Many years ago I was working at a firm that investigated stock pump and dump schemes on Yahoo Finance message boards.
We had to scrape the boards and then analyze messages to see if we could identify the identity of the people running the schemes.
This was 2002 and I wasn't aware that the LWP::Simple existed in Perl (aka the requests library in Python).
I ended up using basic TCP socket libraries to connect to port 80 and do http requests. It was, to put it mildly, a major pain in the ass.
That being said, I learned a TON about how http, tcp, html, etc all work together. 20+ years later, I still use some of that knowledge when analyzing network protocols at work.
I mention this b/c nothing is stopping people from doing similar projects now. e.g. Linux from scratch [0] is one great example of learning fundamentals even though we now have 1 click "launch me a Linux VPS" options.
Joel Spolsky make this point too. Even if you are using Java, it's still helpful to understand how CPUs interact with cache because the highest performance comes from optimizing the whole stack.
My work is more data science related, but remember those same struggles where I spent hours, days, weeks, months, even years crashing my head against a problem. A lot of daily hours researching, talking to colleagues, implementing tangential papers that lead to nothing. Most of the time I arrived to a satisfactory solution, but others just have to gave up.
Maybe because I experienced all those struggles I'm confident to delegate a relevant portion of my work to some LLM, being able to validate the results, knowing what to ask and detect easily when something was bad implemented or where I gave ambiguous instructions.
The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions. It doesn't makes me feel comfortable shipping things I don't really understand, but also is nice to be able to do things that previously required years of studying and practice.
I have a tendency to prefer writing my own library for something instead of relying on someone else's. Not always, obviously, but quite often existing libraries fall short or are too complex to use. And solving the problem myself is almost always an educational experience.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
For personal projects that's fine, but I'd absolutely hate to work with someone who is rolling their own libs for everything, and then when they leave the company puts an enormous amount of tech debt into our hands. It also really doesn't make for good team-work if a developer always forces their own opinion on everything.
Not to take away anything from this guy but man, my mind just stops registering information after lines like this: `As a Junior fresh out of school, “still learning what I’m doing” isn’t a caveat — it’s the job description`
Saw this comment and it got me wondering too, because there are at least some LLM tells as well as some places where it diverges into more natural writing.
There is a byline with a fairly google-able name (reasonably uncommon), and it appears to represent a real person who was formerly an intern at Criteo. English may not be their first language, I guess.
But yes — I think it is a little unfortunate in the context.
uBlock Origin has prevented the following page from loading:
https://tech.criteo.com/blog/human-skills-ai-cant-develop-junior-engineers/
This happened because of the following filter:
||criteo.com^
Apparently Criteo is an advertising tool that collects tons of data from visitors. So why is this blog there? I can't help but wonder if it's part of a scheme to convince people to unblock them.
Yep, I was just about to comment about this but you beat me to it. You know something's amiss when you have to use incognito mode in order for the site to look the way it's supposed to.
I'm pretty sure this article is written by AI as there are lots of those long hyphens in it that AI seems so keen to use. If it is I can't tell whether that's ironic or reinforces their argument.
AI generates syntax fast, but syntax was never the bottleneck. If you do not learn the low-level fundamentals, you just become an editor for an intern who hallucinates.
Many years ago I was working at a firm that investigated stock pump and dump schemes on Yahoo Finance message boards.
We had to scrape the boards and then analyze messages to see if we could identify the identity of the people running the schemes.
This was 2002 and I wasn't aware that the LWP::Simple existed in Perl (aka the requests library in Python).
I ended up using basic TCP socket libraries to connect to port 80 and do http requests. It was, to put it mildly, a major pain in the ass.
That being said, I learned a TON about how http, tcp, html, etc all work together. 20+ years later, I still use some of that knowledge when analyzing network protocols at work.
I mention this b/c nothing is stopping people from doing similar projects now. e.g. Linux from scratch [0] is one great example of learning fundamentals even though we now have 1 click "launch me a Linux VPS" options.
Joel Spolsky make this point too. Even if you are using Java, it's still helpful to understand how CPUs interact with cache because the highest performance comes from optimizing the whole stack.
0 - https://www.linuxfromscratch.org/
My work is more data science related, but remember those same struggles where I spent hours, days, weeks, months, even years crashing my head against a problem. A lot of daily hours researching, talking to colleagues, implementing tangential papers that lead to nothing. Most of the time I arrived to a satisfactory solution, but others just have to gave up.
Maybe because I experienced all those struggles I'm confident to delegate a relevant portion of my work to some LLM, being able to validate the results, knowing what to ask and detect easily when something was bad implemented or where I gave ambiguous instructions.
The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions. It doesn't makes me feel comfortable shipping things I don't really understand, but also is nice to be able to do things that previously required years of studying and practice.
We are on strange times.
I have a tendency to prefer writing my own library for something instead of relying on someone else's. Not always, obviously, but quite often existing libraries fall short or are too complex to use. And solving the problem myself is almost always an educational experience.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
Also, your own library, at this point, is much less of an attack vector than some dependency from a package manager
From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
I was more concerned about supply chain attacks, along with the idea of stripping down all dependencies to truly just what you need.
Need a few math operations? pull those in, instead of an entire math lib, for example.
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
LLMs will easily exploit it these days.
Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
For personal projects that's fine, but I'd absolutely hate to work with someone who is rolling their own libs for everything, and then when they leave the company puts an enormous amount of tech debt into our hands. It also really doesn't make for good team-work if a developer always forces their own opinion on everything.
In a team environment, those libraries also should be team developed, at least, assure a minimal understanding from other team member.
+1 if they litter their own macros on it too
My side projects are all hand coded for this reason. There's no pressure to ship fast, so why not take the time?
Not to take away anything from this guy but man, my mind just stops registering information after lines like this: `As a Junior fresh out of school, “still learning what I’m doing” isn’t a caveat — it’s the job description`
Saw this comment and it got me wondering too, because there are at least some LLM tells as well as some places where it diverges into more natural writing.
There is a byline with a fairly google-able name (reasonably uncommon), and it appears to represent a real person who was formerly an intern at Criteo. English may not be their first language, I guess.
But yes — I think it is a little unfortunate in the context.
This blog post renders horribly on my Chrome browser. Then I realized it's because Ghostery is blocking a lot of it. Looks okay in Incognito mode.
If your site doesn't load basic UI elements because they're designated as ads, you're not doing it right.
I'm getting:
Umm, okay? The entire domain is blacklisted?Apparently Criteo is an advertising tool that collects tons of data from visitors. So why is this blog there? I can't help but wonder if it's part of a scheme to convince people to unblock them.
> I can't help but wonder if it's part of a scheme to convince people to unblock them
what could possibly make you think that?
really? a scheme so that people will go: "oh I'm so curious about this technical blog, better unblock the entire domain on unblock!"
and that's their scheme for evading adblockers?
what?
Also known as PR
I got the same thing with a different adblocker installed.
https://archive.ph/Z6ucP and https://web.archive.org/web/20261007080049/https://tech.crit... have it (archive.ph has it in light mode, web.archive has it in dark mode with no images loaded and some odd page portions).
My Pihole is blocking it too.
Yep, I was just about to comment about this but you beat me to it. You know something's amiss when you have to use incognito mode in order for the site to look the way it's supposed to.
I'm pretty sure this article is written by AI as there are lots of those long hyphens in it that AI seems so keen to use. If it is I can't tell whether that's ironic or reinforces their argument.
So I'm not sure what I've learnt from it!
I find the author’s attitude and approach here really admirable. Lot’s of good ideas in this post.
AI generates syntax fast, but syntax was never the bottleneck. If you do not learn the low-level fundamentals, you just become an editor for an intern who hallucinates.
This article is fully terrifying. I don't really know what else to say.
Except that perhaps, deep down, all those people who thought software engineering should be a chartered profession were right.
one of them developing taste to avoid working for adtech companies (ublock blocks the domain lol)
Is writing a blog post one of them?
I found all the breaks grating.
The skill required to get an AI to cooperate is not the same one as the craft of coding. Typing what it says out yourself will never get you there.
It’s like calling yourself a mechanic because you brought your car to a shop and paid for a mechanic to do an oil change.
I have a disability so I'm already forever midlevel.
Don't believe this about yourself. Everyone is capable of becoming exceptional in their own way.