logoalt Hacker News

skydhashtoday at 1:32 PM1 replyview on HN

I don’t because I trust the process to get the artifacts. Why? Because it’s easy to replicate and verify. Just like how proof works in math.

You can’t verify LLM’s output. And thus, any form of trust is faith, not rational logic.


Replies

ben_wtoday at 2:29 PM

I don't install 3rd party dependencies if I can avoid them. Why? Because although someone could have verified them, there's no guarantee that anybody actually did, and this difference has been exploited by attackers often enough to get its own name, a "supply-chain attack".

With an LLM’s output, it is short enough that I can* put in the effort to make sure it's not obliviously malicious. Then I save the output as an artefact.

* and I do put in this effort, unless I'm deliberately experimenting with vibe coding to see what the SOTA is.

show 1 reply