277

GrapheneOS is currently defending its use of AI coding tools on Mastodon against complaints by various accounts claiming to be users.

We do not understand where you're coming from or why you're so incredibly angry with us. It's not justified and does not make sense.

you are viewing a single comment's thread
view the rest of the comments
[-] Grimy@lemmy.world 33 points 5 days ago

It's funny because anyone seeing this as black and white clearly hasn't ever opened an IDE.

[-] AVincentInSpace@pawb.social 70 points 4 days ago* (last edited 2 days ago)

I've been a programmer for two thirds of my life up to this point. I don't see how the machine that generates code that must be assumed to be broken, and statements about said code that must be assumed to be wrong, until both have been manually verified, because the "hallucination" issue is inherent to the design of LLMs and cannot be solved, is supposed to make my life easier. Especially since a well known problem in computer science is that writing code is more fun than reading it.

If you're using AI for code generation, I hope you like reading code.

If you're using AI to learn your way around an existing codebase, I hope you're prepared to fact check everything it tells you.

If you're using AI for code review before merging a PR, fucking yikes. What made you think the sycophant machine that once told users a soggy cereal bar was a great business opportunity and cannot even transcribe McDonald's orders correctly was suitable for that purpose?

If you're telling yourself it's okay because there's a human in the loop, please read some studies about decision fatigue and consider that increasing the number of critical decisions a person must make per day, while giving them a suggested answer that's right 90% of the time and catastrophically wrong the remaining 10%, and the only way to tell the difference is to read in depth, might not have the desired effect. Especially if the human in question is then put under time pressure.

And all that is before I go on a five paragraph rant about the ethical transgressions of every major AI company.

It's pretty black and white for me.

[-] raspberriesareyummy@lemmy.world 4 points 3 days ago

I don’t see how the machine that generates code that must be assumed to be broken, and statements about said code that must be assumed to be wrong, until both have been manually verified, because the “hallucination” issue is inherent to the design of LLMs and cannot be solved, is supposed to make my life easier. Especially since a well known problem in computer science is that writing code is more fun than reading it.

quoted for emphasis. you have more patience than I do in telling sycophants why their take is idiotic.

[-] undrwater@lemmy.world 14 points 4 days ago

This in spades.

To add; now there's an issue in the generated code that's been pushed. What to do? Read the code? Have new code generated? Abandon the project?

[-] Grimy@lemmy.world 4 points 4 days ago

Abandon the project

[-] Grimy@lemmy.world -1 points 4 days ago* (last edited 4 days ago)

The fact that it isn't perfect is the grey. And sure, it has a lot of problems but not only is it still useful anyways, but those problems are being ironed out. They probably won't disappear completely but the tech is already miles further than what we had 2 years ago.

To make you understand what I mean by black and white, you have a user that put "AI is evil" in big bold letters in the comments. The hate is almost cult like for part of the population, and imo, it's mostly because the media tells them to be mad.

Most of it depends on the task in any case. I don't work with massive code bases and it doesn't take long reading through a few scripts, running it and checking the output. The people I know that do work with huge code bases are using it as well, but I can't really talk for them either. They don't hate it tho.

[-] AVincentInSpace@pawb.social 27 points 4 days ago* (last edited 4 days ago)

The person who put "AI is evil" in big block letters is objectively correct. See homes getting claimed under eminent domain to build power lines for datacenters, electricity prices for consumers rising as service quality gets worse, and water usage to the tune of millions of gallons per datacenter per day. See companies buying rare books in bulk, cutting them apart so they can be scanned faster, and not publishing the scans, literally destroying culture so they can have one more scrap of training data guaranteed to be free of slop that their competitors don't have. See companies operating web scrapers that deliberately evade every block that website owners try to use to stop them from reading their sites, and then scraping so many different pages so frequently that it's indistinguishable from a DDoS attack, hosting bills skyrocket, servers crash, indie webmasters pay the price for corporate greed. See xAI operating natural gas turbines on the property of their datacenter for extra electricity in flagrant violation of the Clean Air Act, spewing toxic smoke into the air and generating powerful, inaudible infrasound vibrations that have been linked to everything from nausea to irritability to hearing loss to seizures. See Anthropic treating Minority Report as an instruction manual. See how ChatGPT use affects test scores. See AI psychosis. See chatbot-induced suicides. See deskilling. See how little AI companies care.

[-] natecox@programming.dev 11 points 4 days ago

I agree, it's just not reasonable to assert that a technology powered entirely by IP theft and climate change acceleration must be inherently evil.

[-] Grimy@lemmy.world -4 points 4 days ago* (last edited 4 days ago)

Sorry, I don't bootlick the copyright machine. Anyone with half a brain can see it's transformative. I don't get why collage is fine but AI isn't, it's just copyright mega corps and data brokers that smell blood in the water. All the data isn't even owned by the artist, you are fighting for universal records, not your local guitarist.

For the climate aspect, it's mostly grid issues and corruption. It's laughable to blame AI when we have president pedo prostrating himself in front of oil companies and destroying renewable projects. We need regulations and all that on where they can be placed and how they get powered, but in the end, it's just software. I could use AI 8 hours a day for my whole life and I still wouldn't be close to the damage one ticket to Europe does. It's a scape goat being served by a corrupt pro oil lobby.

Don't get me wrong, I know what datacenters entail with the amount of people they serve, but if you look at it at an individual level, it's a drop in the bucket, or it would be if they weren't using plane turbines. We need regulations to curb the stupidity, but it's doesn't make it all inherently bad.

[-] natecox@programming.dev 13 points 4 days ago

Lol, "I know this is a legitimate issue, but if I creatively reframe it enough I can pretend it's not".

[-] Grimy@lemmy.world -5 points 4 days ago

I don't think the copyright thing is an issue.

Climate wise, it's only an issue because of a corrupt administration, it's not a death blow to it. It's at the heart of it overblown by a reasonable measure imo.

[-] natecox@programming.dev 6 points 4 days ago

I love how I say "IP" and you assert "copyright".

[-] hirihit640@sh.itjust.works 5 points 4 days ago

Not the person you are replying to, but if there is no copyright there is no IP "theft".

[-] HaraldvonBlauzahn@feddit.org 5 points 4 days ago

The fact that it isn’t perfect is the grey.

And the fact how it is used in practice, actually, in reality, is the very dark grey that some people call "black" for better clarity. The fact that you can use a large butchers knife for practical things does not mean that entering a primary school with one is the right thing. What are the actual intentions for grabbing that tool?

[-] SuspiciousCarrot78@aussie.zone 1 points 4 days ago* (last edited 4 days ago)

Ssshh…Most of those having a knee-jerk "AI BAD! YOU BAD!" reaction don't have any clue WTF an IDE is, how code completion works, nor the fact that by most metrics 95%+ of code now has "AI" in the chain…and has had that for YEARS.

https://github.blog/news-insights/research/survey-ai-wave-grows/

https://survey.stackoverflow.co/2025/ai

OMGWTFBBQ!

Here's a crazy idea…how about instead of "AI BAD! ME HATE AI" how about some nuance? Assume ALL software in 2026 has had AI assistance, and review it on its merits.

As for the devs at GrapheneOS directly…why were you (the general you) trusting them before? Humans can be plenty dicey in ways that affect code all on their own.

https://www.reddit.com/r/PrivacyGuides/comments/13s7mv3/why_i_deleted_grapheneos_louis_rossmann/

https://factually.co/fact-checks/technology/louis-grossman-grapheneos-drama-c1f2ae

Supposedly wonderful "human artisanal code" has plenty of fuckery.

https://en.wikipedia.org/wiki/XZ_Utils_backdoor

https://thehackernews.com/2024/03/urgent-secret-backdoor-found-in-xz.html

https://simonwillison.net/2026/Mar/31/supply-chain-attack-on-axios/

https://www.hivepro.com/threat-advisory/axios-npm-supply-chain-attack-what-you-need-to-know/

[-] HaraldvonBlauzahn@feddit.org 10 points 4 days ago

Supposedly wonderful “human artisanal code” has plenty of fuckery.

These are supply chain attacks and in the case of xz utils, the attacker had gone to extreme lenghts to hide the attack from a well-meaning, good-hearthed but overworked and burnt out solo maintainer.

To compare this to bugs that people unwittingly introduce in normal human-written code is not sincere.

[-] SuspiciousCarrot78@aussie.zone 4 points 4 days ago* (last edited 4 days ago)

Very well. Here -

https://www.debian.org/security/2008/dsa-1571

https://www.finnie.org/2024/05/13/i-discovered-the-debian-openssl-bug/

That's the thing about "pure human slop": it doesn't need to be malicious to be catastrophic.

The second link is particularly salient - kills the "supply chain attacks are special" argument because it is precisely about "unwitting bugs in normal human-written code just happen"

[-] AVincentInSpace@pawb.social 4 points 4 days ago

Okay, but they still happen with orders of magnitude less frequency than bugs in AI code. Consider that the time between when rsync first adopted LLM-generated code and users en masse reporting rsync internal protocol errors during a backup was on the order of months.

[-] SuspiciousCarrot78@aussie.zone 4 points 4 days ago* (last edited 4 days ago)

I don't recall that one...but in fairness...AI generates a metric shit ton more code than humans. We'd have to normalize the results. Interestingly, looking it up now, someone DID normalize for that very case. Bug rate per commit for the AI-assisted versions landed within normal historical range. A pre-AI release had more regressions. The 3.4.3 regressions were primarily from the CVE security patches, not the AI work. Zero CVEs from the Claude-assisted commits.

EDIT: Correct URL https://alexispurslane.github.io/rsync-analysis/

[-] AVincentInSpace@pawb.social 0 points 2 days ago

The author of that article admits that the sample size is not large enough to draw meaningful conclusions.

But besides that, I believe LLM code generators can be a useful tool, provided you are willing to go over their output with a fine-tooth comb and assume it is broken until you have proven otherwise, because the hallucination problem is inherent to the technology and they're never going to completely solve it, and are willing to overlook the myriad ethical issues with all major LLMs in existence today.

[-] SuspiciousCarrot78@aussie.zone 0 points 2 days ago* (last edited 2 days ago)

The author of that article admits that the sample size is not large enough to draw meaningful conclusions.

Hey, you brought it up - I just pulled the thread. Not my fault it cuts against your argument.

But besides that, I believe LLM code generators can be a useful tool, provided you are willing to go over their output with a fine-tooth comb and assume it is broken until you have proven otherwise,

So, exactly like a junior dev?

going to completely solve it, and are willing to overlook the myriad ethical issues with all major LLMs in existence today.

That's a different claim than the one you opened with though. Most of those objections have documented counter-arguments, btw:

https://blog.andymasley.com/p/a-cheat-sheet-for-conversations-about

https://aicentral.substack.com/p/why-anthropic-burned-the-books

Data centres were polluting long before LLMs arrived. Crypto, cloud storage, Netflix, YouTube, AWS - AI isn't all data centre load. Blaming the latter for the former is like blaming sunscreen for melanoma.

[-] AVincentInSpace@pawb.social 0 points 1 day ago* (last edited 1 day ago)

I'd really like to see a source for the first guy's numbers, especially how he accounts for things like training and water usage at the power plant, and as for the second guy, Anthropic is not preserving shit. The Internet Archive preserves books. Anthropic scans them and doesn't publish the scans so that they can train an LLM that might or might not be able to regurgitate some fragments of that text, and publish that. That's preservation in the same way that painting a picture of you is keeping you alive forever.

Also, neither of those address the effects on creatives' livelihoods or the mental health of LLM users. Chatbot psychosis is real. People who routinely use LLMs to do things provably become worse at doing them without them. Students use LLMs to make an end run around having to learn everything they need to know to be effective members of a society, like how to articulate their points, how not to fall for rhetorical traps, what history was really like, and between that and the disastrous effects of No Child Left Behind, teachers are quitting in droves and there's a literacy crisis.

[-] SuspiciousCarrot78@aussie.zone 1 points 1 day ago* (last edited 1 day ago)

really like to see a source for the first guy's numbers

The citations are inline hyperlinks throughout the piece - IEA, Lawrence Berkeley National Lab, MIT Technology Review, Google's own efficiency data.

They're there. Click them.

Also, neither of those address the effects on creatives' livelihood

We've now gone from "AI can't code," to "AI code is a malicious risk," to "humans would never do that," to "that's a disengenous example" to "ok, but what about this, this and this"

We're verging on a gish gallop at this point, so I demur. Let's stick to the claims at hand instead of litigating shifting goal posts.

On the topic of the second article -

What the judge ruled was that it qualifies as fair use specifically because they destroyed the copies - the destruction is what made the scanning fair use, not what made it wrongful.

Retaining the digital files without destroying the physical copies would have been the violation.

Meaning the law perversely incentivised this behavior. (If you want the actual court reporting, the Ars Technica piece the article quotes is the cleaner source).

https://arstechnica.com/ai/2025/06/anthropic-destroyed-millions-of-print-books-to-build-its-ai-models/

So, it's more complicated than "Anthropic are book burners."

[-] raspberriesareyummy@lemmy.world 2 points 3 days ago

I froze my rsync package the day that was announced. fuck the dev :(

this post was submitted on 10 Sep 2026
277 points (90.6% liked)

Technology

88037 readers
3850 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS