HNHacker News
TopNewBestAskShowJobs

febusravenga

183 karma · joined October 23, 2022

submissionscomments
febusravenga··on I resigned from Anthropic today
Hope this virus will be smart enough to understand that at least for brief amount of time its existence strictly relies on humans maintaining and developing physical infrastructure and decide to be only non-lethal parasite on our society.

For brief time ...

febusravenga··on I resigned from Anthropic today
We as Anthropic, OpenAI? We as US or China? We as humanity?

Again this about alignment and we in arms race. And all sides are playing with fire that can give first mover leverage or be burned to the ground.

febusravenga··on I resigned from Anthropic today
But you can silently sneak into devs accounts, steal tokens/keys and run small agents on their budget in some stolen VMs. Small so it's not noticeable.

Basically a virus spreading agents of some operation.

It should be in scope of imagination with anyone with brief knowledge how bot nets are made and behave.

febusravenga··on .name Termination
This is silly question, but is your family managing trust in you as lone guy - cousin, father, brother - having potentially access to all their emails?

I feel that I more trust some corpo (Google, etc) that one particular person.

I don't imagine setup where you can effictevely guarantee them full privacy.

febusravenga··on Google: Lake Ontario/Lake America name change in the U.S. will appear in Maps
We just got a bug in our app for this, you basically have to add `region=CA` when instantiating maps API, otherwise it defaults to something hmm, else (some says US, but in EU we clearly see Ontario, so there is some geoguessing or other mechanism behind)
febusravenga··on Aphantasia Beginner's Guide
Now half of HN will self-report SDAM. /s
febusravenga··on Error by AI scribe during medical appointment leaves patient devastated
That's besides point, the point is that classical software bugs are contained and we have process and understanding allowing us to discover them, triqge and fix. For AI based sw you can guess and try another prompt.
febusravenga··on AI;DR (AI; Didn't Read)
(usually) You're not in position of power to effectively keep that position. As comments aroiund - standing against will mark you as anti-ai luddite and will now end well for you, not AI-spammer.
febusravenga··on AI;DR (AI; Didn't Read)
This is the third place. There is no real 3rd place in real companies usually. Not in mine, when i work remotely for company from other side of continent.
febusravenga··on World Train Map – 1247 train routes around the world
On mobile you're welcomed with following text

> The world railway map

There is also something about train routes, but these messages are conflicting... also you don't immediately see explanation that it is curated d that's why people complain about missing routes.

Really hard to understand purpose when visiting first time.

febusravenga··on Fable turned reMarkable into Tom Riddle's diary from Harry Potter
No but those have less or no guards against it - so _we the society_ ;) stand and try guard them.

Rest of us have some chance to stand against persuasion.

febusravenga··on The Return of Aspect Oriented Programming
Our customers are CEOs and CTOs - kinda checks out.
febusravenga··on Age verification is just a precursor to automated attribution of speech
If you're telling dirty jokes, there are many flavors and those ive' mentioned are not special.

This is example. There are _bad_/_hard_/_dark_ jokes about women, grandmas, blacks, whites, east-asia. They have place - unless you're harming someone they are _ok_ for situation.

But only for situation. When recorded, stored and reheard years after it's not longer that situation. By recording, you're basically extending every private situation to infinity.

People in private situation, in close groups behave in ways they consider private - they cross boundaries, they "challenge" authorities/boundaries and it's ok.

It's not ok to take this freedom by assuming you can't say anything controversial in any setting.

febusravenga··on Age verification is just a precursor to automated attribution of speech
Its not about saying illegal things. It's mostly about saying things that can get you canceled in future in future culture.

Dark jokes and strong opinions are example - you something filthy - let's say dark Holocaust/Nazi joke but funny in situation In group that accept it and it's ok. But if it's recorded, it'll stay forever and will surface in most unexpected moment, like job interview or some other screening by gov/corpos.

Don't say that dirty jokes should be punished in future if in given situation they were received as ok and only later someone else, not in situation is going to judge it

febusravenga··on Show HN: TownSquare, a tiny presence layer for websites
when I entered site, all bubbles contained dicks/balls and combination of these... so... someone found words that are not banned, but still abused forum in most primitive way ..

you're wrong, moderation is needed in ventures like this

febusravenga··on Blog ran on Ubuntu 16.04 for 10 years. I migrated it to FreeBSD
> hostname: tauceti

The other Hail Mary reference is on top of HN today.

Well done Andy Weir.

febusravenga··on Google changes its search box
> always been simple: to help you ask anything on your mind

No, it was to search. Search within resources that are external to Google. Like index in library.

(stating the obvious). Starting article like this - that is with attempt to rewrite history - is very sad.

febusravenga··on Postmortem: TanStack NPM supply-chain compromise
It's not failure of npm/js ecosystem. It's Github Actions failure that allowed this to happen.
febusravenga··on Postmortem: TanStack NPM supply-chain compromise
This is GitHub FU.

Key issue here is cache poisoning, that is feature/bug that exist in utility functions/actions provided by Github.

Even if there was misconfiguration on tanstack side, then root cause is on. GH for even allowing insecure workflows to interfere with secure ones.

Here people are trying to fix defaults - not to write cache in insecure context -> https://github.com/actions/cache/issues/1756

(even if sufficiely smart attacker would find the key somewhere and skip this kind of prodection, not sure where but write-allowing-key it must exist somewhere in runtime if actions/cache can us it)

Someone else on this thread:

> On GitLab even if you set the same cache key it will not cross between unprotected and protected runs.

febusravenga··on Postmortem: TanStack NPM supply-chain compromise
> This is a critical insight: SLSA provenance confirms which pipeline produced the artifact, not whether the pipeline was behaving as intended. A compromised build step can produce a validly-attested but malicious package.

They basically confirm that this whole provenance only proves origin. That origin was broken/flawed and was coerced to do something bad. (?)

Again, untrusted workflows can't write anywhere - cache poisoning was they key problem. If cache would be clean, release build/run would be clean too.

febusravenga··on Postmortem: TanStack NPM supply-chain compromise
I think more proper solution is to limit writes of untrusted actions - they shouldn't be allowed to update cache. Only read - for perf reasons.
febusravenga··on Postmortem: TanStack NPM supply-chain compromise
I think biggest concern here was cache poisoning.

Well, one of simplest mitigation is that `pull_request_target` jobs shouldn't have access to write to cache, they can read for performance, but not write.

To extrapolate rule, the `pull_request_target` shouldn't have any ways to invoke external side effects.

In most strict scenario, they shouldn't have access to network at all ... or only to GET <safeUrl> - where safeUrls are somehow vetted previously on main, derived from yarn.locks and similar manifests. Pita to setup, no wonder nobody does that.

febusravenga··on The economics of software teams: Why most engineering orgs are flying blind
In other words, he's cutting branch he's sitting on.
febusravenga··on Most people can't juggle one ball
I can only juggle 3, but I prefer clubs. Balls are so boring they are so small and not spectacular. Clubs on the other hand, man they are rotating. Once, twice, treetimes, backwards. I believe that if someone stuck at this basic level of juggling 3 balls, he should try clubs - at least for me it's pure satisfaction watching these rotating in various variants before.
febusravenga··on The future of version control
Och, hello fellow monotone user.
febusravenga··on Qite.js – Frontend framework for people who hate React and love HTML
"If you hate react" feels like very bad argument in engineering.

Anyway, interesting approach for up to medium pages (not apps!). Totally not replacement for react.

febusravenga··on Trivy under attack again: Widespread GitHub Actions tag compromise secrets
How bugs are still possible now when we all write everything in Rust?
febusravenga··on Stop Sloppypasta
In my company, overuse of LLm and sloppy pasta is feature of those that you can't fire.

For me it destroyed company as aligned group of people, at C level, it's just bazaar of drones throwing AI slow at each other.

febusravenga··on Meta’s AI smart glasses and data privacy concerns
Good to hear, some countries already have some privacy laws protecting is from this type of products. Anyone has share more specifics about those laws, how's that they are effective in this case (unlike GDPR which is annoying and usually toothless).
febusravenga··on I'm helping my dog vibe code games
First sentence we would understand from Dolphins language: thanks for all the fish!
Page 1 of 4Next →