GrapheneOS is currently defending its use of AI coding tools on Mastodon against complaints by various accounts claiming to be users.

We do not understand where you’re coming from or why you’re so incredibly angry with us. It’s not justified and does not make sense.

  • SuspiciousCarrot78@aussie.zone
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    14
    ·
    edit-2
    3 days ago

    Ssshh…Most of those having a knee-jerk “AI BAD! YOU BAD!” reaction don’t have any clue WTF an IDE is, how code completion works, nor the fact that by most metrics 95%+ of code now has “AI” in the chain…and has had that for YEARS.

    https://github.blog/news-insights/research/survey-ai-wave-grows/

    https://survey.stackoverflow.co/2025/ai

    OMGWTFBBQ!

    Here’s a crazy idea…how about instead of “AI BAD! ME HATE AI” how about some nuance? Assume ALL software in 2026 has had AI assistance, and review it on its merits.

    As for the devs at GrapheneOS directly…why were you (the general you) trusting them before? Humans can be plenty dicey in ways that affect code all on their own.

    https://www.reddit.com/r/PrivacyGuides/comments/13s7mv3/why_i_deleted_grapheneos_louis_rossmann/

    https://factually.co/fact-checks/technology/louis-grossman-grapheneos-drama-c1f2ae

    Supposedly wonderful “human artisanal code” has plenty of fuckery.

    https://en.wikipedia.org/wiki/XZ_Utils_backdoor

    https://thehackernews.com/2024/03/urgent-secret-backdoor-found-in-xz.html

    https://simonwillison.net/2026/Mar/31/supply-chain-attack-on-axios/

    https://www.hivepro.com/threat-advisory/axios-npm-supply-chain-attack-what-you-need-to-know/

    • HaraldvonBlauzahn@feddit.org
      link
      fedilink
      English
      arrow-up
      10
      ·
      3 days ago

      Supposedly wonderful “human artisanal code” has plenty of fuckery.

      These are supply chain attacks and in the case of xz utils, the attacker had gone to extreme lenghts to hide the attack from a well-meaning, good-hearthed but overworked and burnt out solo maintainer.

      To compare this to bugs that people unwittingly introduce in normal human-written code is not sincere.

      • SuspiciousCarrot78@aussie.zone
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        2
        ·
        edit-2
        3 days ago

        Very well. Here -

        https://www.debian.org/security/2008/dsa-1571

        https://www.finnie.org/2024/05/13/i-discovered-the-debian-openssl-bug/

        That’s the thing about “pure human slop”: it doesn’t need to be malicious to be catastrophic.

        The second link is particularly salient - kills the “supply chain attacks are special” argument because it is precisely about “unwitting bugs in normal human-written code just happen”

        • AVincentInSpace@pawb.social
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          3 days ago

          Okay, but they still happen with orders of magnitude less frequency than bugs in AI code. Consider that the time between when rsync first adopted LLM-generated code and users en masse reporting rsync internal protocol errors during a backup was on the order of months.

          • SuspiciousCarrot78@aussie.zone
            link
            fedilink
            English
            arrow-up
            4
            ·
            edit-2
            3 days ago

            I don’t recall that one…but in fairness…AI generates a metric shit ton more code than humans. We’d have to normalize the results. Interestingly, looking it up now, someone DID normalize for that very case. Bug rate per commit for the AI-assisted versions landed within normal historical range. A pre-AI release had more regressions. The 3.4.3 regressions were primarily from the CVE security patches, not the AI work. Zero CVEs from the Claude-assisted commits.

            EDIT: Correct URL https://alexispurslane.github.io/rsync-analysis/

            • AVincentInSpace@pawb.social
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              2 days ago

              The author of that article admits that the sample size is not large enough to draw meaningful conclusions.

              But besides that, I believe LLM code generators can be a useful tool, provided you are willing to go over their output with a fine-tooth comb and assume it is broken until you have proven otherwise, because the hallucination problem is inherent to the technology and they’re never going to completely solve it, and are willing to overlook the myriad ethical issues with all major LLMs in existence today.

              • SuspiciousCarrot78@aussie.zone
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                edit-2
                21 hours ago

                The author of that article admits that the sample size is not large enough to draw meaningful conclusions.

                Hey, you brought it up - I just pulled the thread. Not my fault it cuts against your argument.

                But besides that, I believe LLM code generators can be a useful tool, provided you are willing to go over their output with a fine-tooth comb and assume it is broken until you have proven otherwise,

                So, exactly like a junior dev?

                going to completely solve it, and are willing to overlook the myriad ethical issues with all major LLMs in existence today.

                That’s a different claim than the one you opened with though. Most of those objections have documented counter-arguments, btw:

                https://blog.andymasley.com/p/a-cheat-sheet-for-conversations-about

                https://aicentral.substack.com/p/why-anthropic-burned-the-books

                Data centres were polluting long before LLMs arrived. Crypto, cloud storage, Netflix, YouTube, AWS - AI isn’t all data centre load. Blaming the latter for the former is like blaming sunscreen for melanoma.

                • AVincentInSpace@pawb.social
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  edit-2
                  18 hours ago

                  I’d really like to see a source for the first guy’s numbers, especially how he accounts for things like training and water usage at the power plant, and as for the second guy, Anthropic is not preserving shit. The Internet Archive preserves books. Anthropic scans them and doesn’t publish the scans so that they can train an LLM that might or might not be able to regurgitate some fragments of that text, and publish that. That’s preservation in the same way that painting a picture of you is keeping you alive forever.

                  Also, neither of those address the effects on creatives’ livelihoods or the mental health of LLM users. Chatbot psychosis is real. People who routinely use LLMs to do things provably become worse at doing them without them. Students use LLMs to make an end run around having to learn everything they need to know to be effective members of a society, like how to articulate their points, how not to fall for rhetorical traps, what history was really like, and between that and the disastrous effects of No Child Left Behind, teachers are quitting in droves and there’s a literacy crisis.

                  • SuspiciousCarrot78@aussie.zone
                    link
                    fedilink
                    English
                    arrow-up
                    1
                    ·
                    edit-2
                    8 hours ago

                    really like to see a source for the first guy’s numbers

                    The citations are inline hyperlinks throughout the piece - IEA, Lawrence Berkeley National Lab, MIT Technology Review, Google’s own efficiency data.

                    They’re there. Click them.

                    Also, neither of those address the effects on creatives’ livelihood

                    We’ve now gone from “AI can’t code,” to “AI code is a malicious risk,” to “humans would never do that,” to “that’s a disengenous example” to “ok, but what about this, this and this”

                    We’re verging on a gish gallop at this point, so I demur. Let’s stick to the claims at hand instead of litigating shifting goal posts.

                    On the topic of the second article -

                    What the judge ruled was that it qualifies as fair use specifically because they destroyed the copies - the destruction is what made the scanning fair use, not what made it wrongful.

                    Retaining the digital files without destroying the physical copies would have been the violation.

                    Meaning the law perversely incentivised this behavior. (If you want the actual court reporting, the Ars Technica piece the article quotes is the cleaner source).

                    https://arstechnica.com/ai/2025/06/anthropic-destroyed-millions-of-print-books-to-build-its-ai-models/

                    So, it’s more complicated than “Anthropic are book burners.”