Skip to main content

Rent-free Thoughts

Some thoughts that have been living rent-free recently in my head about AI...

We should be more precise when we talk about it. We’ve had "AI" for decades. Google Translate, Alexa and Siri, computer vision in video games, OCR in mail sorting, protein folding models all fall under artificial intelligence, but there’s no mass panic over these. The current progress is in generative AI, and that's where most of the public concern is. I’m guilty of the shorthand myself, saying "AI" when I mean "generative AI".

People are afraid of generative AI, but the real problem is concentrated power and corporate greed. Someone wanting to sow disinformation could do so without generative AI models, and deep-pocket organizations of state could finance extreme actors if they wanted to. The tools evolved, but the risks aren’t new. The bigger problem that few are talking about is corporations who are aligning the technology for their own goals; they increasingly dictatate what we can use and how we can use it. Railroads were good for America, but robber barons were not. The new American technological libertarianism can lead to innovation and profits, but how do we ensure profit doesn’t eclipse regard for human worth or societial integrity? I don’t have an answer.

AI coding tools could lock in bad practices. Models are trained on massive amounts of code, much of which is dated. But best practices evolve. What was considered good PHP or JavaScript ten years ago is not what we consider best practices today. And retraining models is expensive. If models mostly generate code from old samples, and languages for new projects are picked based on AI support rather than if they're the best fit for the problem domain, the industry is going to end up stagnating with mediocre JavaScript and Python code.

Generative AI is useful, but the truly valuable applications have yet to arrive. The real winners won’t be those who use AI tooling to solve niche problems, like writing code, generate marketing plans, or “talking” to PDFs. And cramming chatbot technology into existing apps and websites isn’t what the market really wants. The real winners will be those who find a genuinely useful application for it. The first example of an interesting AI driven application I’ve seen is Google’s NotebookLM as a study aid. There are probably a lot of behind-the-scenes wins available too, for example reliable data structuring and other ETL tasks.

A few extra stand-alone assertions:

  • No one cares about prompting, they just want things to work.
  • I have no issue with generated content. I do have issue with slop. Unfortunately, there’s a lot of lazy slop right now.
  • I don’t trust Sam Altman, Mark Zuckerberg, or Elon Musk’s vision for humanity’s future. Unless they’re offering me a job.

Comments

Popular posts from this blog

Writing a Minimal PSR-0 Autoloader

An excellent overview of autoloading in PHP and the PSR-0 standard was written by Hari K T over at PHPMaster.com , and it's definitely worth the read. But maybe you don't like some of the bloated, heavier autoloader offerings provided by various PHP frameworks, or maybe you just like to roll your own solutions. Is it possible to roll your own minimal loader and still be compliant? First, let's look at what PSR-0 mandates, taken directly from the standards document on GitHub : A fully-qualified namespace and class must have the following structure \<Vendor Name>\(<Namespace>\)*<Class Name> Each namespace must have a top-level namespace ("Vendor Name"). Each namespace can have as many sub-namespaces as it wishes. Each namespace separator is converted to a DIRECTORY_SEPARATOR when loading from the file system. Each "_" character in the CLASS NAME is converted to a DIRECTORY_SEPARATOR . The "_" character has no special ...

Safely Identify Dependencies for Chrooting

The most difficult part of setting up a chroot environment is identifying dependencies for the programs you want to copy to the jail. For example, to make cp available, not only do you need to copy its binary from /bin and any shared libraries it depends on, but the dependencies can have their own dependencies too that need to be copied. The internet suggests using ldd to list a binary’s dependencies, but that has its own problems. The man page for ldd warns not to use the script for untrusted programs because it works by setting a special environment variable and then executes the program. What’s a security-conscious systems administrator to do? The ldd man page recommends objdump as a safe alternative. objdump outputs information about an object file, including what shared libraries it links against. It doesn’t identify the dependencies’ dependencies, but it’s still a good start because it doesn’t try to execute the target file. We can overcome the dependencies of depende...

A Unicode fgetc() in PHP

In preparation for a presentation I’m giving at this month’s Syracuse PHP Users Group meeting, I found the need to read in Unicode characters in PHP one at a time. Unicode is still second-class in PHP; PHP6 failed and we have to fallback to extensions like the mbstring extension and/or libraries like Portable UTF-8 . And even with those, I didn’t see a unicode-capable fgetc() so I wrote my own. Years ago, I wrote a post describing how to read Unicode characters in C , so the logic was already familiar. As a refresher, UTF-8 is a multi-byte encoding scheme capable of representing over 2 million characters using 4 bytes or less. The first 128 characters are encoded the same as 7-bit ASCII with 0 as the most-significant bit. The other characters are encoded using multiple bytes, each byte with 1 as the most-significant bit. The bit pattern in the first byte of a multi-byte sequence tells us how many bytes are needed to represent the character. Here’s what the function looks like: f...