business

Guest Says He Hasn't Hand-Written Code in Two Months, Citing AI Security Finds Too Dangerous to Ship

Opinion

· business, news

On the Aug. 26, 2026 episode of the Lex Fridman Podcast (#501, "DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux"), a guest told host Lex Fridman that he has not manually written any of the code shipped in the latest version of his Linux distribution, called Quattro, over the past two months.

The guest said the shift followed work on a prior release, Omachi, over roughly three months, with what he termed "agent acceleration" — AI systems generating code with human oversight rather than hands-on authorship — nearing 100% almost immediately and holding there for the last two months. He said he reviewed the overall shape of the code and looked at individual lines only in the system's critical model layer, while UI and auxiliary code went largely unreviewed.

He linked that confidence to a separate episode involving a tool called Fable, which he said was withheld from release because of its capability. "This model was so capable of finding holes that an attacker could exploit that it was simply not safe to release," he said. He argued the underlying skill — chaining multiple minor vulnerabilities into a single exploit capable of remote command execution, or RCE, a term for an attacker running arbitrary commands on a target system — is rare even among humans, typically confined to state-sponsored or clandestine operators. "I have not written any of the code that shipped in Quattro by hand. I've reviewed the shape of all of it," he said.

He drew a distinction, however, between that Linux work and 37signals' commercial products, Basecamp and HEY. He said an early February push to let designers "vibe code" features for Basecamp 5 produced pull requests that individually seemed fine but collectively broke the system's architecture, requiring manual cleanup. He said tooling has since improved.

No performance benchmarks, vendor names for the AI models used, or third-party confirmation of Fable's capabilities were provided in the discussion. Readers should treat the security claims as one developer's account, not an independent audit.

Heard on Lex Fridman Podcast — #501 – DHH: Future of Programming, AI, Agentic Engineering, Vibe Coding & Linux (2026-08-26).

Disclosure. Legal entity: Pinewood Creations LLC. Smorgi Apps appears only as an affiliate partner in house slots — not as publisher or owner. See our affiliate disclosure.

Sources

More from Boardroom

Briefing

Top stories from the HTT News network by email. Free. No noise.

More from our network