers, no?
Of course ‘letting someone do what they want’ seems like it’d be the most empowering thing, what’s more empowering than free will. But doing it this way will not give you any knowledge or skill, if you’d ever need to code without an AI or would need to understand a deeper concept you’d have no ground to stand on.
Basically it’s the instant gratification vs delayed gratification but for programming. Is instant gratification empowerment? maybe for a moment.
It’s not that it won’t help anyone. But what will be the second order effects if it becomes the norm? And I’m not talking just about “jobs”. I’m talking about the growth and empowerment that comes from learning, the critical thought process, etc.
The ability to adapt to a changing world is one of the most useful skills you can have.
I am such a denier. Some colleagues in my department were allowed/instructed to try out AI for coding for months just so that the company could get substantive judgements whether AI is useful or not for coding work.
It basically did not help for the tasks that we are doing (and the tasks that we are doing are quite varied (so there are a lot of different topics where an AI could (purely hypothetically) help), but none of them is "create a scrappy CRUD prototype" :-) ).
Thus: the only impact that AI has on writing code that I don't deny is that a lot of stupid managers fall for the siren call of the various A"I" companies, and cause lots of damage. Of course none of these managers will at the end carry the can for the damage caused.
It's just like the infinite monkey theorem, hitting the enter key repeatedly without understanding the actions and eventually reaching their goal.
You would not see software engineers at SpaceX or NASA "Vibe coding" on software that will be running on rockets or defense technology companies vetting candidates that have been doing "vibe coding".
This euphoria feels like a repeat of the years 1999 - 2000 which we will see a crash that will revert back to reality.
Sure that's true, but I doubt the people with no coding experience who use LLMs to create some application are working on safety critical systems. For me this fad should be embraced, especially by non coders, as it allows them to be creative in new ways.
The whole product will be defined by a specification distilled out of company meetings, slack messages and emails.
There will be only one button labeled "build and deploy" and if something breaks you press it again.
Reminds me of this https://www.sciencedirect.com/science/article/pii/S277318632...
>Non-trivial text generation during the lifespan of our universe is almost certainly impossible.
But the internet stuck around. It was still useful.
Just because something is overhyped, or doesn't meet the standards of the world's most demanding engineering organisations, doesn't mean that it's not here to stay and improve.
Perspective.
After Trump was overtly lying about the US spending $360 billion on Ukraine and that the EU had given their aid as a loan.
The hype is real, the bubble is real, but that doesn't mean it's meritless.
EU/British leaders are very naive. Just like getting everyone dragged into that Ukraine conflict, the US now drags everyone into AI and makes them pay for it.
Just like the war hype, the AI hype will collapse. In one case the MIC made the profits, in the other case it will be tech bros.
The UK recently announced plans to go big on AI even before the Trump meeting. Much to my dismay, as we've actually done a really good job of grid decarbonisation so far and there's no way building a ton of GPU-filled data centres is going to aid that or our spiralling energy costs.
Coding is easy, testing and maintaining is hard.
This is no different than what amateurs have been doing for a long time. Hopefully they’re not taking in PII or charging anyone for these apps.
I think there are likely opportunities too to have models or system prompts that cater or adapt to the experience level of the person it's working with. "As you interact with the user, determine their relative level of knowledge and experience. If they seem to be relatively inexperienced with software development, be much more aggressive in helping to warn them about and avoid common pitfalls, bad architectural decisions, and security issues."
I suspect it's probably going to enable a lot of poor quality stuff, but it also may to some degree raise the floor of what's being produced at the same time.
Versus software I were there’s hundreds of different outlets hundreds of different wires tens of different storage mechanisms. Now if the LLM is even slightly unsure, it will hallucinate leading to a mess when things go wrong that the user doesn’t know how to fix
Then an actual expert will have to come in and try to understand what went wrong, which adds additional time than if it was just built right the first time
edit: english is hard for english speaker without tea
Yes it is. They now have a cohort, a drunk hallucinating expert.
>Hopefully they’re not taking in PII or charging anyone for these apps.
You bet they most definitely are. Also remember that the S in "vibe coding" stands for security.
Neighbors have existed long before AI.