Adam de Delva

459 posts

Adam de Delva

Adam de Delva

@Adedelva

Literally just Cars, Hybrid Cloud, Modern Apps, K8s, OSS & memes. internet plumber: @dtrio_ // Principal Alchemist: https://t.co/c3jTkhsO0L Ex - @Microsoft

Queens, NY Katılım Kasım 2017
469 Takip Edilen153 Takipçiler
Adam Pippert
Adam Pippert@AdamPippert·
If I share something personal when I’m known for more technically focused content, does that make me more human or less relevant for people on this platform? On the one hand, I don’t want a personal tragedy to be seen as an excuse for attention, but on the other hand, I am real.
English
1
0
5
88
Adam de Delva
Adam de Delva@Adedelva·
HLIX is the last 15 years of IP that I’ve (and the collective have learned) in a BoM.
English
0
0
0
26
Adam de Delva
Adam de Delva@Adedelva·
Do not bet against the collective. Our position remains the same.
English
0
0
1
28
Jarret Willey
Jarret Willey@JarretW·
@karpathy @grok I had a feeling this was going to happen when millions were installing. Is this as bad as I think it is? Could personal private information be stolen ?
English
2
0
2
26
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.4K
5.4K
28.1K
66.2M
Adam de Delva retweetledi
Adam Pippert
Adam Pippert@AdamPippert·
The feedback speed ALONE makes open source better. This could literally be the only reason America makes any investment whatsoever in open source AI, and it would be the right thing to do.
English
1
1
2
53
Adam de Delva
Adam de Delva@Adedelva·
@JosephJacks_ Sovereignty, Agency & Resilience Planning are all that matter. The future is open.
English
0
0
0
516
JJ
JJ@JosephJacks_·
Huge layoffs are coming. Across the board.
English
128
78
1.4K
141.6K
Adam de Delva
Adam de Delva@Adedelva·
7x. Do not bet against the collective.
English
0
0
0
52
Adam de Delva
Adam de Delva@Adedelva·
We got the new Elon in the collective. Good luck going against this.
English
0
0
0
36
SmartAssetsIO
SmartAssetsIO@smartassetsio·
We need a Byzantine Faul Tolerant arch. for network management
English
2
0
2
0
Adam Pippert
Adam Pippert@AdamPippert·
@Adedelva Radicle is decentralized git, guys we know like @iotcoi use it extensively. Have some ideas cooking about how to hook agents into all of this, but first I have to rebuild them to shed the OpenClaw stank off.
English
2
0
2
82
Adam Pippert
Adam Pippert@AdamPippert·
So, I’m thinking about deleting my GitHub, or at least marking certain projects read only and posting code elsewhere going forward. Any advice from people who have gone to self-hosted, Radicle, or other less well known repositories?
English
1
0
1
345
Adam de Delva
Adam de Delva@Adedelva·
Gonna f' around and find out and turn Open Office into a Smart-Asset, and power it with HLIX. This is going to be a fun one.
English
0
0
1
62
Adam de Delva
Adam de Delva@Adedelva·
@georgevasyagin @jefielding It’s pathetic. Since then - our collective has grown to 3.1M engineers. All of them passed on us three years ago… are now salivating.
English
0
0
0
33
George V.
George V.@georgevasyagin·
Most companies I've designed for treated the product as the strategy. The ones that actually "made it" treated distribution as the strategy and the product as the vehicle to deliver real value to real people. VCs are just now catching up to what operators figured out years ago? So.. time to shift focus? :-)
English
1
0
3
1K
Jenny Fielding
Jenny Fielding@jefielding·
Half the VCs I know are changing their focus areas / investment thesis right now. Feels like a moment of deep reflection - or panic.
English
125
37
573
108.8K
Adam de Delva
Adam de Delva@Adedelva·
Universal Object Reference, a universal language to pin to all geometry? All potential realities? Somehow.... Underpinning the fabric of the system that powers existence itself? Yeah... I think that's what we've arrived to. Language is only the first and direct implementation.
English
1
0
1
57
Adam de Delva
Adam de Delva@Adedelva·
“We’re doing a lot with fumes, and we’re turning those fumes into nuclear power.” Marie Patterson//Adam de Delva
English
0
0
0
45