Objectively, a terrible hammer. But a reminder that we still are in the earliest days of GenAI touching various fields. image Like CAD. Wehere I think the impact of GenAI will be enormous. Natural place for it. So many human hours spent creating extremely simple repetitive things with slight variations. Checking in on the incumbent Autodesk..and looks like they are incorporating AI in assistant / #ML ways. image Looks Interesting. Conservative. Very incremental. Makes sense given their codebase & users. Lots of inertia there too so I wonder what they have in the pipe? And how they will handle the upstarts going hard on generative model / asset creation.
Vibecoding is super interesting. And powerful. Coding syntax is getting better. But secure coding isn't keeping pace. image In a test of 100 coding models, 45% of them introduced a serious vulnerability. For example, in 86% of tests, code wasn't secured against Cross-Site Scripting. NOW-TERM IMPLICATIONS This has big implications. Sure, there are the YOLOcoders that ship whole vibecoded apps without thinking about security. Or code review. Some percentage of their users will get rekt. If those projects get near high risk users, they are sprinkling knives in the weeds with potential for harm. BUT BIGGER MODELS = BETTER? Interestingly, even big fat models aren't massively better with security. image S'EVERYWHERE My other worry? Vibecoding without security check steps is happening in existing projects / platforms etc. Even when people say they are coding. Sometimes they be vibecoding. This sort of thing has already come to tools you use, including to handle your funds & privacy. Sure secure code writing & review has never been anything near universal, but the scale and speed of new code creation that #vibecoding enables is new. VULNERABILITY DISCOVERY...ALSO ACCELERATING ICYMI, vulnerability DISCOVERY is also accelerating a lot faster than secure code creation... Whole industries are spinning up, including lots of offensive projects. ME? I #VIBECODE I love the change in how I create with code. But I think we are in for some really rough times, and the least informed parties are gonna be users. As ever. image In the longer run this problem space also seems to offer paths for AI-driven improvement in secure code creation. But since not everything is accelerating at the same pace, the deltas = harm. Sauce:
The EU's Digital Identity Wallet project has a lot of big icks. Looking at the GitHub for the android Age Verification application feels like chewing rocks. image Like the proprietary attestation baked into a must-use form of identification is absolutely the wrong path... image And while we're at it, recall the rule of thumb: Age Verification either by deliberate or convenient naรฏvetรฉ is almost always a surveillance trojan horse. Source:
Proton #VPN signups spike1,400% as the UK Online Safety Act rolls out. Proton says spike is sustained & higher than when France blocked adult content. image Source: https://archive.ph/i2d9W
Tea enforced ID & selfie collection. And doxxed their own users. image In other news, the UK Online Safety Act is forcing websites to begin collecting IDs. This will end, predictably in fresh breaches. image And more harm to users.
The only way to deal with an unfree world is to become so absolutely free that your very existence is an act of rebellion. -Attributed to Camus
Your honor, in my defense I was being extremely productive at the time of the crash. image
You read dystopian sci-fi as a warning. These companies found business plans.. image Just as there are war hawks that delight in hard talk about military action, there are surveillance-yearners... image For reasons I'll never fully understand the UK politicians aren't just surveillance-permissive. They delight in the idea. Pre-crime preventative detention coming soon... image
Mass biometric surveillance is a one-way ticket away from democracy.
How it began: "our service helps consumers quickly do X..." How it's going: "we help business understand consumer behavior..." Soon: "we're launching a surveillance subsidiary for government customers..."