2,268 karma · joined March 31, 2009
No free lunch. LLMs are capable of writing exploitable code and you don’t get notifications (in the eg Dependabot sense, though it has its own problems) without audits.
We're computer people, so we have a good analogy here; the COVID vaccine did speculative branch prediction. They basically operated _as if_ they would get approval at all stages where they could, parallelizing much more of the process at the cost of a _very_ expensive branch fail if something went wrong.
I imagine I'm not alone in having seen a _big_ secular shift in colleague behavior since Opus 4.5 came out. The organization will lag the behavior, but weird things are happening.
(I'm not speaking to the rest of your points; the crypto-bro stable coin bit was jarring for me too. Europe will just go onto Faster Payments, the US will eventually catch up with FedNow, you don't need crypto).
So, yes, “too much trouble”, much of it nontechnical.
When you do "tool calling" with an LLM, all you're doing is having the LLM generate output in a particular format you can parse out of the response; it's then your code's responsibility to run the tools (locally) and stick the results back into the conversation.
So that _specific_ part isn't RCE. It's still bad for the nine million other obvious reasons though.
https://genius.com/Jorge-luis-borges-on-exactitude-in-scienc...
At any kind of reasonable scale, yes. CUDA accelerators, like most distributed systems, are nondeterministic, even at zero temperature (which you don't want) with fixed seed.
There's going to be a bifurcation; caricaturing it, "operating system kernels" and "disposable code". In the latter case, you don't maintain it; you dispose of it and vibe-code up a new one.
This applies to exploits, but it applies _extremely_ generally.
The increased interest in TLA+, Lean, etc comes from the same place; these are languages which are well suited to expressing deterministic success criteria, and it appears that (for a very wide range of problems across the whole of software) given a clear enough, verifiable enough objective, you can point the money cannon at it until the problem is solved.
The economic consequences of that are going to be very interesting indeed.