Superintelligence CouncilСовет гения · sim.im

DHH · 2026-08-26 · source ↗ · whole document (8)

Programming with AI agents

`0:14:12`

Yes, but that said, AI is insanely capable at both finding-... and fixing security vulnerabilities. This was the whole blowup about Fable. This model was so capable of finding holes that a an attacker could exploit that it was simply not safe to release. So the irony here is that when you look at that field, it seems like we've reached levels of intelligence that virtually no human can match because many of these security holes are about stringing combo moves together. You find one little vulnerability here that by itself might not be the worst thing in the world, but then you combine it with four others, and suddenly you have RCE, remote command execution. Humans who are able to do that are very rare. They usually work inside state-sponsored organizations or other clandestine operations. They're not just out and about finding things. So they've gotten so good at that. The Linux distribution is why I've gotten 100% AI pilled. Because I've been working on Omarchy for the last three months, this version that just dropped a few days ago called Quatro. And almost right from the beginning I'm working on that version, the agent acceleration neared 100%, and in the last two months it has been 100%. I have not written-

`0:15:43`

... any of the code that's shipped in Quatro by hand. I've reviewed the shape of all of it. I've reviewed the individual lines of anything that's critical in the model layer of the system, and I've not looked at a bunch of the UI code. I have not looked at a bunch of the auxiliary code, and I've not written any of the new functionality entirely by hand. But then the web part, actually evolving Basecamp and Hey, our professional products that have lots of users and are relatively large code bases, have proven surprisingly tricky to fully accelerate with agents. We just released Basecamp 5 not too long ago. That was the first product at 37signals that was really agent accelerated. Because we were in this final sprint phase from around February. By then, agents were already good. And we had this early surge of, "It's solved. We can just have the designers do the programming. They know what features they want. They know what shape they want it to take. Let's just-- Let them vibe." And we let them vibe. And we ended up with a lot of PRs that individually perhaps could have been justified for a hot moment, taken all together, destroyed the architecture of the system. And we actually had to clean up manually, mop it up by hand, by human hand, to get back to an architecture that felt cohesive and coherent. So we still have a bit of that-- that was February, by the way. Things are quite different now.

`0:17:33`

To be able to vibe code on existing substantial

`0:17:38`

... code bases, even if they're crud, if you wanna retain the element of architecture that got that system to where it was. Now, that's also a point where I've stressed many times that when people accuse vibe coders of being slob generators, I go right back at them and say, "Have you looked at the average programmer's output?" That is some other slob too. If you've looked at behind the scenes of many great companies and what their code bases look like after there's been 3,000 humans through them, they're awful. Absolutely awful.