Many years ago I was working at a firm that investigated stock pump and dump schemes on Yahoo Finance message boards.
We had to scrape the boards and then analyze messages to see if we could identify the identity of the people running the schemes.
This was 2002 and I wasn't aware that the LWP::Simple existed in Perl (aka the requests library in Python).
I ended up using basic TCP socket libraries to connect to port 80 and do http requests. It was, to put it mildly, a major pain in the ass.
That being said, I learned a TON about how http, tcp, html, etc all work together. 20+ years later, I still use some of that knowledge when analyzing network protocols at work.
I mention this b/c nothing is stopping people from doing similar projects now. e.g. Linux from scratch [0] is one great example of learning fundamentals even though we now have 1 click "launch me a Linux VPS" options.
Joel Spolsky make this point too. Even if you are using Java, it's still helpful to understand how CPUs interact with cache because the highest performance comes from optimizing the whole stack.
My work is more data science related, but remember those same struggles where I spent hours, days, weeks, months, even years crashing my head against a problem. A lot of daily hours researching, talking to colleagues, implementing tangential papers that lead to nothing. Most of the time I arrived to a satisfactory solution, but others just have to gave up.
Maybe because I experienced all those struggles I'm confident to delegate a relevant portion of my work to some LLM, being able to validate the results, knowing what to ask and detect easily when something was bad implemented or where I gave ambiguous instructions.
The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions. It doesn't makes me feel comfortable shipping things I don't really understand, but also is nice to be able to do things that previously required years of studying and practice.
I have a tendency to prefer writing my own library for something instead of relying on someone else's. Not always, obviously, but quite often existing libraries fall short or are too complex to use. And solving the problem myself is almost always an educational experience.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
If I could have a dollar for every casual strcpy in my DIY libraries I would be a rich man. And would never dare to put them in the line of fire of unwashed Internet :-)
Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
I've gone back and forth on this. I've been burned with third party libraries, but I've also been burned spending so much time/effort maintaining my own library that I can't get the real job done.
For personal projects that's fine, but I'd absolutely hate to work with someone who is rolling their own libs for everything, and then when they leave the company puts an enormous amount of tech debt into our hands. It also really doesn't make for good team-work if a developer always forces their own opinion on everything.
Most of the dev work out there in the broader corporate world (not startups) doesn't care about "shipping fast". Writing code is not the bottleneck.
When your day consists of lots of meetings with humans who have technically vague requirements, nobody ever meets you halfway. Your primary job becomes bridging those knowledge gaps mostly by yourself. You have to buckle down and make independent decisions that neither the stakeholders, nor the LLMs, can help you with. You get paid because the organization trusts you with lots of information that only lives inside people's heads.
In that situation, the LLMs are only really useful for familiarizing yourself with the existing code. They are completely irrelevant to writing code. You'll have entire two-week sprints to make very precise changes to only about a dozen lines of code, but the coding is not even 10% of what you're paid to do with that time.
In my opinion, this is what senior software engineering always was. Everyone raving about LLMs are basically code monkeys working in sweatshops.
I fully agree. I see this today, even "so early" in AI adoption (it's been ONLY a couple of years!). I'm a firm believer in "know the stack all the way to the bottom". Possibly I'm an extremist, I believe every developer should at least know a little bit of assembly and maybe even run the NAND game (build a computer from NAND gates - https://nandgame.com/). But basic skills lead to deeper understanding of the elements in the stack. Exactly how TCP works. BGP. Why "it's always DNS". Interrupts. Virtualization. What the hell is PSI. Why kernel space is not user space. JVM allocation pressure. String interning. Concurrency and thread sync and "why isn't my code working multi-threaded" or even "I'll just sync through the db".
I don't know how to solve these. I tried Java internal tech talks (internal to my company) but most devs just weren't interested. I try ad-hoc with sessions with devs but very rarely I feel a bite.
The pipeline is collapsing. In 5 years, who will be the next senior devs? I have so few candidates to look at, and no new ones at all.
I feel like this has been a growing problem even before AI, I've seen so many people who have spent more years at better universities than I have, who during their junior years could barely do what I was doing when I got out of community college with only an associates, and this was back 10 years or so. I also have a few new graduates who are very solid, I don't know if it's just that their specific university prepares them better, or they took it more seriously. I remember how notoriously hard the testing was at UCF for the CS program, I hear they've made it 'easier' and I believe it was and still is pen and paper, this was for the CS Foundation course, which if you failed (and many did/have) you couldn't take upper level CS courses.
I think the reality is that schools need to stop pretending like they're producing good students just because they're doing the classwork, nobody wants to hire incompetent people.
I think the reason Anthropic thinks programming will be dead in "6 months" or whatever random nonsense they spout is because you might not need intimate knowledge, but they forget how over expensive all their tech is, by the time they can produce an always perfect software developer, will anyone be able to afford it?
Heck they can't stop people from jailbreaking the models, or from having it commit felonies.
Not to take away anything from this guy but man, my mind just stops registering information after lines like this: `As a Junior fresh out of school, “still learning what I’m doing” isn’t a caveat — it’s the job description`
Saw this comment and it got me wondering too, because there are at least some LLM tells as well as some places where it diverges into more natural writing.
There is a byline with a fairly google-able name (reasonably uncommon), and it appears to represent a real person who was formerly an intern at Criteo. English may not be their first language, I guess.
But yes — I think it is a little unfortunate in the context.
uBlock Origin has prevented the following page from loading:
https://tech.criteo.com/blog/human-skills-ai-cant-develop-junior-engineers/
This happened because of the following filter:
||criteo.com^
Apparently Criteo is an advertising tool that collects tons of data from visitors. So why is this blog there? I can't help but wonder if it's part of a scheme to convince people to unblock them.
Yep, I was just about to comment about this but you beat me to it. You know something's amiss when you have to use incognito mode in order for the site to look the way it's supposed to.
On one side, as an engineer, Did you really expected to delegate thinking to a Large Language Model? On the other side, How human of the author to believe the illusion that fluency means knowledge, can't fault him for that.
On one side, so you discover that the development of your personal skills can be stilled to a set of instructions to an LLM? How much more of you are you willing to capitulate? On the other hand, I think is brave to write the article confessing his growth.
There will be a generation were had been trained using the current teaching methods where education in it self is a product as opposed the gym where the brain develop muscles. The muscles end up been develop at work. This is not about "seniority", this is about the character to develop yourself, to welcome the challenge. Which I guess good for him, he has it.
Reading these kind of things for me is weird.
(btw. I don't like the term AI because there is no I in AI, but that is a different talk, or maybe that self awareness is what makes it so confusing)
AI generates syntax fast, but syntax was never the bottleneck. If you do not learn the low-level fundamentals, you just become an editor for an intern who hallucinates.
I'm pretty sure this article is written by AI as there are lots of those long hyphens in it that AI seems so keen to use. If it is I can't tell whether that's ironic or reinforces their argument.
This is something that I worry about as well for my junior incident responders at my company.
We have a culture that I’ve pushed to always understand what the model is doing, even if you have to go back after the response action is done and walk through it step by step.
I encourage everyone to use AI to the extent that they feel comfortable and can do their jobs but I feel it’s necessary to always be able to do what the LLM has done if you don’t have access to it
Many years ago I was working at a firm that investigated stock pump and dump schemes on Yahoo Finance message boards.
We had to scrape the boards and then analyze messages to see if we could identify the identity of the people running the schemes.
This was 2002 and I wasn't aware that the LWP::Simple existed in Perl (aka the requests library in Python).
I ended up using basic TCP socket libraries to connect to port 80 and do http requests. It was, to put it mildly, a major pain in the ass.
That being said, I learned a TON about how http, tcp, html, etc all work together. 20+ years later, I still use some of that knowledge when analyzing network protocols at work.
I mention this b/c nothing is stopping people from doing similar projects now. e.g. Linux from scratch [0] is one great example of learning fundamentals even though we now have 1 click "launch me a Linux VPS" options.
Joel Spolsky make this point too. Even if you are using Java, it's still helpful to understand how CPUs interact with cache because the highest performance comes from optimizing the whole stack.
0 - https://www.linuxfromscratch.org/
My work is more data science related, but remember those same struggles where I spent hours, days, weeks, months, even years crashing my head against a problem. A lot of daily hours researching, talking to colleagues, implementing tangential papers that lead to nothing. Most of the time I arrived to a satisfactory solution, but others just have to gave up.
Maybe because I experienced all those struggles I'm confident to delegate a relevant portion of my work to some LLM, being able to validate the results, knowing what to ask and detect easily when something was bad implemented or where I gave ambiguous instructions.
The catch is that I'm starting to do things where I haven't experienced those struggles in prior times, for example, web app development for my data work. I don't feel confident that I'm doing a good work, I'm just vibing, don't know the implications of some decisions. It doesn't makes me feel comfortable shipping things I don't really understand, but also is nice to be able to do things that previously required years of studying and practice.
We are on strange times.
I have a tendency to prefer writing my own library for something instead of relying on someone else's. Not always, obviously, but quite often existing libraries fall short or are too complex to use. And solving the problem myself is almost always an educational experience.
For example, I'm currently writing my own graph layout library because I'm not happy with Dagre and ELK.
Also, your own library, at this point, is much less of an attack vector than some dependency from a package manager
From maintaining dozens of projects over decades: yes and no.
Your custom library probably won't fall to a library-specific attack unless you were actively aiming for interoperability. However your custom library almost certainly has many vulnerabilities that you haven't heard of yet. Just a few weeks ago I saw a custom library (PHP) with SQL injection vulnerabilities, I couldn't believe it. I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
> I suggested to the client that if he still resists having another professional audit it, at least let some frontier LLM have a look. Yes, I recommended this guy to vibe code his security-sensitive code because "professional developers" today still miss the basics.
Amen. Nowadays it is borderline malpractice to not use a coding agent for checking the security of your code.
They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
If I could have a dollar for every casual strcpy in my DIY libraries I would be a rich man. And would never dare to put them in the line of fire of unwashed Internet :-)
I was more concerned about supply chain attacks, along with the idea of stripping down all dependencies to truly just what you need.
Need a few math operations? pull those in, instead of an entire math lib, for example.
Same as people often say about AI writing bespoke applications, these days... Libraries (like applications) often have 98% stuff you don't need, and 2% stuff you do. You can end up better off with your own thing.
I've always liked writing my own libraries and minimal frameworks for PHP, which seems to be a very unpopular opinion, but it almost entirely removes churn from your stack, which is nice for tools that may stick around for years or decades. I also never switched off jquery, preferring simple techs. I'm almost definitely operating at a smaller scale than most web developers here, though.
I've gone back and forth on this. I've been burned with third party libraries, but I've also been burned spending so much time/effort maintaining my own library that I can't get the real job done.
LLMs will easily exploit it these days.
For personal projects that's fine, but I'd absolutely hate to work with someone who is rolling their own libs for everything, and then when they leave the company puts an enormous amount of tech debt into our hands. It also really doesn't make for good team-work if a developer always forces their own opinion on everything.
In a team environment, those libraries also should be team developed, at least, assure a minimal understanding from other team member.
+1 if they litter their own macros on it too
My side projects are all hand coded for this reason. There's no pressure to ship fast, so why not take the time?
Most of the dev work out there in the broader corporate world (not startups) doesn't care about "shipping fast". Writing code is not the bottleneck.
When your day consists of lots of meetings with humans who have technically vague requirements, nobody ever meets you halfway. Your primary job becomes bridging those knowledge gaps mostly by yourself. You have to buckle down and make independent decisions that neither the stakeholders, nor the LLMs, can help you with. You get paid because the organization trusts you with lots of information that only lives inside people's heads.
In that situation, the LLMs are only really useful for familiarizing yourself with the existing code. They are completely irrelevant to writing code. You'll have entire two-week sprints to make very precise changes to only about a dozen lines of code, but the coding is not even 10% of what you're paid to do with that time.
In my opinion, this is what senior software engineering always was. Everyone raving about LLMs are basically code monkeys working in sweatshops.
Terry Tao has a term for this I liked quite a bit, "productive struggle"
I fully agree. I see this today, even "so early" in AI adoption (it's been ONLY a couple of years!). I'm a firm believer in "know the stack all the way to the bottom". Possibly I'm an extremist, I believe every developer should at least know a little bit of assembly and maybe even run the NAND game (build a computer from NAND gates - https://nandgame.com/). But basic skills lead to deeper understanding of the elements in the stack. Exactly how TCP works. BGP. Why "it's always DNS". Interrupts. Virtualization. What the hell is PSI. Why kernel space is not user space. JVM allocation pressure. String interning. Concurrency and thread sync and "why isn't my code working multi-threaded" or even "I'll just sync through the db".
I don't know how to solve these. I tried Java internal tech talks (internal to my company) but most devs just weren't interested. I try ad-hoc with sessions with devs but very rarely I feel a bite.
The pipeline is collapsing. In 5 years, who will be the next senior devs? I have so few candidates to look at, and no new ones at all.
I feel like this has been a growing problem even before AI, I've seen so many people who have spent more years at better universities than I have, who during their junior years could barely do what I was doing when I got out of community college with only an associates, and this was back 10 years or so. I also have a few new graduates who are very solid, I don't know if it's just that their specific university prepares them better, or they took it more seriously. I remember how notoriously hard the testing was at UCF for the CS program, I hear they've made it 'easier' and I believe it was and still is pen and paper, this was for the CS Foundation course, which if you failed (and many did/have) you couldn't take upper level CS courses.
I think the reality is that schools need to stop pretending like they're producing good students just because they're doing the classwork, nobody wants to hire incompetent people.
I think the reason Anthropic thinks programming will be dead in "6 months" or whatever random nonsense they spout is because you might not need intimate knowledge, but they forget how over expensive all their tech is, by the time they can produce an always perfect software developer, will anyone be able to afford it?
Heck they can't stop people from jailbreaking the models, or from having it commit felonies.
Not to take away anything from this guy but man, my mind just stops registering information after lines like this: `As a Junior fresh out of school, “still learning what I’m doing” isn’t a caveat — it’s the job description`
Saw this comment and it got me wondering too, because there are at least some LLM tells as well as some places where it diverges into more natural writing.
There is a byline with a fairly google-able name (reasonably uncommon), and it appears to represent a real person who was formerly an intern at Criteo. English may not be their first language, I guess.
But yes — I think it is a little unfortunate in the context.
This blog post renders horribly on my Chrome browser. Then I realized it's because Ghostery is blocking a lot of it. Looks okay in Incognito mode.
If your site doesn't load basic UI elements because they're designated as ads, you're not doing it right.
I'm getting:
Umm, okay? The entire domain is blacklisted?Apparently Criteo is an advertising tool that collects tons of data from visitors. So why is this blog there? I can't help but wonder if it's part of a scheme to convince people to unblock them.
> I can't help but wonder if it's part of a scheme to convince people to unblock them
what could possibly make you think that?
really? a scheme so that people will go: "oh I'm so curious about this technical blog, better unblock the entire domain on unblock!"
and that's their scheme for evading adblockers?
what?
Also known as PR
I got the same thing with a different adblocker installed.
https://archive.ph/Z6ucP and https://web.archive.org/web/20261007080049/https://tech.crit... have it (archive.ph has it in light mode, web.archive has it in dark mode with no images loaded and some odd page portions).
My Pihole is blocking it too.
Yep, I was just about to comment about this but you beat me to it. You know something's amiss when you have to use incognito mode in order for the site to look the way it's supposed to.
I have so many mixed feelings about this...
On one side, as an engineer, Did you really expected to delegate thinking to a Large Language Model? On the other side, How human of the author to believe the illusion that fluency means knowledge, can't fault him for that.
On one side, so you discover that the development of your personal skills can be stilled to a set of instructions to an LLM? How much more of you are you willing to capitulate? On the other hand, I think is brave to write the article confessing his growth.
There will be a generation were had been trained using the current teaching methods where education in it self is a product as opposed the gym where the brain develop muscles. The muscles end up been develop at work. This is not about "seniority", this is about the character to develop yourself, to welcome the challenge. Which I guess good for him, he has it.
Reading these kind of things for me is weird.
(btw. I don't like the term AI because there is no I in AI, but that is a different talk, or maybe that self awareness is what makes it so confusing)
AI generates syntax fast, but syntax was never the bottleneck. If you do not learn the low-level fundamentals, you just become an editor for an intern who hallucinates.
This article is fully terrifying. I don't really know what else to say.
Except that perhaps, deep down, all those people who thought software engineering should be a chartered profession were right.
The skill required to get an AI to cooperate is not the same one as the craft of coding. Typing what it says out yourself will never get you there.
It’s like calling yourself a mechanic because you brought your car to a shop and paid for a mechanic to do an oil change.
I find the author’s attitude and approach here really admirable. Lot’s of good ideas in this post.
I'm pretty sure this article is written by AI as there are lots of those long hyphens in it that AI seems so keen to use. If it is I can't tell whether that's ironic or reinforces their argument.
So I'm not sure what I've learnt from it!
I was using a lot of dashes before AI. What do I do now? -- Change?
AI has gotten to the point where there really is no telling.
Is writing a blog post one of them?
I found all the breaks grating.
This is something that I worry about as well for my junior incident responders at my company.
We have a culture that I’ve pushed to always understand what the model is doing, even if you have to go back after the response action is done and walk through it step by step.
I encourage everyone to use AI to the extent that they feel comfortable and can do their jobs but I feel it’s necessary to always be able to do what the LLM has done if you don’t have access to it
one of them developing taste to avoid working for adtech companies (ublock blocks the domain lol)
I have a disability so I'm already forever midlevel.
Don't believe this about yourself. Everyone is capable of becoming exceptional in their own way.