9 Comments
User's avatar
ToxSec's avatar

“A lack of knowledge of a system’s internal workings will eventually drive maintenance costs to an unbearable level and create significant technical debt that will need to be paid off someday.”

totally agree. this is totally a hidden cost that ends up being paid much later. great read! 🔥

Erich Winkler's avatar

This was true even before there was a tool capable of generating an enormous amount of code that nobody really understood.

I think companies often underestimate how valuable developers' knowledge is to their business in the long term.

Chad Thiele's avatar

That last one is so common. I'm not sure if I've ever seen an AI agent do field validation unless I specifically asked it to.

Erich Winkler's avatar

And even if you ask for it, it is very difficult to force it to validate ALL inputs, not just some.

That inconsistency is also something I see very often in AI-generated code.

Chad Thiele's avatar

That's very true too.

Erich Winkler's avatar

It’s a funny world we live in!

Thank you for your comments, Chad!

Nelson Lopes's avatar

This reminds me of my first vibe-coded platform. Even though my very first prompt made it clear that security was of the utmost importance, a few iterations later I did a review and found an endpoint with no authentication. When I asked about it, the answer was that it had been created "just for testing purposes."

Anyone marveling at how fast these platforms come together (with genuinely great layouts), may end up shipping to prod without the review that catches this stuff

Erich Winkler's avatar

That’s something I tried to stress in the article. The way AI generates code, it’s impossible to ensure that it will produce only secure code. And this particular issue appears surprisingly often.

We used to have complicated code review processes before pushing any code to production because people make mistakes. Maybe we shouldn’t abandon those processes. They can still be quite useful!

Nelson Lopes's avatar

Absolutely!