With the power of AI, you too can take your startup from “fucking around” to “finding out” in as little as two days!
@daisy I have a sneaking suspicion that those weird people who are making his saas behave in unexpected ways are what techies often call 'users'.
@clockworkfish @daisy guys, I'm under attack by people trying to normally use my website whose internals i am completely ignorant of
@clockworkfish @daisy he should replace them with an AI

@wesdym @clockworkfish @daisy From elsewhere and years ago:

Someone: "What if I walk into a beer and order a bar, though?"

Me: "Due to a bad inheritance tree, walking into a beer is allowed. The bar init begins and attempts to build a stock of beer. A bug in the beer cache causes the bar to attempt to stock the beer you're in. Since it's currently in an undefined state, it dead locks. You drown in beer."

@sharif @wesdym @daisy see also: If this bar doesn't do drive through beer, why did you make this door large enough to drive through?

Testers are awesome. <3<3 Buy your Tester a beverage today! (If they want one. Otherwise, just ask them what they'd like as a show of appreciation, I guess.)

@clockworkfish @daisy youn know, I even think it's not users, it could simply be because the code is complete garbage and generates random things because, it's just... randomly generated code.

@daisy

"Sure, I don't know how to write code and I've admitted I don't actually know what I'm doing, but clearly I'm being attacked and I'm not the victim of my own foolish pride."

@daisy

BTW, as a web developer, in a time when build-your-own-website builders are available, I've seen a similar scenario play out hundreds of times.

@rgulick @daisy A friend of mine was accused of hacking a website. Turns out, he did. By accident. He happened to know more about the software than the guy who set it up. No malicious intent, but to the owner it was an out-of-the-blue attack.

@wesdym

I hope the owner paid the guy for security testing services.
@daisy

@rgulick @daisy In a sense, he did. Once the whole thing got sorted out, he did end up being a web consultant for him.

@rgulick @daisy

Frontpage for websites.
Microsoft Access for databases before that.

This tool lets me do things without having to understand them!

@daisy then people wonder why data protection laws exist, so people selling services, with no clue about security, can be held liable when inevitable their users data gets stolen.
@daisy while sharing what he does on X might be part of the problem, it's certainly far from the root cause.
@daisy I am sure its the "ppl" not the code.

@daisy

For the curious, this is the product said person is selling: https://enrichlead.com

GDPR compliant according to the website homepage 😅

EnrichLead | Generate quality leads from website traffic

Generate quality leads from website traffic, even if they don't fill out a contact form.

@JayeLTee @daisy Ah yes, the incredibly gross digital equivalent of following every window shopper back to their house, ringing their doorbell, and trying to sell them something. Couldn't be happier that the whole thing fell apart on them due to incompetence.
@JayeLTee @daisy I have seen this kind of snake oil before. Beats me how people think this is possible without grossly being creepy and invasive.
@JayeLTee @daisy wow am I glad I’m not in a position to be told to “try” this new pixel on the company website, any more
@JayeLTee @daisy Presumably here he means people should listen to Pearl Jam more. I don't disagree, but not sure what the relevance is to the bit above...
@woe2you @JayeLTee @daisy "no code" - gives out code to copy to your code.

@JayeLTee @daisy Fuck's sake, if this is correct it's literally using a bare git repo's content path instead of actually publishing it proper somewhere.

Amazing.

@daisy That's the plot from Goethe's "The Sorcerer's Apprentice", modernized.

"Tired of fetching water by pail, the apprentice enchants a broom to do the work for him, using magic in which he is not fully trained. The floor is soon awash with water, the apprentice realizes that he cannot stop the broom because he does not know the magic required to do so. "

https://en.wikipedia.org/wiki/The_Sorcerer%27s_Apprentice

The Sorcerer's Apprentice - Wikipedia

@mithos @daisy

"Cook, little pot. Cook!" and the pot cooked porridge...

@daisy local man learns you should NOT release sensitive data about how you built your SAAS cloud service publicly.
@daisy Maybe he should take some of that money he is making and hire a competent human developer.

@daisy "I made this black box by telling another black box what to do! It does a thing, I have no clue how it works but it does the thing which I also have no clue about, isn't that awesome?"

LATER:

"Shit fuck, this black box is doing things but I don't know what! I am caught in a riptide of my own creation pulling me out to sea, send help!!"

@daisy His postmortem is fun to read — he left his API keys exposed and allowed users to bypass the subscription process by editing their own data, then wrote it all off as a learning experience because he would STILL rather use an LLM than an experienced developer. The next security mistake he makes he won’t even see coming.

Reminds me of how my brother asked me last year if I could help him build a secure software system for his fantasy startup — on an old computer in his basement.

I had to tell him (1) that’s not what I specialize in, and (2) if you really want that stuff secure, then pay a web host who already knows how to do it right. A repurposed PC in your basement might be okay for a static website, but not for anything you really need to protect.

@daisy i love the smell of ai bros tears in the morning

@erizocosmico @daisy

Damn it Shin! I read this in your voice-over.

@daisy Plot twist: The weird people are just the usual automated bots that scan the internet for services with the standard login credentials and exploit those...
@daisy Now, look at that. If AI doesn't make people more intelligent in a shortest time possible, I don't know what does.

@daisy HA!

All developers should stay faaaar away from assisting with this

Let them brew

@daisy This has big confident (and wrong) Elon energy, like: "I unplugged a bunch of shit and Twitter still works, lol, guess I we didn't need those after all."
@daisy
Replace “my saas” with “X” and “people” with “Ukraine” and you get #musk whines all last week.

@daisy Given the fact that I know how over 90% off all "Howtos" on the Internet are written I'm absolutely not surprised that AI miserably fails on basic operational (security) tasks...

"Club chmod -R 777 *" YOLO!

@daisy don't learn to code i guess :D. Cause you have ai that can do all the things :D
@daisy
this is why we do devsecops and hate vibe coding

@daisy

I'm less than an amateur in coding and never heard of Cursor, but I have this feeling that this AI builder is providing the usual weird usage built-in with the product it created. Cos it obviously learnt how the finished product should look like: used. Actually, I wouldn't be surprised if the post itself was AI... 🤔 🤪

#deadInternet

@daisy
They forgot to config robots.txt to "No funny stuff guyz. OK?".
@daisy I stand by my statement that "AI is no substitute for knowing what the hell you're doing".

@veronica @daisy

this.

AI is great for simplifying or speed up the tasks you have to do. But first you must understand what the AI is doing with your tasks. And the only way to learn this, is by doing it yourself.

@daisy "I had an AI completely construct this building and now people are sawing at the support beams how do I stop them please help I didn't major in Architecture"
@[email protected] i love that this incident stopped him from capitalizing letters
@daisy I call this well deserved just for still being on this fascist platform.
@daisy finally, something to make me laugh today 😂
@daisy the whole account look AI generated.

@daisy ”there are just some weird ppl out there”

Yeah. This is classic libertarian. They have it all figured out.

Little children with no experience fighting a war, surprised that there are bullets flying everywhere!

@daisy I see things are going well on Bluecheck Twitter

@daisy All those vulnerabilities would have been discovered and fixed if only they'd used my CRaaS (code review as a service) AI.

(don't tell anybody but CRaaS just pipes it through lint.)

@daisy
Quoting the founder:
"Unpopular opinion: coding skills are a disadvantage for SaaS founders. They get stuck on tech, often ignoring marketing.",
because software is about money, not features and user experience...