NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
Developers are attached to tools because tools encode trust (stackoverflow.blog)
firasd 1 hours ago [-]
I feel like these abstractions like "CI might not work well in the era of agentic tooling" are fine for thought-leadership posts but there's so much hands-on work to be done. The last word on AI computer use shouldn't be bash utils that were already feature-complete before MJ recorded Thriller.

There is some movement in this direction--there is a new 'gh' subcommand called repo read-file for example, that lets agents view a file without cloning a repo. And I made something called venetianblinds that shows equidistant samples of a file. In combo they work pretty well:

gh repo read-file sqlite3.c --repo clibs/sqlite --output sqlite3. c && npx github:firasd/venetianblinds sqlite3.c

    --- sample 2/20 char 283427 line 5855 col 53 range 283367:283487
    le].
    **
    ** ^Closing a BLOB shall cause the current transaction to commit
    ** if there are no other BLOBs, no pending prep
                                                    ^
hahahaa 1 hours ago [-]
MCP is the answer to not using bash, right?

Bash is a great control surface anyway for LLMs as it is wordy and powerful.

firasd 55 minutes ago [-]
Yeah as far as what I'm talking about bash CLI vs MCP doesn't matter (there could be a file_sample MCP tool)---I'm saying that by default Windows, Linux etc don't have this venetianblinds affordance of seeing equally spaced samples. It's a trivial algo but it's very handy these days cause LLMs can't really just be like 'okay I'm gonna open this file at random and scroll around'--the file itself is an unknown blob (JSON data, Python, Typescript, a log file etc) without coordinates. So they fall back to thinking they've gotten a good sense of the file from head/grep or they write ad-hoc Python to manipulate the file.

Another venetianblinds survey, of the Paul Graham 'What I Worked On' article that's used in many LlamaIndex examples:

npx github:firasd/venetianblinds pgworkedon.txt

  --- sample 1/20 char 0 line 1 col 1 range 0:60
  Before college the two main things I worked on, outside of s

  --- sample 2/20 char 3946 line 19 col 237 range 3886:4006
  d an intelligent computer called Mike, and a PBS documentary that showed Terry Winograd using SHRDLU. I haven't tried re
LelouBil 23 minutes ago [-]
Also, this is a trivial example but I would rather an LLm call a recursive "grep" than using 1000 read_file MCP calls.

Having a scripting language as a tool is powerfull, and can help remove unnecessary stuff from the LLM's context.

ElectricalUnion 57 minutes ago [-]
Problem is that bash is too sharp to handle to smart and gullible clankers without a sandbox - That I think everyone should be using anyways, for everything, even things not related to clankers - Android and Qubes are right. The app/vm, and whatever it tries, should not be considered trusted by default.
applfanboysbgon 15 minutes ago [-]
Qubes is directionally correct, Android is extremely not. Safety must not be obtained by preventing users from controlling their own computing devices, or else we face a dire future.
inigyou 1 hours ago [-]
This is a lot of words to say absolutely nothing. Seems apropos for Stack Overflow though.
utopiah 2 hours ago [-]
Im typing this in GVim thanks to Tridactyl using my new mechanical keyboard running a ZMK firmware I just built via Github actions (or directly via ZMK Studio).

This is ridiculously complex to just type a few paragraphs. Nobody in their right mind would invest this amount of yak shaving... and yet I do so because I bet, rather confidently, that in few years, heck few decades, all those tools will be different (or maybe not, I still use Vim on my server, desktop but even mobile phone) but the lessons will remain practical.

IMHO the trust comes from trust yes but also more directly plain ownership.

oooyay 54 minutes ago [-]
I'm not sure the difference changes the conclusion but I think projects demanded certain workflows and resultant processes, not the other way around. That's why Jetbrains has so many workstream specific IDEs that sold very well. The processes didn't go away but a lot of us changed our IDE surface. Those processes still need to exist, largely, but the way in which we invoke them is moving and changing. To some degree, the processes are also changing because other factors are changing outside of the tooling.

For example, I use Codex and Claude Code by default, but when I need to look at the API surface, read tests, etc I have those tools setup to open Zed. Zed is also rapidly evolving in the other direction, where it's closer to the tools that are opening it. It won't be long, I think, until I can continue my prompt from inside Zed.

shostack 59 minutes ago [-]
An example of this in action is the utter inability to get deepseek v4 flash (even the new version) to stay concise. I have jumped through all sorts of hoops with deterministic checks, pre-message injection hooks, memory framework, etc and when it fails still and I ask why it essentially says "I forgot."

This makes it unreliable and preferences are things I need to assume are treated as exactly that, preferences, not hard settings.

It is an area where it is more like working with an unreliable human than I would prefer.

overgard 2 hours ago [-]
I have to admit, I asked ChatGPT to do a TLDR summary because I found the writing meandered quite a bit. I think the overall point is sound:

> "Developers become attached to tools like Vim, Emacs, or an IDE because years of experience make those tools predictable extensions of their thinking. The attachment is less about features and more about accumulated trust, muscle memory, and a workflow built around known boundaries.

> AI coding agents disrupt that trust because they are fast but probabilistic, opaque, constantly changing, and capable of producing more code than humans can realistically review. This shifts the bottleneck from writing code to specifying, reviewing, validating, and operating it safely."

(Note the > is paraphrasing)

Trust is a big problem I'm having with these tools so far. What I've been running into a lot is, I'll get the equivalent 40 hours of work done in 8 hours, and I'm like, wow, that really was quick. Then I'll start using the application I'm making more directly (a tool for writing), and I'll start to see that it's broken all over the place in very surprising ways (ie, updating this menu item broke something on the other side of the app, etc.). So then I spend another 40 hours of real wall clock time kind of fixing everything that was broken, and at the end of those two weeks I'm like, did I actually go much faster or was that all kind of a wash? Because if I'm not going faster in overall terms, then the loss of deep understanding of the code base might not be worth it if my pace is the same.

I'm sure someone is going to be like "BRUH AUTOMATED TESTS" or "BRUH MODEL CHOICE". I have a LOT of automated tests, and I don't like fussing with models so I pretty much use Opus on high reasoning for most things (or the equivalent from other providers). Code review also doesn't help that much, for much of the same reason it doesn't tend to help find bugs in human written code either.. you're reading the happy path usually.

Anyway I wouldn't say these tools aren't useful, but, I'm deeply skeptical of all the productivity claims because I think people just look at one dimension of it while ignoring all the other important dimensions. Yeah you can generate a lot of crap fast, but most of it is not shippable and making it shippable does take time.

derek1800 2 hours ago [-]
If you are spending 40 hours fixing everything that was broken, the question I have is does your AI tools have the necessary context to be successful and not result in a lot of broken items?

Also, is there ways for AI to help prevent the loss of deep understanding of your code base without you having to know every line of code deeply?

overgard 54 minutes ago [-]
I was a bit hazy on numbers because I don't scientifically record them, but I guess what I'll say is the fixing and verifying takes a lot longer than writing the initial code. This was true before LLMs, but when writing code by hand I had the context of the code in my head, so potential issues, blast radius, etc. was a lot more obvious. By definition most of the things that break are things that are not trivially testable. Unfortunately, it's not as easy as saying "Claude, the thing broke, plz fix"; I've had to spend a lot of time recently helping it with context from debuggers, or just debugging myself manually, adding log statements, etc.

Am I giving the agent enough context? Well, I'm giving it as much as I can. Each submodule has an AGENTS.md, I have the agents add gotchas and instructions for some feature work when I discover where an agent went wrong, the codebase has a lot of comments along the lines of "if you edit this section, you need to also edit XYZ", and I lean on the type system as much as I can to make wrong-code not compile. It has access to playwright for driving the UI if it wants to. (Weirdly, I've found that Claude is really inconsistent about using these tools -- even though the instructions make it clear that it's allowed and encouraged. I think if your workflow differs from the models training and thusly you have to tell it so in AGENTS.md/CLAUDE.md, then it's very inconsistent about following those instructions. For instance, I don't want Claude to commit and I don't want it to sign commit messages, and it still does that all the time even though it's my like #1 directive of "don't mess with my git history")

There are some things though that are very hard for it to test. I'm exporting essentially a programming language to three game engine runtimes. They all have automated tests, but, I think people that have worked in video games know that games are very hard to automate testing on. This isn't really the fault of the agent I would say, just the nature of the problem, but it is worth noting.

I guess this is a long winded way of saying, even with LLMs tech debt is a thing you have to manage, and I think managing tech debt becomes even more important when you're dealing with LLMs, not less important.

dijit 2 hours ago [-]
"40 hours" in his context here is actually a work day, so 7-8hrs.

He says "40 hours" because he feels like he's managed to do 40 hours worth of work in this time, but then has to spend another "40 hours" (actually: 1 day) just going around kicking tyres.

Obviously the implication is that it's a net gain of some kind, but he's unsure if he caught everything.

(sorry to reiterate the GP, but I feel like you missed the important nuance that it's not a real 40 hours of time).

grey-area 2 hours ago [-]
No the second 40 hours is a real 40 hours (two weeks), and the implication is there is no real time saving.
inigyou 59 minutes ago [-]
Wow, just wow. This is the first time I've encountered this particularly AI apologism. To recap:

Alice: "in the end, AI doesn't make me any faster because it still takes 80 hours to do 80 hours of work once I fix it"

Bob (AI booster): "actually you might've been holding it wrong, did you try XYZ?"

Carol (AI double-booster): "Bob, actually Alice means it took 16 hours to do 80 hours of work. So it did work for her."

Alice: "no I fucking didn't"

overgard 51 minutes ago [-]
Sorry, my original phrasing was confusing which you should not be downvoted for. I've edited my original comment to clarify what I meant (hopefully).
pmichaud 2 hours ago [-]
I was surprised to see you say you have automated tests. To me this makes most of the difference, but you have you actually have a good test suite, like one that actually proves the code does what you want it to do. Unit tests, property tests, e2e tests. The other part that makes all difference, is you have to be all up in the model's business about architecture. Pick something that wants to testable and isolation friendly, data models that are correct by construction (ie invalid states are not expressible), etc. It absolutely will try to cut corners give you bullshit slop at every turn, you have to keep the structure sane and build the right tests and harness around it.

And I can hear your objection now: correct, it's probably not worth all that for a throwaway, but the effort per output goes down as the infra builds up and you end up with a program that can reliably expand.

overgard 44 minutes ago [-]
I think testing is really important (even without LLMs). Currently I have 2247 unit tests across 132 files in a ~150K LOC codebase (test code included in that count). It takes about 50s to run. There could be more, but it's not nothing. There is playwright for it to test drive the UI, although if I'm being perfectly honest even before LLMs I thought that kind of test tends to be brittle and annoying to write (I guess I don't have to write them anymore, but they are still brittle). I'm honestly trying to give it as much structure as I possibly can -- I'm not trying to setup the agent to fail so I can be like "gotcha!"

I'll also just point out my philosophy for using LLMs for this project, which is that I'm not trying to go as fast as I can. (I want to go at a good pace, but this isn't an experiment to just finish something over a weekend). The 150k LOC have come about since February, with some mix of me writing code and LLMs, so on average I'm probably bringing in about 800 LOC per day, which I imagine a lot of vibers would find to be glacial. To me that's the sustainable rate of what I can do when you factor in that I need to test drive every feature, make sure it doesn't conflict with another feature, check for bugs, check that the code looks reasonable, and debugging. (I also think that rate limit is specific to this project: I could see easier to test things going much faster, and harder to test things going slower)

skydhash 43 minutes ago [-]
> Anyway I wouldn't say these tools aren't useful, but, I'm deeply skeptical of all the productivity claims because I think people just look at one dimension of it while ignoring all the other important dimensions. Yeah you can generate a lot of crap fast, but most of it is not shippable and making it shippable does take time.

My own stance is that there's never any reason to go fast on anything. Communication has always been the bottleneck. Whether it's about gathering requirements or understanding the purpose of a badly written code, any speed improvements I get has always been a small percentage of the overall progress.

What has helped more is my understanding of the platform and some theoretical knowledge. Because one I get the information, I can quickly derive a solution in my mind. And that solution has always been easy and fast to implement, at least the happy path. 90% of the time taken in coding is always about handling all the edge cases, aka fixing bugs. And writing tests so that you're not easily introducing more bugs.

alyx 2 hours ago [-]
[flagged]
nvgjbdhmkdd 2 hours ago [-]
[dead]
kittikitti 1 hours ago [-]
I operate on zero trust because I find that people won't trust me regardless of what their stated reasons are. They just feel uncomfortable. On top of that, people will hallucinate things in order to not trust me.

I update my toolset all the time. It always results in discomfort and backlash but people don't understand that the goal isn't their perception or trust. It's about skill, ability, and execution. This idea probably won't get me promoted but it will get me paid. I am not attached to tools because I learned the hard way that they will always find a way to take them from me.

Zero trust is a better alternative for people like me. In terms of cybersecurity, being attached to a tool is crutch because fatal flaws in every design are frequently found. As it relates to agentic AI, I never select the "Yes, trust the AI and let Claude execute arbitrary commands in a non-sandboxed environment" option. However, I frequently utilize agents, but I'm not going to have the "Jesus, take the wheel" moment with them right now. That being said, AI is a very helpful tool that helps me create boilerplate code, brainstorm ideas, and review my work. I also anticipate when AI can, in fact, take the wheel and I'm looking forward to it.

Parallel to this, I also know that developers often disagree, and I'm not casting judgement on anyone for being attached. If it's Turing-complete, then I have the background to complete the task. In these scenarios, I just adopt whatever tools work best in team building because, in my own words, I'm not too attached to the way I do things.

hahahaa 1 hours ago [-]
What constitutes taking the wheel? Skip permissions in a proper sandbox is fine IMO. There is a small amount of risk I admit though.
fibuladev 20 minutes ago [-]
[dead]
hamza7159 1 hours ago [-]
[dead]
fitsumbelay 2 hours ago [-]
a slightly OT comment

Stack overflow was really attractive to me once but gave me a really hard time. Literally for years I really wanted SO to like me and did what I could to that aim, but always in vain. There were moments but you had to be a sucker in love to value those feeble crumbs, man and boy was I. Pretty sad.

These days I barely think about SO since agentism opened up the world -- nay -- universe to me. I've got new and rather impressive homies now; some, like Claude, I've yet to meet.

Life is good. And I honestly wish SO well, no hard feelings.

inigyou 58 minutes ago [-]
Yes that is what happened to SO. They now get practically zero questions, zero answers, zero page views, and zero ad revenue. It is their own fault because they froze everyone out of the site and then once LLMs became an alternative, everyone started asking their questions to LLMs. They are now trying to somehow pivot to AI to make revenue again, starting with Stack Overflow for Agents, and now with wordy vacuous blog posts to show off how AI they are.
youareinsuffera 1 hours ago [-]
I see that Hacker News has, in its usual fashion, expressed their love and solidarity by downvoting your post.

Apparently you just deserve a life of pain.

zephen 1 hours ago [-]
> Apparently you just deserve a life of pain.

Don't we all?

(I can see that you are starting to get downvoted as well. Spread the love.)

Stack overflow was interesting. Its design was the only thing like it at the time, and made it a Schelling point for programming knowledge distribution, but also a welcoming environment for the programming equivalent of grammar nazis.

Some of those programming nazis, of course, had suffered at the hands of previous ones on stack overflow before becoming "enlightened." And thus, the generational hazing began.

It was great if google directed you to exactly the right answer, but god help you if you couldn't figure it out, and posed a question that someone thought didn't contain an MCVE.

Also, a few too many of the high-reputation people would post complete garbage on topics they knew absolutely nothing about.

inigyou 56 minutes ago [-]
You can't just call everyone you don't like a Nazi.
Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 20:20:32 GMT+0000 (Coordinated Universal Time) with Vercel.