While this looks cool and useful with the proliferation of vibe coded things and artificial bot signals make it tough to trust things like this anymore. while this doesn't have much to do with this particular piece of software it's something that tickles the back of my brain every time i see a new project. it wouldn't be hard to stick some backdoor into a piece of ostensibly good software that does something useful now that code is so easy to generate. the onus is always on the user of the software but the onus seems to be larger than before. now i have to audit the code directly which is a big task.
I'm not worried about backdoors, I'm worried about product quality. How do I know it's worth my time to learn and install this new tool? Will it work thoughtfully and well? Will it be updated in a year?
It used to be such a hurdle to program a new tool that the product designer was somewhat invested. Now you can just build something like this with an hour's thought. A lot of the resulting products suck.
No idea about montray. It sounds like a useful idea! But I'm not sure it's even worth my time to evaluate, even though I need something like it.
I can't guarantee anything about the future development because obviously it consumes my free time which I don't have much and dunno how much of it I'll have in the future; but you can get some sense about the level of my investment in this tool by looking at the 5-year git history.
Anyway, not trying to sell it to you at all, and def don't invest your time in it unless you feel like it!
weaksauce | 4 hours ago
While this looks cool and useful with the proliferation of vibe coded things and artificial bot signals make it tough to trust things like this anymore. while this doesn't have much to do with this particular piece of software it's something that tickles the back of my brain every time i see a new project. it wouldn't be hard to stick some backdoor into a piece of ostensibly good software that does something useful now that code is so easy to generate. the onus is always on the user of the software but the onus seems to be larger than before. now i have to audit the code directly which is a big task.
definitely a cool piece of software though!
nelson | 3 hours ago
I'm not worried about backdoors, I'm worried about product quality. How do I know it's worth my time to learn and install this new tool? Will it work thoughtfully and well? Will it be updated in a year?
It used to be such a hurdle to program a new tool that the product designer was somewhat invested. Now you can just build something like this with an hour's thought. A lot of the resulting products suck.
No idea about montray. It sounds like a useful idea! But I'm not sure it's even worth my time to evaluate, even though I need something like it.
[OP] dimonomid | 2 hours ago
I can't guarantee anything about the future development because obviously it consumes my free time which I don't have much and dunno how much of it I'll have in the future; but you can get some sense about the level of my investment in this tool by looking at the 5-year git history.
Anyway, not trying to sell it to you at all, and def don't invest your time in it unless you feel like it!
[OP] dimonomid | 4 hours ago
Tbh in my mind the effect is the opposite.
LLMs don't really make it significantly easier to sneak a backdoor in a software product. It was easy enough without LLMs as well.
However, LLMs make it much easier to find such backdoor in a big software product, or with reasonable certainty conclude that no backdoor exists.
So, you can ask LLM to check if Montray or other project is clean of backdoors, and then use it with a peace of mind.