André Staltz
@andrestaltz
Followers
25K
Following
16K
Media
849
Statuses
13K
JavaScript and open source guy. Working at @SocketSecurity Previously @manyver_se, SSB, @cyclejs, RxJS
Helsinki, Finland
Joined January 2012
AI is only a threat for people whose job is to solely produce low quality content. For those who produce high quality content, AI is not a threat, it's a tool. It will increase productivity on impressive (but not game changing) scales.
1
1
8
By "content" here I mean anything that AI can currently produce: images, text, audio, code, video, etc. There is demand for low quality AND high quality content, the world is not heterogeneous.
1
1
4
Our AI future means two things IMHO: 1. A proliferation of quick but low quality content, for creators who don't care about quality 2. A marginal increase in productivity (I bet 2x–8x) for creators who still care about high quality, and iterate a lot with AI
1
2
8
I'm basically tired of AI. Not excited, not scared, not impressed. Just tired of it all. It's not like terribly bad, but it's also not very good. The slot machine nonsense sometimes impresses, but generally speaking it just tires me.
3
3
32
@SocketSecurity Would highly appreciate if you can link to some visible work that is nearly all yours, and you're proud of building.
0
0
2
Want to work with me and a number of world-class JS open source developers at @SocketSecurity protecting ALL open source libraries from supply chain attacks? We're looking for stellar frontend developers. DM me
5
2
8
🚀 We’re kicking off another Launch Week at Socket, with a new feature launching every day! First up: Pull Request Stories, a dashboard view that helps security teams track supply chain risks by showing the real impact of every PR.
1
4
9
There is one thing in React which has been conceptually broken since always: conflating state and events in controlled components. You can't discretely "set" the value of a controlled component without setting its state. This comes up as bugs very often with text inputs.
BY FAR the biggest reason I'm souring on React is the discrepancy of what's happening in the DOM and how I express my code I just want to do something on mount, just want to create an instance once and never again, or 100 other things React has built it's own language so you
1
2
10
Raise your hand if you were right about NFTs and metaverses being fads.
3
7
37
Artificial Garbage Intelligence
We ran a randomized controlled trial to see how much AI coding tools speed up experienced open-source developers. The results surprised us: Developers thought they were 20% faster with AI tools, but they were actually 19% slower when they had access to AI than when they didn't.
1
3
17
🚀 The Socket dashboard just got a major refresh! We've streamlined navigation, reduced visual clutter, and put your most critical security insights front and center. ✨ Check out what we've been building, now live for all users! https://t.co/1Z9vg5hTiQ
0
1
1
AGI Artificial Garbage Intelligence. Just absolutely useless walls of text that are simultaneously presumptuously confident and quick to admit its mistakes, over and over as you prompt for more garbage.
3
2
28
It can't use a calculator, and folks trust it to write code.
Ever since Anthropic came out with "computer use" in October 2024, I have been trying to make it use the calculator to perform some simple calculations, like "1+2". Alas, I never got it to work reliably. Now OpenAI also has come out with computer use, so I tried again. Same
2
3
15
Was really sad to hear about @mikeal’s passing yesterday. Mikeal was one of a kind person, and instrumental in my own open source journey. A friend sent me this great pic from an old conference with the decentralisation JS gang
2
6
46
Yup yup yup. It's not gonna magically become sentient. It may help you write your text in a different way, provide some divergent thinking, or introduce you to some new topic you know little about. Help you get some things done quicker. It. Won't. Grow. Sentient.
when you don't count on it becoming magically sentient, you start to think in terms of what the tool is, how it works, and what you can begin to do to keep it on the rails or leverage its strengths
0
2
11
We just bought a company. Why? Because vulnerability scanning is fundamentally broken. And I’m tired of pretending it’s fine. We acquired Coana, the best reachability analysis engine on the planet. The whole vuln industry is addicted to quantity over quality. More alerts, more
62
67
525
🚀 Big news! Socket is acquiring Coana, bringing best-in-class reachability analysis to modern SCA! Coana's technology reduces false positives by up to 80%, letting teams focus on vulnerabilities that actually matter. #AppSec 1/4
6
7
19