985 karma · joined January 27, 2024
You'd have to specifically task it with disabling default safeguards to make this happen.
I majored in history. I'd say the data is misleading. I drew a boy "In the Ganges Plain, 1411 BCE". According to the summed up data he had a 54% risk of dying of neonatal tetanus, sepsis or dysentery. Which isn't wrong as such, but it would probably have been better to sum it up with all the other diseases, parasites and infections that would be needed to reach the 54%. Like resporatory infections... "Other causes" is listed at 14%, I assume that malnutrition is part of this, but malnutrition would be the leading cause in the 4-8 year age group, and less so in others.
The life stories themselves are over dramatic. Which isn't weird, considering you don't have a lot of source material dealing with the "boring" lives. Like if you think of Scandinavia in the VIKING ages you'll find a lot of research and data on the people who went viking. In reality 95% of the populations were farmers who didn't even see the coast in their lifetimes. Unless the AI is specifically tuned to value the few sources on everyday farmin in Scandinavia higher than the ones published on viking culture in general... Well.. I think you get it.
That being said. Many people probably don't know that you could have 18 children at only see one of them grow to the age of 20 a few hundred years ago. So the data is accurate enough to be educational in my opinion.
I do think the "typical marriage age" might be suffering from AI safe-guards. For most times I've tried it seems to land oddly close to 18. Which is unfortunately much higher than reality.
In the big threat picture a vibe coded web tool that's not on the internet and runs in total isolation on it's own management group on the "this might get hacked" tenant in Azure is nothing though. I'd worry more about all that OT which was compromised from the factory which sits around in the energy sector. Especially because it's very easy to draw you a risk analysis that will tell you that unless you're running a Nuclear Powerplant then it makes no financial sense to secure your stuff. The audits are so rare and the consequences so low that it's cheaper to just pay the fine (if you ever get one).
Most actual security happens when someone on the ground decides that it's just too stupid that something clearly labeled "DO NOT PUT ON THE INTERNET" was put directly on the internet.
If you really want to go into it, I've previously talked about how we used AI tools provided to us by one of our major investors who do so for all the companies they are invested into. These were also Anthropic and OpenAI models. The main difference is that Cowork has access to files on a users one drive (and that we get a lot more control over what goes into it).
I still doubt we will ever give an AI access to run code on our systems directly though. In isolation, sure, but other than that.
This is a side note, but my personal favorite part of Cowork is that I can roll out our compliance policy to every developer as a Microsoft Teams app (no, that makes no sense to me either). So when they try to install some package that isn't pre-approved their Cowork agent won't let them and will instead explain how they might get approval. If they then continue to reference it, Cowork will even alert us.
From an enterprise perspective this becomes complicated for various reasons. RBAC is one area. In the perfect world you have a system to handle roles and rights to every system, something that you can give managers access to so they can maintain the access available to their employees, something linked with HR. In reality you have EntraID with a hieracy which is sort of automated by HR data, but not really, because sometimes HR puts everyone on the CEO level by mistake, and, if you trusted HR as authoritative that would've just broken all the EU laws. So you have all those Entra groups and you need IT Operations to maintain them and since you want to build it on job roles and not people you'll typically not be able to maintain them in the off the shelf system. Which means that you would have had to build a web portal for the plant managers manager where they could maintain a couple of Entra groups in a web interface. That or you'll have to setup an IT support flow where you add yet another system that IT has to maintain access for.
Then we get to the actual customization. Maybe you buy a custom API on top of your BC365 platform. Maybe your C-levels deciced that paying €50k a year to avoid outages on major updates isn't worth the cost. Then when things predictably and completely avoidable fail you're going to hav to deal with the literal shitstorm. You'd think that all the people being locked out of their jobs and the €150k cost of getting an immediate and prioritised update to the system would mean you'd start paying for that $50k service after this. You'd be wrong. Ok, to be fair, in this particular example it would be a different scenario. For a small system like this you'd find a cheap consultant house in your area and get them to build the customization for you. Only they would outsource it to some solo developer who will build it in a way that basically requires that specific person to alter it. Then when it breaks or needs to be customized futher a year down the line, that person is no longer a solo developer. So you reach out to another cheap consultant house and do it all over again, from scratch.
This doesn't even mention how poorly all those 300 off the shelf systems work together. I mean, I don't maintain a SDK delivering a way to use Apache-Arrow to write and read parquet files from our datalake in the same manner for fun. I do it because those 600 container apps which basically simply translate data from one system to another need it to be as slim as possible.
Am I jaded? Sure. But who isn't in enterprise IT?
As you point out this portal isn't that, but what protects us is the processes around compliance. This can't grow from X to Y because not even the CEO has the authority to overwrite our compliance gates. The EU is a tremendous help in this area since personal liability changed things completely.
Don't get me wrong. It's not great. It would never pass any of our policies for things that actually operate stuff on the power grid, but as an administrative tool that can live in total isolation from the vital networks. It's perfectly fine. It's also not like we would have hired the best software companies to build it otherwise. We'd hire some low-level cheap consultant house who would then likely get cheap student labour to build it. With that in mind though, the AI is much better than what the realistic alternative would be.
Money wise it's also cheaper. It's been roughly €1000 + the time it's taken us both. If I had known they were doing it, I would have rolled out the developer cowork app/skills/whateveryoucallconfigurationsthesedays to them. This would have avoided their AI building it to be depoyed on a VM rather than in our managed k8s in our Azure. It would also have written the code a little different, used UV and maybe django rather than flask. But hey. For what it is, it's like a 90% cost saving compared to buying what would've been a less maintainable and lower quality system.
I think perhaps the greater issue will be finding people who want to extract the gold from the heap of shit and getting it to run in production. I don't personally mind, but it's not like any of my colleagues would've wanted the task.
MMO's let you go online and be social and build communities. WoW did that really well back then. Eventually as things went on, MMO's got more and more tools that let you avoid building those communities. Like the dungeon finder in WoW. I think a lot of MMO's and games in general turned to letting peope get their dopamine fix from increasing numbers through RNG rather than being social.
I know people who stuck around with WoW because of the social communities they build. One of the guilds I was in 20 years ago still meets up in the real world, I know because one of my old friends still plays. I also know people who stuck around because of what is essentially the idle gambling. I became a jock of sorts back around the burning crusade release because I had to put a lot of focus into water polo training. Which meant I didn't do a whole lot "nerdy" stuff for a decade. Once I started doing "nerdy" things again it was easy to find people near me because everyone is a "nerd" these days.
I rarely speak about it but something about reading you accepting the failure of your ambitions made me want to do it. Are you sure it's a failure? For me family life turned out to be what I wanted and work is just a fun place which makes me money, but I totally get why people want to do it the opposite way. In some ways you could say that I did something significant, but it made me misserable. So I failed just as much as you, if not more.
I don't regret any of it either though. It's what made me who I am.
I would say that this is very on point. Even during the renaissance "inventing" was a hobby for the aristocracy, as the author gets around with Giovanni Fontana. I'm not sure if a bicycle would've been a "cool" invention at the time. Because what would you do with it?
For the majority of people there was very little need for personal mobility in society. I know we have this nice fantasy idea of towns having taverns and getting visitors, but in reality, most towns didn't even get what we'd consider a modern pub until the industrial revolution. Sure there were ale houses, but an ale house wasn't a permanent establishment, it was simply whomever had most recentely brewed beer. You'd bring your own chair, and your own cup. So even if you had a bicycle you would frankly have nowhere to go.
Unless you're speaking about a specific Ceuta incident in 2021, in that case just ignore me.
AI changes that. Especially because it appears that LLM's can't understand the OOP abstractions any better than your hardware can compute it.
That being said. OOP and DOD both have advantages and disadvantages. If you go back to what I said first it wasn't exactly a failing of the OOP paradigm. The biggest issue I have with OOP is actually that it's too easy to do things wrong with it. Which isn't helped by the multimillion dollar industry which thrives on teaching developers everything except core computer science. People know their DRY, SOLID, CLEAN, TDD, Agile and every design pattern in the world, but they don't know how the interface they've just implemented actually handles their data.
That being said the modern war logisitcs (and economy) are sort if wild. Imagine the USA and Canada were in a land war and you needed parts for a bunch of drones. Rather than turning to your goverment or official military industrial complex, you'd turn to Temu resellers on Amazon to get your fiberoptic spool. Which means it's a legitimate target, but I suspect that it's also a great way to impact a lot of Russian citizens without fire bombing them.
It's crazy that you could face 35 years in jail for trying to free knowledge in a harmless manner. The longest anyone has been imprisoned for in my country in modern times is 26 years, 11 months and 6 days. We have a few people posed to break that record. Peter Lundin has been in prison for 25ish years, and him and Peter Madsen (the discount elon musk turned murderer who killed some poor journalist in is selfmade submarine) are contenders to people who will probably go beyond 35 years.
Not that our system is perfect. I think we're far too lenient on some crimes, but risking 35 years in jail for downloading and sharing academic knowledge... That's objectively evil.
I think the way I worded it was maybe a little too close to just being about hardware, because performance do matter a lot in the energy industry. I do think it applies to SWE in general. You mention .NET and I've met C# developers with years of experience who couldn't tell you the difference between IEnumerable and IQueryable. I've met even more experienced Python developers who don't know what a generator is. Stuff like that, not having knowledge of the tools they use. I guess you could argue that those are bad developers, but I don't personally think that has been the case for most of them. Still, you'd rather have someone who thinks about these things rather than eventually using batches once they run into memory issues.
I also think these changes are appearing faster in non SWE enterprise. As you said, product owners who are AI explorative (for the lack of a better word) are rock stars. We see this a lot in our finance and risk departments, where domain experts now write fairly decent software with AI. My team has build them tools so that they build things the same way, use the same developer setups and pull the pre-approved external packages or are offered alternative ways of doing things. A few years ago this would've been done by these domain experts "ordering" the software they needed from our SWE team, and if they hadn't already been mostly laid off due to Putin's invasion of Ukraine changing the markets, I belive they would've been now because of AI.
Because frankly, a lot of the software that gets produced in these areas, don't need computer science, until it does, and the domain experts can make the software they need so much faster than before by vibe coding it. From my perspective it's not that much of a difference in the quality of the code that gets produced. I also had to help with performance and security when we had more software engineers on staff. Though now I do it more through writing and distributing AI agent applications rather than writing a C binary or optimising the code directly.
A few months back this would be something every developer kind of did on their own. Maybe they shared skills, we certainly encouraged it and tried to do all the change management things, but nobody really had the same versions of the skills. Which was horrible in the deployment pipelines, something like the compliance documentation often had to go back and forth several times before it could be approved. Now it's just there, for everyone.
In a year or two, I expect a lot of these things to have become even more standardized. So that we don't even really have to build our own apps, but can simply use the ones in the catalog with minimal configuration (and that config will likely only be necessary because I'm from a tiny country that nobody will maintain standards for).
This isn't something which is unique to software development though. We're currently building enterprise AI apps that we can deploy into the AI agents working for anyone of our employees. The key thing we're currently seeing is that the people in a team who are the ones that everyone turn to for advice, are the only people who aren't in "danger". Even people who are great at their jobs are being outperformed by AI in many cases.
I think it'll be a massive challenge for our society in the coming years. Maybe we're even going to get to the point where the AI will also be capable of replacing a lot of the "domain experts". Right now that seems far out, but then, if you had asked me about AI four months ago I would've told you it was all hype.
Email is probably the closest to anarchy. If you could get people to use it for group communications, every user could decide who they include in their "reply all", which would probably lead to absolute chaos.
An average employee cost around $30000 a month in my country. So it would be 3.3% in the budget for this single employee. I looked up average cost on a company our size and an IT budget of 5mil in Microsoft expences, and a max AI spending limit on 150k across the organisation would be a 5% increase of the IT budget on Microsoft services. Please note that these numbers are not ours, but averages from organisations in my area of the world.
Now I can say that the IT budget is one of the smaller budgets in non-tech enterprise. The cost of a 5% increase in the budget would not even trigger the audit margin for error in the big picture. I don't think you're necessarily wrong about the FOMO. I think that for many organisations this level of spending might trigger questions about why we aren't spending more.
This is the difference between small companies and enterprise. I once worked in a place that spent a million a year on unused Adobe licenses. The c-levels didn't even send an acknowledging reply to the email sent informing them it had been shut down.
If you find yourself on the outside, it might just be that you're the village idiot. Before SoMe platforms like twitter, facebook and other places without local moderation the village idiot didn't have much of a voice either.