Mike Sperber

376 Followers
456 Following
1.9K Posts
Husband, father, C*O at Active Group, functional programmer, researcher, teacher, theater person.
websitehttps://www.deinprogramm.de/sperber/
software architecture
theater
searchable

So here's the other thing that bothers me about all this. Regardless of the eventual results, this thing they're doing is *incredibly* resource intensive. They routinely spend billions of dollars on training these models, and billions more on operating them. It's not simple to parse out what fraction of that is directly attributable to the massive scale vuln finder/fabricator. But for the sake of argument lets just pick a plausible number, and call it 50-100 million dollars.

What could we have gotten for 50-100 million dollars of sponsorship for security audits? Prior to this, the largest single investment into FOSS security I'm aware of was the 2015 audit of openssl, after the heartbleed incident. It's hard to find precise costs for that, but I found a few sources estimating 1.2 million dollars, and that is arguably the most security critical piece of software in the world.

But suddenly there's 100x more resources available to do this work, now that producing the artifact can be done with stolen labor? Now that they can externalize the cost of false positives onto the already mostly unpaid maintainers of these projects? Even if their claims are true, which we have no reason to believe and very good reason not to, it's still a travesty

I've spent most of my adult life writing codeโ€”not because I had to, but because I love the process. And I've taught hundreds of students (thousands through courses) to love it too. There's a beauty in expressing human reasoning in code, just as there is in mathematics. You can put care into even the most mundane of tasks.

I know not everyone feels that way about it. I know for many, maybe most, it's just a job. It's just business.

But god damn, we created a wholly new form of expression here. I don't think it's that different from others. It just sells better, so "art" is hard to assign to it.

I still think it can be beautiful. But the beauty comes first from the creator's hand.

@deech It's one of the ironies of modern programming that what used to be OO is obsessed with process, and the FP folks are the ones doing the data ("object") modeling.
@wingo Even funnier with the German dubbing, where they say โ€œOonixโ€.
rewatched jurassic park recently and the unix vibes are v v good

โœจ ๐—ก๐˜‚๐—ฟ ๐—ป๐—ผ๐—ฐ๐—ต ๐—ฒ๐—ถ๐—ป๐—ฒ ๐—ช๐—ผ๐—ฐ๐—ต๐—ฒ ๐—ฏ๐—ถ๐˜€ ๐˜‡๐˜‚๐—บ ๐—ฆ๐—ผ๐—ณ๐˜๐˜„๐—ฎ๐—ฟ๐—ฒ ๐—”๐—ฟ๐—ฐ๐—ต๐—ถ๐˜๐—ฒ๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—™๐—ผ๐—ฟ๐˜‚๐—บ ๐Ÿฎ๐Ÿฌ๐Ÿฎ๐Ÿฒ! ๐ŸŽ‰ In genau einer Woche treffen sich Softwarearchitekt:innen, Entwickler:innen und IT-Expert:innen in Mรผnchen, um zwei Tage lang รผber moderne #Softwarearchitektur, aktuelle Herausforderungen und bewรคhrte Lรถsungsansรคtze zu diskutieren.

๐Ÿ’ก ๐—ช๐—ฎ๐—ฟ๐˜‚๐—บ ๐˜€๐—ถ๐—ฐ๐—ต ๐—ฑ๐—ฎ๐˜€ ๐—ฆ๐—”๐—™ ๐—น๐—ผ๐—ต๐—ป๐˜:
โœ” 2 Tage mit 22 Expert:innen und 23 Sessions auf Deutsch
โœ” Praxisnahe Inhalte statt Sales-Pitches
โœ” Themen: #DDD, #KI, #APIs, #Cloud etc.

๐Ÿ‘‰ saf.isaqb.org

#SAF2026 #iSAQB

@lindsey there are ways to make conferences cheaper, but making this suggestion out loud is akin to farting in a quiet room

RE: https://discuss.systems/@activegroupgmbh/116318230028504286

Nรคchste Woche ist iSAQBยฎ Software Architecture Forum, und @sperbsen ist dabei! Noch gibt es Tickets:

@leah Yeah, bummer, as it was such a pleasure to use. One of the most ergonomic languages ever.