An AI Vibe Coding Horror Story | 海外技术热榜
原文链接
🔗 An AI Vibe Coding Horror Story
翻译说明
本文翻译自Hacker News最新热门技术文章,内容仅供学习参考,版权归原作者所有。
完整翻译内容
[Tobias Brunner aka tobru] [Tobias Brunner aka tobru]
Menu toggle button
- Home ✩
- Tech [EN]
- Reisen [DE]
- About
- More
- Newsletter
- About the Newsletter
- tobru
- Sign in
- Sign Up
An AI Vibe Coding Horror Story
[Tobias Brunner] Tobias Brunner
Mar 28, 2026 2 min read
[An AI Vibe Coding Horror Story]
And so it happened, my first real-world AI vibe coding horror story, one that affected me personally. --> Deutsche version
I went to a medical appointment and was greeted by a friendly person. Shortly after the warm welcome, they mentioned watching a video explaining how easy it is for anyone to build software with AI these days. That sparked an idea: why use an industry-proven solution when you could just build your own patient management system?
So they did exactly that. They fired up a coding agent, built a custom patient management application, imported all their existing patient data into it, and published it to the internet. They even added a feature to record conversations during appointments and send the audio to not one, but two AI services for automatic summaries. No more manual note-taking.
Everything that could go wrong, did go wrong.
A few days later, I started poking around the application. Thirty minutes in, I had full read and write access to all patient data. Everything was unencrypted and completely exposed to the open internet. My first move was to notify the person immediately. The response I got was 100% AI-generated, thanking me warmly for reporting it and assuring me they had taken immediate action by adding basic authentication and rotating some access keys.
This person had no idea what they had built, or what the consequences could be. The data wasn't just wide open: it was stored on a US server without a Data Processing Agreement, voice recordings were being sent to major US-based AI companies, and I had never been informed any of this was happening. That is not how medical patient data can be h | 翻译自海外技术热榜andled. They almost certainly violated multiple provisions of the nDSG law and potentially professional secrecy laws (Berufsgeheimnis) as well, though I'm not a lawyer.
Technical Background
The entire application was a single HTML file with all JavaScript, CSS, and structure written inline. The backend was a managed database service with zero access control configured, no row-level security, nothing. All "access control" logic lived in the JavaScript on the client side, meaning the data was literally one curl command away from anyone who looked.
All audio recordings were sent directly to external AI APIs for transcription and summarization.
There was more, but this is already enough to get the idea.
Outlook
That's not the AI future I'm looking forward to. Personally, I'm using AI coding agents as well, but I'm able to understand what's happening, can read the code and have an idea of software architecture. Anyone just vibing away clearly won't give us a happy future.
Tech AI
Share this article:
The link has been Copied to clipboard!
[Tobias Brunner]
Tobias Brunner
[Eine KI Vibe Coding Horrorgeschichte]
Older article
Eine KI Vibe Coding Horrorgeschichte
Mar 28, 2026 2 min read
You might also like
[Eine KI Vibe Coding Horrorgeschichte]
Eine KI Vibe Coding Horrorgeschichte
Mar 28, 2026 2 min read
[Migrating from Gitea to Forgejo]
Migrating from Gitea to Forgejo
Feb 09, 2024 3 min read
[Authoritative DNS with deSEC and DNSControl]
Authoritative DNS with deSEC and DNSControl
Jan 21, 2024 4 min read
[Gitea Actions Container Builds]
Gitea Actions Container Builds
Nov 22, 2023 3 min read
Subscribe to newsletter
Stay up to date! Get all the latest posts delivered straight to your inbox.
Name Email
Subscribe
Great! Check your inbox and click the link to confirm your subscription.
Error! Please enter a valid email address!
[Tobias Brunner aka tobru] [Tobias Brunner aka tobru]
Tobias Brunner aka tobru
Main Categories
- Tech [EN]
- Reise | 翻译自海外技术热榜n [DE]
Newsletter
- About
- Archive
- Sign Up
- Sign In
About
- tobru
- Your Webanalytics
Follow:
© 2026 Tobias Brunner aka tobru - All right Reserved. Published with Ghost
Press ESC to close.
See posts by Popular tags
Tech Newsletter Reisen Reise2014 Australien Network Tipp Kolab Jekyll OpenShift
You've successfully subscribed to Tobias Brunner aka tobru
Great! Next, complete checkout to get full access to all premium content.
Error! Could not sign up. invalid link.
Welcome back! You've successfully signed in.
Error! Could not sign in. Please try again.
Success! Your account is fully activated, you now have access to all content.
Error! Stripe checkout failed.
Success! Your billing info is updated.
Error! Billing info update failed. | 翻译自海外技术热榜
翻译声明:本文由AI自动翻译,如有不准确之处欢迎指正
🙏 如果本文对你有帮助,欢迎打赏支持,你的鼓励是我持续输出优质内容的最大动力! 💴 打赏通道:点击文章末尾「赞赏」按钮即可,每一分支持都是我前进的动力~