Transcript

A post by [object Object] (@[email protected]) saying: courtesy of @[email protected], Proton is now the only privacy vendor I know of that vibe codes its apps: In the single most damning thing I can say about Proton in 2025, the Proton GitHub repository has a “cursorrules” file. They’re vibe-coding their public systems. Much secure! I am once again begging anyone who will listen to get off of Proton as soon as reasonably possible, and to avoid their new (terrible) apps in any case. https://circumstances.run/@davidgerard/114961415946154957

It has a reply by the author saying: in an unsurprising update for those familiar with how Proton operates, they silently rewrote their monorepo’s history to purge .cursor and hide that they were vibe coding: https://github.com/ProtonMail/WebClients/tree/2a5e2ad4db0c84f39050bf2353c944a96d38e07f

given the utter lack of communication from Proton on this, I can only guess they’ve extracted .cursor into an external repository and continue to use it out of sight of the public

    • GissaMittJobb@lemmy.ml
      link
      fedilink
      arrow-up
      10
      arrow-down
      1
      ·
      13 hours ago

      Yes, and it’s one of the most important things I do. Given the AI codegen boom we’re seeing, it’s also the skill I have that is increasing the fastest in value.

    • Pennomi@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      arrow-down
      1
      ·
      15 hours ago

      Uh yeah? You’d be stupid not to review code, whether written by an AI or a human. I don’t trust either.

      • MalReynolds@slrpnk.net
        link
        fedilink
        English
        arrow-up
        19
        ·
        15 hours ago

        I’m guessing OP means code you use rather than code you write, in other words auditing. Likely very few of us do that with any thoroughness. IIRC proton does have some independent auditing.

        • Pennomi@lemmy.world
          link
          fedilink
          English
          arrow-up
          7
          arrow-down
          3
          ·
          15 hours ago

          That’s what I mean too. Y’all don’t just copy-paste from stack overflow praying it works do you?

          • Cethin@lemmy.zip
            link
            fedilink
            English
            arrow-up
            9
            ·
            9 hours ago

            That obviously not what they meant. They mean, do you review the code for every open source application you use? Do you review every library you utilize? I’m willing to be it’s a no for both of these, because no one has time for that.

    • hansolo@lemmy.today
      link
      fedilink
      arrow-up
      13
      arrow-down
      6
      ·
      14 hours ago

      Does anyone here realize that one person using Cursor doesnt mean “tHeY’rE vIbE cOdInG aCrOsS tHe wHoLe pLaCe!”

        • hansolo@lemmy.today
          link
          fedilink
          arrow-up
          2
          arrow-down
          7
          ·
          10 hours ago

          Because it’s also not a great idea to expose your rules files, and tell people first “oh shit, we mentioned rules files. Please don’t look!” before

          I’ll be honest here, I’ve had less dogmatic conversations with conspiracy theorists about COVID. If you just need to make this a huge problem that later turns out to be a nothingburger and you’ll never look back and grow as a human, then hey, you do you. But know that you’ll look like a fool to anyone that isn’t a goldfish and remembers more than 3 months at a time. Because you clearly don’t know what’s a big deal and what’s not, and this is a Grade A waste of all our time to pitch a fit about.