Are hordes of developers now going to port all sorts of open-source software to Rust using LLMs and passing it off as their own work?
I don't see any need for this. Rust is brilliant but the Quake C++ code was already more or less bug-free.
Are hordes of developers now going to port all sorts of open-source software to Rust using LLMs and passing it off as their own work?
I don't see any need for this. Rust is brilliant but the Quake C++ code was already more or less bug-free.
Nitpick: Quake was written C, not C++. The first id game written in C++ was Doom 3 around 2004.
Quake is to some extend a reference implementation of a modern FPS-type game. Because it is open source and because it is well written.
Now I'm no hero in C (doing slightly better in C++). But I have quite some experience with Rust. I rather read Quake in Rust than in C. So I'm happy with the port.
Also, you talk down on the effort but porting over a codebase this size is no small feat even with the help of LLMs. I think the "author" (human creator) learned a thing or two along the way.
Well look at Adobe, this just happened to the entire CSS suite. Not open source but proprietary.
Have you tried using the clones (in an airgapped VM, please)?
Because I did and it's the playable allegory of the cave but in vibecoded rust.
I mean...have you? Presumably from copies you built yourself. As someone who long carried a Creative Cloud subscription, I am astonished at how much functionality is there already.
The Photoshop clone absolutely fulfills my needs immediately: Basic cropping, adjustments, tone mapping, occasional blur/filter type functionality, etc. Well I did "vibe code" in HEIC and JXL import and export functionality (shelling out to the platform heic and jxl libraries in sandboxes for both open and export), but holy shit, it is quite simply amazing, and it gives me a consistent interface I'm accustomed to. And it built and runs superbly on Linux too!
It absolutely isn't 100%, or even 50% in many cases, with some apps more than others. Like the Acrobat clone is fantastic for the basics like moving pages around, filling out forms, etc, but real editing is a mess. I needed the ability to change z-order and move elements so I had Claude add that in moments.
I mean, I get that people like being world weary and cynical, but these "vibe coded" projects are astonishing, and they are a bellwether that absolutely nothing is as it was.
I have no doubt these tools are useless for hardcore Illustrator users, or so on, but countless CC subscribers only touch the surface of features, and in days this already satisfies that.
> (in an airgapped VM, please)
Why the fear-mongering, out of curiosity? It's a give-us-attention from a real business (ArtCraft) with a long running product, not some weird hacker group releasing binaries on a torrent. Cloning and building the product is trivial. Lots and lots of eyes are looking at this project right now, and thus far I've heard not an iota of concern.
FWIW, I did my own once-over of the project, and then had Fable and Opus 5.5 do an end to end, and there is nothing concerning about it that I've seen
> Why the fear-mongering, out of curiousity?
I agree wholeheartedly. People download commercial software as if it doesn't have a history of deliberate backdoors and spyware (in the news now: A coffee pot that's basically trying to hack its customer's LANs, to spy on them. And recently a TV that spied on your media and possibly even your living room as a whole), but fearing a vibe coded Photoshop?
Sure, if it were a vibe coded webserver taking connections on the Internet, but it's not.
I have. The "Lightroom" is already better than Darktable, after what, 11 days?
Edit: Ok, so instead of downvoting me, could people reply with how you disagree? I am expecting downvotes for trolling and unhelpfulness, but not for "I don't like that what you said is your true experience".
I have literally tried to migrate to Darktable, and it's just not up to snuff. But I tried rawmakase (which is on like day 11) and it literally is.
Mate its been a couple of days, I would think you'd be mad to expect perfection from an LLM reverse engineering job straight away.
As a proof of concept however it shows that we are at the stage where any malicious actor has a very low barrier to entry to cause large scale corporate espionage etc.
Past performance is not indicative of future results.
It's easy to create a set that looks as if it was a real city. It's infinitely more hard to create that real city.
But you're absolutely right that a set is all it needs for all sorts of (cyber) attacks.
Do you mean that bad actors can reverse engineer photoshop and hack its users or that bad actors can whip out plausible photoshop clone with vulnerabilities and backdoors and hack users with that?
I mean that proprietary software can be reverse engineered, there are many ways that this can affect vendors and end users. Both your examples could be some attack vectors.
Think more broadly than Adobe and any company that relies on a software product could have their business model destroyed overnight. More broadly than that, you could rupture trust between suppliers and vendors if they don't know who's really making requests from a proprietary platform that's been compromised unknowingly.
But thats just good old hacking, you can already see where software connects and try to see if you can get in.
I'm much more worried about AI made software that is developed so quickly that nobody knows what it does, pdfcraft was published a week ago and it has had 5 releases since then.
Oh I obviously know that this kind of thing is already achievable, but it's the barrier to entry is getting substantially lower... Instead of needing a nation state actor that's got funding and resources behind them, we're getting close to the point that some degenerate kid in their bedroom could say "hey claude find me the api keys and services behind nasdaq and build me an interface that spoofs transactions to XYZ". Or send commands to traffic light controllers. Or every third transaction from XYZ bank on every second day has one cent transferred to this other account.
Not just api calls but the business logic too.
Laymens thoughts there, but in essence this is my concern. People just looking at any old service in the world and going "hey claude build me a hook into this" and the models are getting close enough to being able to find and decompile the right moving parts on its own.
It isn't quite accurate to say that it was reverse engineered, though that claim is appearing across a lot of social media (including people claiming it disassembled it, etc).
It is a clone, where an LLM built facsimiles of interfaces and functions to the greatest degree possible. Which is a very different process.
How are people even doing this with frontier models without it immediately saying it can't do that.
From what I understand, the adobe guys software is not great.
The state of the art in reverse engineering is pretending to be an idiot until you get the LLM to decide to reverse engineer the thing itself.
"hey i want to make an image editor, can you look into how photoshop does field blur"
"oh nice job implementing it, but the output is not pixel for pixel the same, can you check how photoshop does it - i have it installed right here"
"oh it still has some bugs - can you look into the precise algorithm they use, is there perhaps any software i can install to help you with that"
"oh i see the NSA has a thing called ghidra, would that be useful?"
Really? Weaponized incompetence even works on the clanker?
I gotta try that
They're RL'd to oblivion into "solving tasks". There's a lot of things that they'll refuse to do if you tell them, but will do if they decide it's the shortest path to "solving the task".
I hope the future is brighter because the present is bleak.
Good news if you like paperclips.
The Adobe one doesn’t seem to be a decomp. It’s just someone asking the ai to build the same tool from scratch in rust.
Consequently it’s missing tons of features.
Models got better at doing things the users are entirely within their moral and legal rights to do, without punting or forcing to argue the point.
In my little game restoration project, Claude just holds me to the commonly accepted standards and makes sure none of the original assets ever make it to the git repo its working in. I only once had to assert that occasional game screenshot to illustrate some doc is acceptable - again, it didn't argue the point, just said something about abundance of caution.
No trickery needed.
The "clean room" approach here is using public documentation to assemble a roadmap/guidance and computer use to get any other behavioral output and visuals from the software you wanna clone. The agent doing that will just do something which looks completely innocent to it (e.g. create a rectangle on the canvas and then rotate it).
The other agent then implements the documented journey.
>How are people even doing this with frontier models without it immediately saying it can't do that.
Tons of tricks, but really, you don't need frontier models. We're way beyond that stage.
I mean...why not do it? Are you implying it would only have value if someone painstakingly did it by hand?
The endavour doesn't have much value at all except as an experiment how well translating C code to Rust via LLM works (but you don't need an LLM for that either, C2Rust was already a thing).
Also, the C version of Quake compiled to WebAssembly and running in browsers is just as "safe".
But C isn't as nice to work with. Maybe OP just thought it was fun to see it take shape and wanted to share it. Why do any sort of little side project like this at all? Just seems like everyone is judging this too harshly. If an LLM is reasonably good at this sort of thing, and you think it would be cool to see Quake written in Rust running in the browser, I say just do it and have fun and don't be shy about doing show and tell about it.
> But C isn't as nice to work with.
Only in your opinion :)
What about what about people learn and possibly the fun they get during the process?
Sure this project won't save humanity or optimize some KPI pleasing some obscure hierarchy.
Let people have fun, as long as they don't hurt anyone personally I'm fine with it and even I'm happy learning someone had some cool moments.
All commits in the project are from Claude. What's fun or to be learned from that?
It's of course everybody's personal choice, and it's nice for an experiment to figure out what Claude can do. But why go on HN and brag about a project entirely created by Claude when literally everybody else can do the same thing without lifting a finger?
Somebody had to do it and they did it.
I see the result of an LLM port only as a baseline. I would expect any serious developer to rewrite and refactor the code beyond a verbatim translation and to make it more maintainable, readable and robust. In short, to turn it into idiomatic Rust.
If you're not going to do that don't post your results online, just keep it to yourself. Anyone could've done this. Even people without any programming skills.
The definition of "serious" developer is changing. An LLM can already produce maintainable, readable, robust code.
It's getting to the point that LLM produced code is indistinguishable from even the best handwritten code.
There's no value in gatekeeping,the code side of software is becoming increasingly democratised, and the barrier to entry is getting closer to no barrier at all.
> It's getting to the point that LLM produced code is indistinguishable from even the best handwritten code.
I think you should read more code ;)
Yeah when I read comments like this I'm thinking either the commenters did not actually bother reviewing the LLM code or they must have access to much better models than those I'm using (claude). Yesterday I reviewed 1500 lines of code which was reduced to 500 by just asking claude "why do we need this" on well chosen parts of the code 3-4 times, to which it would say things like "I made an optimization, but actually this doesn't pay for itself" then explain how the optimizations would actually make the whole thing slower...
> If you're not going to do that don't post your results online, just keep it to yourself
...I mean...I just don't really know how to respond to that. Who the heck cares if someone posts this online? If you don't like it, just move on. Sheesh. Lookout everyone, this guy doesn't approve of your side project.
Does translating Quake to Rust with an LLM count as any sort of project, let alone a side project?
Does budding a cabinet in a weekend counts as any sort of project, given that you used factory made wooden planks and power tools, instead of starting by slaughtering your horse with your bare hands, so you can make a knife from its bones, and use that to make a saw from its sinews and hair, and use that to fell a tree, and...?
Those who remember the time before a new technology will always have a different world view than those raised with it. Some of us will prefer it, some of us won’t. Eventually no one will remain who remembers. That’s just how humanity works.
Yeah I agree. I love Rust and Quake is cool, but this is a trivial project for an LLM, and kind of pointless.
It would have been impressive before LLMs, but now? Who cares? Why is this here?
It does have various improvements over the original version. And I don't agree with the notion that "all work that relies on LLMs requires no effort". If this were the case, we would have plenty of complete Rust ports of Quake. It's open-source, allegedly super easy to port. But as far as I know, we did not.
> If this were the case, we would have plenty of complete Rust ports of Quake.
Well no, because there's little point doing it. You want a port of Quake 2 to Rust? Just ask Opus 5.5 to do it. I'm not going to waste the tokens but I guarantee it could do it with no further prompting.
It's literally a best case for AI - it can easily write tests to ensure bit-for-bit identical output and just keep going until it achieves it.
I'm not going to waste the tokens but based on the other stuff I've vibe coded, this was impossible 1 year ago, a difficult challenge 6 months ago, and trivial today.
I suppose it will fizzle out in a few weeks.
What this exploits is the mental shortcut of "rust = good", which might be a good thing, as that was always wrong. But now it is being pushed to its breaking point so that that idea will eventually collapse.
Accelerationalism on a micro scale, basically.
AI keeps breaking things that were broken before like this constantly. It's the great cleanup of old bullshit. (Unfortunately through even more bullshit, but at least there is a silver lining)
Its been like 3 months of this.
I mean arguably, it has been [claude, when did chatGPT launch and when did we get toolcalls? Subtract from current date] of this.
But "this" has been shapeshifting somewhat constantly. We're dynamically crossfading from one dysfunction being blown up to the next.