cross-posted from: https://lemmy.world/post/51749088

GrapheneOS is currently defending its use of AI coding tools on Mastodon against complaints by various accounts claiming to be users.

We do not understand where you’re coming from or why you’re so incredibly angry with us. It’s not justified and does not make sense.

  • FearMeAndDecay@literature.cafe
    link
    fedilink
    English
    arrow-up
    20
    ·
    edit-2
    2 days ago

    Why are coders so desperate to replace themselves with ai? Like you rarely hear of actual artists or writers using ai in such large waves as coders do. Sure you’ll get lots of people who have an idea for a story just have an llm do the work for them, but its less common to hear about established authors doing that. Just like how people who have an idea for a game will just have an llm write the code. Meanwhile professional coders seem thrilled to outsource their work to ai. Why???

    Edit: is it bc they don’t see their work as art like artists and writers do? Bc it is a form of art just like how mathematical formulas and stuff can be art

    (Obligatory not all coders. I know there are many that hate ai and hate being required to use it at work, but its really starting to feel like they’re in the minority)

    • ZILtoid1991@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      5 hours ago

      A lot more software developer are only there for as a career than artists in the art world, so you’re immediately surrounded by people who see stuff like code performance and readability as “something nerdy”, while you can push out more lines of code instead of optimizing. Not more features, more lines of code, as coding got taken over by the careerists.

      That mixed with:

      • most tech criticism used to come from out-of-touch parents, thinking you’re from one Quake match away from getting a machine gun to “play it in real life” (was even prevalent in non-US countries due to all kinds of moral panics);
      • seeing unsupportative parents utterly devastating their kids’ careers in tech due to weird beliefs and expectations,
      • seeing at least some tech fad eventually working out after the toxic hype cycle (Jack Tramiel wanted you to use your C64 for food recipes),
      • forgetting that many hyped tech did actually die off (remember Kinect and NFTs?)

      lead to people to think LLMs are the next big thing even if AGI won’t come.

      There’s also the issue of how society frames AI “extremism”. People like to think in horseshoe theories, and that extremists are necessarily annoying. The tech industry likes to frame “vibe coders with AI psychosis” and “people really not wanting to engage with AI” as the extremes to avoid. In reality, the two extremes are TESCREALists, and anti-tech extremists. Also seen many “totally not vibe coders” using AI to generate a general understanding for the code to avoid scrutiny, while seen “AI assisted” coding going just as off the rails as vibe coding due to overly trusting the chatbot, with many still going down the AI psychosis route.

    • Lee Duna@lemmy.nz
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      13 hours ago

      as a coder myself, I admit that sometimes coders are the dumbest people in the world because they live in their own bubble. they only see LLM as mere tools that would greatly help with development.

      do they know how many resources are wasted by data centers? do they care when the people suffer from data center pollution? or do they realised LLM trained by stealing people works? etc

    • HieroProtagonist@feddit.org
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      10 hours ago

      Why are coders so desperate to replace themselves with ai?

      (Obligatory not all coders. I know there are many that hate ai and hate being required to use it at work, but its really starting to feel like they’re in the minority)

      Because real coders are no fucking luddites who cannot see that they defend a ship that is not only sinking, its deck is already submerged. You either accept that the oh so glorious past is gone, dead and buried and move on or you become some weird neckbeard who defends coding using ed via teletype.

      • ZILtoid1991@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        6 hours ago

        In my experience, it’s always those weird neckbeards who are constantly trying to push me for neovim or emacs also thinking I should have started vibe coding by yesterday, because they can ship much more lines of code, and who cares about code quality or performance when you can claim you’ve written 983744892736487645 lines of code.

    • IMALlama@lemmy.world
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      1 day ago

      In a work environment there’s always been pressure to ship software faster. The industry has never been good at measuring individual or team effectiveness, which has resulted in all kinds of dumb metrics (lines of code, ticket count, etc). I see AI as just another amplifier bad behavior. Don’t use it? Odds are a teammate will and they’ll be viewed as more productive than you. In today’s world of tech layoffs that’s not a good position to find yourself in.

      There’s a second angle to this too: there are two cohorts of AI users. Those who follow what I would call the YOLO path and those who spend the time iterate on the output. In my case, layers of management are blissfully unaware of this distinction, but they sure like the “line go up fast” nature of the YOLO crowd.

    • boraginoru@lemmy.zip
      link
      fedilink
      arrow-up
      10
      ·
      2 days ago

      There are different attitudes of engineers. Some are more results-oriented and see the code as just a means to an end. It’s difficult to get good at programming and AI makes it so you don’t really have to, so they gladly accept it as a way to build things faster.

      And then there’s me on the exact opposite end of that spectrum. I don’t care much at all for the end result except that it’s what allows me to get to do programming. I like the puzzle and figuring out how to make it all work line-by-line. AI takes away all of the fun part and it does it so terribly.

      Up til now both types of programmers got along decently well because building things correctly and quickly have usually taken similar paths. But with the advent of AI we’re now quite at odds with each other, and it’s been quite a pain for me.

      • Yaky@slrpnk.net
        link
        fedilink
        arrow-up
        2
        ·
        19 hours ago

        Up til now both types of programmers got along decently well because building things correctly and quickly have usually taken similar paths.

        IMO those paths diverged in web development somewhere around 10 years ago. While you could write efficient websites using standard HTML features and minimum of JavaScript (the good-efficient path), companies and developers started going towards various frameworks, which were “faster” for developers to use, but usually at expense of performance on users’ side, numerous dependencies, and security. Each framework trying to do its own thing, and some are conceptually entirely different from bare HTML+JS.

      • FearMeAndDecay@literature.cafe
        link
        fedilink
        English
        arrow-up
        7
        ·
        2 days ago

        Ugh that sounds like such a pain. Stay strong! Once they’ve smoothed out their brain using ai your skills will be in high demand to fix all the mistakes the ai makes, and then hopefully people will understand that you can’t be replaced by an ai

    • rangber@lemmy.zip
      link
      fedilink
      arrow-up
      6
      ·
      edit-2
      2 days ago

      How many AI driven cyber attacks are artists dealing with? Because they are here, cheaper to make, and much more potent than they used to be.

  • deliriousdreams@fedia.io
    link
    fedilink
    arrow-up
    18
    ·
    2 days ago

    Wasn’t prepared for Graphene to break my heart this morning. That’s what I get for having feeling I guess.

  • HaraldvonBlauzahn@feddit.org
    link
    fedilink
    arrow-up
    18
    ·
    2 days ago

    Copied from discussion on c/Technology:

    OSS projects have already started to recognize that LLM is just a tool and how you use that tool matters a lot more than whether you are using said tool at all.

    This tool is however not neutral but has a lot of steering and bias built in. Like an advisor who optimizes heavily for personal gain. For example, it constantly tells you that it knows it all and also that your ideas are the best thing since sliced bread. A lot of stuff around them is engineered to increase engagement and make you dependent on them. Precisely like social media which is full of “brain hacks” - no, this isn’t hyperbole, this is the name that engineers at Facebook gave to their creations. As social media, commercial LLMs are “addictive by design”.

    Lets bring StackOverflow for analogy: we didn’t ban browsers for code development because one can navigate to StackOverflow and copy-paste some really crappy code.

    Stack Overflow is a really good example. I am programming over 40 years, since 35 years as hired programmer, since 25 years on PhD level and I used Stack Overflow a lot to find interesting new angles on issues with seemingly obvious answers. Like “what is the most portable, clearest way to efficiently serialize message data in a C struct, given that type punning is only defined for some compilers and can lead to undefined behaviour”.

    Stack overflow has typically various opinionated commented answers here, which gives you different angles and you can decide what is best in your case. This is crucial since a lot - one could say, almost all - of software engineering is about trade-offs.

    ChatGPT is the know-all of stack overflow responders: It gives you a single smart-allecky answer and is purposefully built so it tries to take decisions out of your hands. It currently also makes a ton of suggestions of which some have a point, some might apply in other cases but not yours, and some are bullshit. If you let it run free you will easily get ten times more code than needed. And ten times more code means ten times more bugs - this is well-established.

    So grabbing LLM to get a sense of direction or shape is an OK use in general, but copy-pasting it’s results blindly is silly and dangerous.

    The thing is that commercial LLMs in practice are engineered to short-circuit your judgment and decision-making.

    There’s a second argument that AI is ruining OSS communities which I believe is true, but refusing to accept AI code is a self-defeating action. Why? Because AI training needs unadulterated source of knowledge, one not tainted with AI and OSS communities rejecting AI would be that source.

    First: These companies will siphon off open source code anyway, be it legal or not. That is outside of the influence of single open source developers or projects. Maybe a matter of high courts and civil society lawsuits to decide. And these will have to fight an uphill battle against the current political climate around favouring large companies in general and that kind of exploitative AI in particular.

    But what projects do have influence over is the quality of their code base and what ingresses into it.

    Further, it is to expected that the quality of commercial code bases continues to degrade at a rapid pace and also that companies will depend even more on open source infrastructure and libraries - and FOSS developers training the LLMs they use on anything that is new. Because the average commercial project or github project just will turn to shit. Companies will soon wistfully remember old times where Sturgeon’s law was a thing and when only 90% of all public code was shit, and not 99.999% . (Congratulations to that future five nines!).

    There is an asymmetry between open source code and proprietary software: Open source code is protected by copyright law. Which GenAI vendor companies practically do ignore. Proprietary software is usually protected by copyright law, and also obfuscation by it being binary or behind server APIs. Currently, this works in favour of companies: They get to use GPL-proteced public code, but are not exposing their own, uh, creations. (And of course, LLM vendors will make the solemn pinky promise that they never ever will publish commercial code their customers are working on as LLM output (ask top-notch mathematicians how that worked out).)

    But will this stay like this? Because another issue is that the same methods can be used to decompile binary code, and LLMs can also be trained on decompiled proprietary code. Which will, for example, make its many hidden security issues much more acute. (Another thing is I think one can transform decompiled control structures in binary code to control flow graphs, and then use standard graph search algorithms and graph databases in order to find out which GPL’d open-source code some proprietary product has included, including which potentially vulnerable versions. So-to-speak a software-bill-of-materials by code inspection.)

  • Yaky@slrpnk.net
    link
    fedilink
    arrow-up
    41
    arrow-down
    6
    ·
    3 days ago

    It’s unclear what would be accomplished by banning AI for a tiny portion of the code while continuing to use Linux, AOSP, Chromium and hundreds of other projects heavily using it.

    AI or not, this is such shit attitude. Call it peer pressure, or appeal to authority, or whatever, but think for yourself. Especially for a project like GrapheneOS.

    • ContactClosure@lemmus.org
      link
      fedilink
      English
      arrow-up
      29
      arrow-down
      2
      ·
      3 days ago

      Sounds like the people that respond with “well you have a cellphone” when mass surveillance is the topic.

    • chloroken@lemmy.ml
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      3
      ·
      edit-2
      2 days ago

      They’re describing the idea that the projects that Graphene is built atop and alongside of all use AI. That even if tomorrow it was decided to not allow any AI-generated code, due to the nature of being downstream, avoiding its inclusion in all capacities is actually impossible.

      There is not a hint of peer pressure in this snippet. And if you knew Graphene’s history, you’d realize how absurd of a statement it is to accuse them of being peer pressured. They regularly do random shit and tell critics to get bent.

      With that said, I would of course prefer they don’t accept any AI-generated code at all, but quite frankly it’s a bit bizarre of an ask in 2026 given the game Graphene plays with cutting edge development’s intersection with privacy tools.

  • A Sharky Anthro@fedia.io
    link
    fedilink
    arrow-up
    21
    arrow-down
    2
    ·
    3 days ago

    I think the anger is justified as there is a precedent for LLMs being used badly and how unethically the training data is collected (open source has been hurt deeply by scraping attacks for years). How quickly people can be driven off the deep end and form deranged relationships with chatbot style LLM assistants. The fear and anger are very valid, if they couldn’t foresee a hostile reaction to a beloved project starting to utilize the same tech that has caused harm in huge ways…Well, that’s called not reading the room, hun. I wasn’t going to fly off the handle about it. But I am deeply disappointed about it. I don’t really trust the usage of LLMs in any project as by design these are things constructed to channel skill into the hands of those with wealth, while denying those with skill access to wealth. It is mighty hard to trust anyone to use these things that are built on outright manipulation, theft, and a multitude of harms.

    I have been dropping projects left and right for it, it insures that I will never touch GrapheneOS. Begrudgingly, I am still using Linux (despite the LLM usage on the Kernel). There is no real safety hatch to escape into yet. Unless, I just want to retreat into the woods and never interact with modern society ever again. Which I am mighty tempted to do, despite it meaning a gradual and uncomfortable death.

    • AdamBomb@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      2 days ago

      Human review and deterministic code analysis, just like with code of any other provenance

      • bowsertattoo@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 days ago

        so as long as there’s proper human oversight, ai code doesn’t actually compromise the mission of graphene?

        • AdamBomb@lemmy.world
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          2 days ago

          Are you asking rhetorically with a specific mission statement in mind that you believe AI code violates? I’m not aware of Graphene’s mission specifically; I am making a general statement about how AI code can be used responsibly.

  • e8d79@discuss.tchncs.deM
    link
    fedilink
    arrow-up
    12
    arrow-down
    2
    ·
    3 days ago

    I already had my doubts in the capabilities of the GrapheneOS leadership and these doubts where renewed after the recent kerfuffle about hardware memory tagging on the Pixel 11. With these new revelations it might be time to start to look out for an alternative. Maybe its for the better. They never where able to handle criticism gracefully no matter how carefully formulated.

    • Kewlio250@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 days ago

      What abiut the hardware memory tagging issue brought up doubts? I think it was a reasonable stance for a group focused on pirvacy/security

        • OilyArena@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          Yes, but the first builds from Google made no reference to it, so it was reasonable to prepare for a situation where Pixel 11 wasn’t supported.

    • wizardbeard@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      12
      arrow-down
      1
      ·
      3 days ago

      While I agree with you, a counterpoint would be that it further normalizes AI usage in general, which is a large negative as long as corporate AI is still the dominant force/incarnation of it.