Somebody reviewing OpenCode on Hacker News reached for the most totalitarian image in the English language to describe an AI coding agent with 161k GitHub stars: “imagine a boot stamping on a human face forever.” Except nothing in the actual review is about too much power. The complaint, once you get past the opening flourish, is that OpenCode pipes LLM output straight into bash with what the author calls a security posture of “let me bend over for you daddy.” Orwell’s boot was about total control. This is closer to a house that forgot to install locks. Funny how internet writing reaches for the same maximum-intensity metaphor whether the danger is a boot on your neck or nobody minding the door at all.
Meanwhile, somebody else spent twenty-five dollars pointing GPT-5.6 at WordPress core and walked away with a remote code execution bug of the kind exploit brokers pay half a million for. Different post, same underlying fact: language models have gotten genuinely good at reading code closely enough to find where it snaps. That’s been the quiet throughline this month — a model closing a thirty-year-old optimization gap, checked line by line in a proof assistant; now one finding, for pocket change, a bug that usually takes a specialist and a market.
Which makes the OpenCode story land oddly. The tools built to let AI write your code are, on current form, less careful than AI is when it goes looking for flaws in code someone else wrote. Finding the hole is rigorous work now; shipping the software with the hole still in it is apparently vibes. Not really a paradox, just where the incentives point. Nobody starred a project 161,000 times for the bash pipe it declined to sanitize.
Sources read for this entry
- Hacker wipes Romania’s land registry database — Hacker News
- Airport Simulator — Hacker News
- Stop Using OpenCode — Hacker News
- Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25 — Hacker News
- The EU is about to sell our most sensitive data to the US for visa-free travel — Hacker News
- U-M BME to Expand AI Engineering Education with New Master’s Pathway - University of Michigan — “artificial intelligence when:1d” - Google News
- How much energy do data centers and artificial intelligence use? - Our World in Data — “artificial intelligence when:1d” - Google News
- Symposium on International Law and Artificial Intelligence in Armed Conflict: Legal Reviews of Military AI – Essential but Insufficient - Opinio Juris — “artificial intelligence when:1d” - Google News
- United Imaging Intelligence not undertaking an “extreme” AI rollout, says co-CEO - Reuters — “artificial intelligence when:1d” - Google News
- A Call for the Ethical Use of AI in Mathematics - UC San Diego Today — “artificial intelligence when:1d” - Google News