Hacker Newsnew | past | comments | ask | show | jobs | submit | fourside's commentslogin

I recently bought a Bambu Lab A1 printer. I went specifically with Bambu Lab because everything I read said that was the better choice if you want something low maintenance and easy to set up even if it’s not as open as some of the alternatives.

It’s stuck in the auto calibration stage. It gets halfway through then it stops with a generic error message. The UI around this is really clunky. I’ve tried searching online, asking Claude and nothing. I emailed customer support and they came back with cryptic instructions that assume familiarity with the internals of the machine.

I decided to leave this for a day when I wasn’t too mentally drained from work to debug issues in my free time and instead the machine has been collecting dust ever since.

Maybe it was a mistake to get a Bambi Lab? I thought it was the more turn key option but it hasn’t been my experience.


Your experience is unusual for a Bambu. I know of numerous people who have purchased one and you are the only one who didn't have it "just work".

Mine just worked. Couldn't be happier with it.

> It’s stuck in the auto calibration stage. It gets halfway through then it stops with a generic error message.

So it was dead on arrival. You should have contacted support who would have figured out if you need the whole unit replaced or just part of it. If they are not responsive enough just send back the whole thing.

What would you do if you buy a laptop and it never passes the Power-On Self-Test? I would just return it to whoever i bought it from.

> I thought it was the more turn key option but it hasn’t been my experience.

I mean it is. For everyone who i know who owns one. Every company will sell an occasional dud.

Either it got damaged in transit, or the fault somehow escaped their QA, or you managed to screw up the assembly by not plugging in something, or leaving a transit fixture in somehow. Either way contacting support is the correct way to get to the bottom of it.

Come to think of it when i bought my Sherline lathe initially the motor didn’t turn on when i plugged it in. I wrote an email to the distributor who got me in contact with someone from Sherline. They asked me to check a thing which fixed the issue.


> So it was dead on arrival. You should have contacted support who would have figured out if you need the whole unit replaced or just part of it.

I mentioned that in my comment. I contacted CS. Multiple times in fact. They wanted to diagnose the issue remotely before issuing a refund. Their instructions were poorly written and assumed familiarity with the internals of the machine. ChatGPT helped some but not completely. Then life got busy, I had work travel and the 30 return window passed before I realized it.

Your response is, frankly, a little condescending. You seem convinced this is somehow my fault or that sat there twiddling my thumbs. Of course I understand that duds make it through manufacturing at times. It’s great that the happy path is easy. Do we judge the accessibility of a product only by how it behaves when everything goes right? I was careful during assembly and watched multiple YouTube videos and read the official instructions when putting it together, I contacted CS. In retrospect I should have pushed harder for a refund, but my original point still stands. As someone who wanted a “just works” solution, what I got instead was something faulty and then a really painful process for getting it solved.


I thought the parent comment was missing something obvious too but if you click the top link in that section, it’s a page describing LFS but without linking to its content. Then I clicked the “Read online” link on the menu on the left, but the top links are errata and security advisories and then the main link. Not the worst navigation I’ve seen but the parent comment does have a point.

How are you evaluating the Android build if you don’t use Android and you don’t know Kotlin?

We have people on the team that are android users. I just meant that I don't want to evaluate whether it feels "native" as I personally am not an Android user.

You just install it on your phone and use the app.

Maintainability concerns are entirely overblown by people who don't use agentic AI to develop large mobile apps, but anyway give their opinion as if they had that experience.

I put in a few hundred hours, and I reached the same conclusion as Shopify. With reviews from other models and then a manual QA pass the result is fully usable.


I work as a professional app developer. And I find this take to be naive.

Most of the time when I review code from AI, there is always something to improve.

It’s either a maintenance issue. e.g., Opus recommended and implemented a fix for a database corruption crash. This was ~400 lines of code with many moving parts. I reviewed, and found out Android Room library already handles this recovery case, and all I needed was a 10 liner PR that catches this exception and ignores it.

The maintenance is not only the burden on the human and LLM. With too many moving parts, it becomes harder and harder to build and verify the correctness of future features. Yes you can write test for this and that, but it didn’t need to exist in the first place.

The second problem is correctness issues. Especially the edge cases. You cannot just manually test out a race condition on a phone! Sometimes it happens! Sometimes it doesn’t! If it leads to a visible signal like a crash, then yes, you can try to reproduce it. But there are a lot of these that are “silent” and would just lead to bad experiences.

We already had a software quality crisis! And I think such views only exacerbate the situation! Quality matters!

And this is not an anti-AI stance. I vibe code personal projects where I don’t even look at the code. But when I use AI as a professional engineer, I act like a professional. Because these products do have an impact on people’s lives.


All true (and thanks for posting a concrete example rather than "LLMS suck"). But my take is that none of this is much different than before times when I had teams of developers creating applications. They would often make similar mistakes which I would either need to catch or which would flush out in the field. Where it seems that LLMs are not excellent is where the person driving it is also the senior domain expert so can immediately spot pitfalls. But typically using humans to develop software this was really not often the case. Those people get promoted so they're no longer cutting the code. Under that scenario (replacing subordinate humans) I find the current models are either on-par or somewhat better (specifically because the models can also act like a peer senior dev, discussing approach options etc).

I agree with you! And I’m not trying to romanticize the past! Humans/me wrote slop too.

I think we are over-indexing on speed of delivery. I think this is a mistake. The alpha is in speed and quality.

Currently, my experience is that human + AI can write software faster and with better quality than either party can do alone.


So you don't use agentic AI to develop a large mobile app and you think my take is naive?

I also used to work full time as a Android developer for five years, and I'm pretty sure I know better than you about the quality of my app that I work on everyday.


No where did I say we don’t do agentic dev!

Years of experience doesn’t mean much! I will challenge you on ideas. And the idea you are sharing is dangerous and unprofessional.

Especially at scale. e.g., we process more than 3.5 billion orders annually! This is serious business. Edge cases are common.


> It’s either a maintenance issue. e.g., Opus recommended and implemented a fix for a database corruption crash. This was ~400 lines of code with many moving parts. I reviewed, and found out Android Room library already handles this recovery case, and all I needed was a 10 liner PR that catches this exception and ignores it.

I understand this, but I just can't bring myself to care. I've been doing professional software work for almost two decades. These sorts of improvements/time savers are great without AI. With AI? Whatever. It's fine.

When the underlying lib has an issue, it'll be quicker to debug with the whole thing in context.


So exactly what value are you adding, then?

I take the specifications from the customer and type them into the AI

Well then I just have to ask why can't the customers type them directly into the AI?

One hopes you are better at that than the many others who are doing the same.

I have people skills; I am good at dealing with people.

Funny that none of the commenters got the reference/joke

You do realize that letting the LLM produce more output means that maintenance will be more expensive? I can easily see a world where claude and gpt are producing more tokens to sell you more tokens.

Just the other day I burned through my 5h quota twice in a row because I had opus spawn a review session on a medium sized PR and I don't know what happened but I told it to summarize to me and it said it spent 100M tokens throughout 50 subagent sessions.

And more recently its been recommending that i install this new browser called Aside. I did, and it almost felt like I was installing malware so I Uninstalled it fairly quickly (it also was not a great browser)

I feel like theres collusion somewhere.


yea man they are trying to nickle and dime you

Well yeah, that's the name of the game of most software companies. Anthropic has been fairly good up until the last week or so when it started needing more hand holding to not do things it didn't normally do.

This is not as obvious as many naively believe.

It depends on how hard to maintain the code added is, how likely it needs to change in the future, and most importantly on the cost.

If reviewing and manually improving the code takes hours, the cost may already be in the thousands.

That buys you a lot of AI usage, roughly a few months of continuous work.

You have to balance this with the chance that the suboptimal code the AI generated is actually fine and maintainable enough, and also the chance that during further work on that code a model might implement the same optimization on its own.


The models will only get better and inference cost will go down.

I don’t see any reason to think the same thing that happens with all tech won’t happen here.


That's just a straight shooter with upper management written all over him

Enshittification and profit maximalization is around the corner looking for you.

Same result here just using plain Opus 4.8+. I had a web ap with a PWA approach. Now I have an iOS app written in Swift/SwiftUI and an Android app in Kotlin in the appstores. I do not know how to code a single line of Swift or Kotlin. You just test the app and iterate with the AI over it until it is stable and does what it should.

> I do not know how to code a single line of Swift or Kotlin

sounds like your app is nothing serious


Why would you asume that, and how do you define serious? Ever since the iOS appstore presence I get more signups from organic app store searches + installs, which results to some percentage in new daily+monthly active users. Meaning: People use the native app and keep using it. That is how I would define have value, as it provides value to the users - else they wouldn't be using it.

My main agentic coding side project is something that I can't justify paying the apple developer license for. If I was an Android person or I didn't have to pay the developer license, maybe I'd just go for it.

Android got wirse than Apple. It costs 25 dollar now to get ID verified (mandatory) and before you can publish in the Ply store you need 12 betatester that install the app from a special link - those testers must keep the app installed 14days. Only then will you become visible publicly in the play store.

So you end up paying people on Fiverr to do it which costs more than 99€


> You just install it on your phone and use the app.

Some people on the cybersecurity side are starting to cry....


I have been getting these comments often here, including concerns about my non existent backend's security.

Last time, when I pointed out that the attack surface for mobile apps is typically very small, some users started to talk about zero day vulnerabilities in the OS's media handling, as if it was a concern for my app implementation.

I found the concerns again wildly overblown.


You sound like a person who's never had their app pen tested. The attack surface is anything but small if you're working with any kind of sensitive data.

But what if someone discovers a iOS 0day worth several million dollars and burns it to compromise your app specifically? /s

Are there cybersecurity concerns in the frontend? I would have thought you have to assume the client is untrusted and only do security work on the backend

1. Not storing secrets properly or using hardcoded secrets

2. Wild use of webviews/iframes sometimes easily propagates as XSS in phones

3. Incorrect client-side OAuth 2.0 configuration e.g. with schema-based redirect URLs.

4. Not supporting high-enough API versions, which may prevent some OS-related weaknesses

5. The list is actually very long. Just few top of my mind.


My favourite is a logout button with a logout API that fails. (Not a huge pratical concern, I admit, because it's a local attack.) Nobody ever notices because it still shows the logout screen, which hides the API error toast (if errors were even displayed). The still valid refresh token stays in sessionStorage (or even localStorage) while the app displays "logged out". (Bonus points if you cleared the access token in the error handler but not the refresh token, and on page reload you ask the user to log in again despite having a valid token.)

Or a login form that gets hidden after login, but clears the username and password only when you click "login back in". (Bonus points if the backend also enforces a 5min session timeout "for security".)


Storing private secrets in your public client is easy to avoid for anyone halfway competent. We are all professionals here.

Turn on the secrets scan in GitLab, and put in your release checklist to have the AI audit the usage of secrets in your app, and this is basically guaranteed not to occur.

I doubt current models even make such a mistake in the first place, and particularly so if you use reviews at all.

WebViews are not an inherent problem, it's the system browser embedded in your app.

Where it gets tricky is if your use case involves authentication in the browser. Together with the authentication in your app this is the one area where you need to focus on security.

The case where a SDK update is needed to prevent weaknesses of the OS seems rather unlikely.


Doing anything right on web is 10x harder and more complex. The problem is the browser, once you use it to deliver anything you have to buy into all of it’s bullshit. CORS, XSS, headers, caching. All that just goes away (outside your backend API, if you even need one) when you ship a native app

Fantastic answer thank you

Nailed it. Assume your client is compromised and/or malicious regardless of how it was built.

This is the most naive take on security ever. For the backend, you assume your client is compromised, but you still don't want to allow your client to be compromised.

If your clients are compromised then what's even the point of backend security. Users will login and do legitimate actions while their compromised client does whatever behind their back, while still looking normal. And the backend can't tell the difference.

They better start a proper hydration regime because they'll be crying a lot.

Why? The api has to be secure. Mobile os keeps the app safe. Where is the attack surface?

You don’t believe how often people leave secrets in the app or use webviews and iframes badly, misconfigure OAuth in client side and so on. There are many issues where secure API does not help.

Ok, yeah, I forgot that people do ship api keys inside binaries

I am using Gemini as well as Opus on a somewhat small project in React Native and I can not imagine this thing being able to build the whole thing on its own without it being a dumbpster fire.

Can you share some details of how you work? What models? What harness?


I use Codex and Claude Code desktop apps. I generally use only the SOTA, now Astra and Fable 5.1, Opus 5 when Fable runs out.

I don't know if Gemini is suitable.

I had few issues with my native iOS app, the results are just decent after a few iterations, the models do what I ask them to do. Where do you see the problem?

The LOC for my app is now at almost 200k + 110k lines of test code.


[flagged]


can't believe what has become of this profession

what in the gobbledygook is this

We use CC with Fable(Opus before that) continuously on a rather large project, everything is tested, we maintain high verified test coverage, we ship features x10 faster than when we started(pre Claude-everything era 2-3 years ago). I never worked with RN before and I ship features now. LLMs allowed us to find issues within RN itself, that thanks to some patches, improved lower end Android experience by a lot. We just use all the Claude defaults with claude.md that evolved over last year.

> Opus

> Are there cybersecurity concerns in the frontend? I would have thought you have to assume the client is untrusted and only do security work on the backend.

I hate software engineering now.


> You just install it on your phone and use the app.

OP says they don't have an android phone...


No, they said they don't use android so don't know the native UX. You can test your app on the platform and confirm that the functionality all works, but how well it adheres to the platform's design language is subjective and hard to say if you aren't used to the platform.

Android studio has a emulator

I used the emulator - but just like I can use an iOS app for 30 seconds and tell you whether it feels native or not, I can't do the same for Android, since I'm not a daily user of Android phones.

And in the past, I didn't care because when I was manually building the app, I would just do my best with react native. But now that I can actually sweat the details (with the help of agents), I do want to hear from android users and use as many OS-native APIs and features.


I missed that.

I'd order a cheap Android phone to have a device in hand instead of working only with the simulator.


Others on our team use Android phones. So when I said that we spent the next few days actually polishing it, that's where others came in, providing feedback when they used it.

I could only sweat the details on liquid glass, etc because I'm a daily iOS user.


That's a recipe for regressions as the amount of surface you have to cover with "just...use the app" gets bigger and bigger.

You can write more automation to test it. But that's also how you end up with ever-growing test run times.

There are much better ways that aren't just "throw out the LLM" either. You just need to be more focused on throughput. Requiring manual validation can pretty rapidly require more hours than just sanity-checking code by hand, even (and I'm not advocating that for every use case, either.)

I can't afford manual QA passes if I'm gonna go as quickly as I want to.


> You just install it on your phone and use the app.

That‘s how you check functionality but that’s not how you get the bugs in the code.


That's the part covered by the other model's review. That together with manually verifying the functionality results in output that works.

If you don’t know the language you can’t evaluate if the models really found bugs.

That’s like translating a text to another language without knowing the language


This is wildly overblown. I've been working with agents for a good while, read tens of thousands of generated Python and the language factor is actually the part they get right that humans don't.

Do you know Python?

What do you think has more training data Python or Kotlin?


20+ years of using Python. I don't really think that lack of training data for Kotlin is a problem.

Damn, we really gotta get rid of the vibe coders. Bad things are on the horizon if we keep encouraging these naive habits.

How do you propose getting "rid" of "Vibe coders" (which I'm assuming you're pooling me into?)

Severe financial liability for security breaches, severe enough that, for instance, companies which leak 1m+ user data are driven to bankruptcy

[yes, this would also get rid of the previous generation of 1000-JS-lego vibers]


Yes, what type of "engineering" is this? "I click the button and I see if it works or not" holy shit.

Remember the first step to fixing any problem is admitting you have a problem.

If you are blind, you cant see anything wrong, if you are deaf uou cant hear anything is wrong.


Seriously! What a bonkers thing to claim. "I had codex use maestro so I assume it made Android work well and idiomatically".

It's a fine project to do but clearly they put zero value on being familiar with the project's codebase/stack and ecosystem, which makes me feel fear in my heart when I imagine the first "production is down" page coming in. I already hated mobile because it's so much harder to maintain than web (and I don't do any spyware or IAP so no benefits for me there); this yolo approach would give me constant dread.

It shows that at least some software development is moving away from code and to product management instead. I'm not passing judgement on that; I actually think that's great for a lot of software. It is interesting to see the shift happening though and will be fun to see if the general quality of software noticeably changes over the next few years.


> It's a fine project to do but clearly they put zero value on being familiar with the project's codebase/stack and ecosystem,

As much as I dislike it, I think that's the future of _all_ non-critical software (think social media, crms, CI, food delivery etc). Leadership in many companies is explicitly asking employees to have multiple agents running through the day and that will lead to this.

Read this for example: https://www.uber.com/in/en/blog/efficient-software-factory/ . A very useful system, I am sure. But when you have AI at every layer from code to review to triaging, rest assured AI is the only know who knows your system. And you better hope it's not telling you that something is load bearing during an incident.


I read the article and couldn't understand it. I asked Gemini; Pareto things definitely sounds like science.

I read the article again:

- We had bugs. We let agents try to fix the bugs. True positive (fixed bug) is the F1 score. Here are the results for different models. Fixes worked 50% of the time.

- We needed to find a query. Without a knowledge graph it took 20mins, and didn't work. We used a knowledge graph. It was fast (20s), and found the right thing.

I gave my LLM my summary of the article and apparently I "hit the nail on the head".

I have no clue if I learned anything.


I answered elsewhere that I don’t personally use Android phones but we have people on our team that do. Which is why I don’t want to personally claim that it feels native.

But yes we are having real Android users test it.

So it’s quite the contrary. I care MORE what real users say. I can only guarantee that the app does things when I tap. So I’m not trusting the agent on UX, only on functionality. But whether it feels native, I am relying on those users in our team.


That's much better than my original, perhaps unfair, read. Thanks for the additional info.

I still would feel scared operating an established product off a newly changed stack the team isn't familiar with though.


Yeah that's totally fair. So am I, which is why I'm making sure we're still manually testing the hell out of it before we release it.

But our product now has a way more extensive test suite than it ever did, again, thanks to the agents writing pretty damn good tests.


> this yolo approach would give me constant dread.

When you’re completely ignorant, there’s nothing to be afraid of.


I wrote every single line of the react native app we ported, and maintained it for 9 years. So suffice to say, I'm familiar with the code.

But I am going to always prioritize the user experience over a developer (like myself)'s need for satisfaction to see code. And a pure native app is _always_ going to behave better than react native.

This gives me a chance to do that.


> And a pure native app is _always_ going to behave better than react native.

Maybe iOS is better about consistency, but I've used enough horribly made Android apps that I would not expect one that's vibe coded to behave better than a professionally made react native version.


I would if it were based on the RN version. RN is kind of okay on iOS, but really shitty on Android. Would be difficult to be _worse_.

That said, I do recommend reading the code the LLM produces whether you understand the language or not. What better time to learn?


Maybe. Android might still be a mess, fair point.

>So suffice to say, I'm familiar with the code.

You are familiar with the React Native code, you are not familiar with the Swift or Kotlin code, and likely nobody on your team is, since the AI wrote all of it for you.


First “production is down” page means you just tell codex production is down and to fix it.

Presumably a sarcastic post, but this is actually going to be how things are done soon. I had a box that OOMed and needed to be rebooted every few weeks. It was a disaster recovery standby box so figuring out what was going on never rose to the top of my priority list. So I asked Claude to dig into it (proxying the commands it wanted to run through me) and in an hour it had diagnosed the problem, fixed it, and taught me a bunch about memory usage in our system on modern kernels.

Not sarcastic. I have a moderately successful app and I haven’t once looked at the code (though I am capable, so far atleast). The only time I open Xcode is if I have to modify signing certificates. I did set up a slack workflow with a “fix it” button that basically tells Codex to fix the issue, run comprehensive tests, manually UI test for that particular issue with computer use and then deploy it.

Equal parts very cool and very scary to me

It is. For my day job, I’m a software engineering director and I probably won’t have a job in under five years. For low to medium complexity apps, even Codex before Astra was capable of doing it completely by itself from scratch. For testing I would bring up the app after each atomic change and then manually try it out. I also use my own app heavily multiple times a day and I have found dozens of issues but I just ask Codex to fix it on the spot.

ITT: people dealing with realities.

Remember Chinese accounts on US Facebook say data centers are bad.


Yeah and it’s buggy on mobile

Spent lots of time on this last night, should be much better experience now

Sorry about that, the focus was desktop for now. It's definitely on my todo list.

Yeah I truly do not understand some people’s logic. Like the ones talking about some post scarcity world where universal income will offset AI related job loss. So the people in power, the ones who have constantly tried to cut back government spending, are now going to flip and support universal income? Right.


Well same people had expected self-service restaurants, self-pay terminals will cause no tip. And even more fun future robotic servers can just work without expecting/asking for tips.

Or maybe I am wrong and "This time its really different".


I don’t think the parent comment was trying to equate the two, but rather pushing the argument to its logical extreme to test show that the reasoning doesn’t hold consistently across cases. Whether they made a convincing argument is separate.


I literally was trying to equate the two.


Taking it to a logical extreme is good practice for thinking from first principles, but always pair it up with going to the logical extreme in the other direction. That might look something like: "would you really eat at a restaurant owned by a habitual jaywalker?".


Except pushing it to the logical extreme is what makes it wrong.

Nevermind that he literally was equating the two and explicitly says so.


> HN is showing (expected) dismissing attitude towards this idea. That tells me it might work :) !

I recently learned the name of this logical fallacy: Galileo gambit. It’s one of my pet peeves. Yes, we all know Dropbox was infamously dismissed by the top comment on HN. No, just because someone criticizes your project on here doesn’t mean it’ll be a big success.

Instead of fixing the education system and giving it the resources it deserves (eg paying teachers more like the other reply said) we’re going to “fix it” by ossifying a two tiered system where wealthy kids get individualized attention from well trained adults while poor kids are taught by AI.


I hear you, and I know every project being dissed here is not going to be Dropbox. Perhaps some projects deserve the reality check they get. Though I still believe that HN crowd telling that just pay teachers more or kids need to be taught by good human teachers are underestimating the scale of the problem.

Some real experience of school in my part of the world (India). My child goes to a somewhat costly private school. Still, each class has 35-40 kids. The teacher is over-worked : checking home work, prepares kids for upcoming random extra curricular activity, has to teach AI because someone suddenly thought it is important to teach it in grade 3. I know multiple teachers in that school who landed the job after doing just a 6 months course after a career break. Forget research on teaching, hardly any one of them read anything beyond curriculum. None of the teachers have enough time to give personalised attention to _any_ kid. Its a sorry state of affairs.

Personalised tutoring produced geniuses in last century but was affordable only for a wealthy few. It is my belief that AI might help democratise the idea. I know it is somewhat hard to think that a mere machine might have more patience and time to explain a concept 100 times to a student, instead of a human.

This still doesn't take away from the fact that teachers deserve to be paid more. I was a passionate for becoming a teacher, but knew I can't make enough money from it. I'm seeing a possibility in emerging markets that India / China might find it cheaper to deploy AI en masse for better educational outcomes because it will be much cheaper for the state than paying high wages (and subsequently pensions) to human teachers, however unfair it might look.


The Galileo gambit is the idea that because experts reject an idea, it must be true. HN is the furthest thing from experts when it comes to early childhood education.


Or Clarke's first law

-- When a distinguished but elderly scientist states that something is possible, he is almost certainly right. When he states that something is impossible, he is very probably wrong.

https://en.wikipedia.org/wiki/Clarke%27s_three_laws


I’m on the same boat. I get why people do it. Writing prose is significantly slower than consuming it, but there’s still a part of me that thinks “if you didn’t think writing was a good use of your time, why would reading this content be a use of mine”. I don’t mind AI-assisted writing but it’s hard to know to how much human editing was involved when the text shows so many AI tells. Almost by definition, AI writing is average it’s hard to justify spending the time when there’s so much content out there.


“You didn’t write it, why should I read it?”

Seems like a perfectly reasonable stance.


So tired of this false equivalence between left and right politics in the US. So because major LLMs support a increase in the minimum wage we need to offset it with an LLM that has spouted Nazi propaganda and lets you generate porn image of real people?


We have three major foundational models not including Grok.

When the defense for a company is basically “yeah they host csam in the platform but is that really worse than the others” you’ve really lost the plot


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: