• 0 Posts
  • 372 Comments
Joined 2 years ago
cake
Cake day: July 3rd, 2023

help-circle





  • This reminds me of the new vector for malware that targets “vibe coders”. LLMs tend to hallucinate libraries that don’t exist. Like, it’ll tell you to add, install, and use jjj_image_proc or whatever. The vibe coder will then get an error like “that library doesn’t exist” and "can’t call jjj_image_proc.process()`.

    But you, a malicious user, could go and create a library named jjj_image_proc and give it a function named process. Vibe coders will then pull down and run your arbitrary code, and that’s kind of game over for them.

    You’d just need to find some commonly hallucinated library names



  • Many people have found that using LLMs for coding is a net negative. You end up with sloppy, vulnerable, code that you don’t understand. I’m not sure if there have been any rigorous studies about it yet, but it seems very plausible. LLMs are prone to hallucinating, so you’re going to get it telling you to import libraries that don’t exist, or use parts of the standard library that don’t exist.

    It also opens up a whole new security threat vector of squatting. If LLMs routinely try to install a library from pypi that doesn’t exist, you can create that library and have it do whatever you want. Vibe coders will then run it, and that’s game over for them.

    So yeah, you could “rigorously check” it but a. all of us are lazy and aren’t going to do that routinely (like, have you used snapshot tests?), b. it’s going to anchor you around whatever it produced, making it harder to think about other approaches, and c. it’s often slower overall than just doing a good job from the start.

    I imagine there are similar problems with analyzing large amounts of text. It doesn’t really understand anything. To verify it’s correct, you would have to read the whole thing yourself anyway.

    There are probably specialized use cases that are good- I’m told AI is useful for like protein folding and cancer detection- but that still has experts (I hope) looking at the results.

    To your point, I think people are trying to use these LLMs for things with definite answers, too. Like if I go to google and type in “largest state in the US” it uses AI. This is not a good use case.











    • crawl stone soup. A classic rogue like.
    • elden ring + dlc. Big masterpiece of the genre.
    • the binding of Isaac (+ all the dlc). Huge rogue lite. Lots of stuff I haven’t unlocked yet.
    • monster hunter (maybe world? I liked rise too though).
    • if I could have online, guild wars 2. Otherwise, maybe the original doom. Especially if it comes with a map editor, fan made maps, or Oblige to randomly make maps.

  • I bought a couple games on epic when they were cheaper. I don’t think I’d do so again.

    • the client isn’t as good. It’s slower, the way it paginates your games (I got a lot of free ones) is annoying. It really wants to show you store stuff
    • less (zero?) Linux support
    • don’t think it does the game recording steam does
    • I don’t think it has the remote play together steam does

    There’s probably other stuff I’m not thinking of. It’s just not as good a service.