跳到正文
原文
Hacker News · Vibe Coding 讨论· eustoria·· 14天前AI 评分62

Vibe Coding 的危险:为什么 AI 生成的代码仍需逐行人工审查

原文标题:The Dangers of Vibe Coding

AI 导读

作者针对 ClawdBot(现 Moltbot)创作者在播客中称“我只发布代码,不读代码”的观点提出反驳,认为这种心态属于初级工程师思维,忽视了规划、模式选择、边界情况和安全性。

正文

当前语言的正文正在等待翻译,暂时显示原文。

I just listened to the podcast with the creator of ClawdBot (Now Moltbot) titled, “I ship code, I don’t read”. About 51 minutes in he says that the people who dislike AI are often the people who enjoy solving hard problems because the AI solves those problems now.

This seems like a junior software engineer mindset to me. When I was a junior software engineer I did not understand why senior engineers took so long to build and ship systems. How many hours went into planning, picking the correct patterns, ensuring edge cases, making the code maintainable… and above all making sure the code was secure.

The vibe coder problem is exactly what we see with ClawdBot’s recent security issues. The problem all comes down to the fact that vibe coders have that junior software engineer mindset that shipping code is the important thing.

Writing clean well architected code that is secure is one of those hard things, and if I disregarded it I could speed up how fast I ship even hand written code. No, I cannot type as fast as Claude Code can, and between that speed and how it can quickly look up libraries and API’s it is faster than I am. I currently use AI to write about 80% - 90% of my code. However, I review every line of code and often find both structural issues and security issues with the AI generated code.

Let’s address the massive security elephant in the room.

  • If 250 poisoned documents can compromise a model trained on 260 billion tokens, with the attack succeeding similarly regardless of model or dataset size [1],
  • And if backdoors can be constructed that are computationally undetectable even with full white-box access to network weights and training data [2],

Then the only remaining defense for AI-generated code is human review. Automated defenses show promise but have not achieved full restoration of compromised models [3]. The model cannot certify its own outputs. The attack surface is the entire training corpus, which no user can audit. Therefore, if you do not review and understand every line of AI-generated code, you have no basis for trusting it is not malicious.

References:

来源:Hacker News · Vibe Coding 讨论 · thesimpledev.com