sl0 📯 Ω 

69.3K posts

sl0 📯 Ω  banner
sl0 📯 Ω 

sl0 📯 Ω 

@JohaPrime

Senior Systems Engineer @::1 using Linux since 1995, still going strong. Habe Mut, Dich Deines Verstandes zu bedienen. Kant.

CCAA since MCMLIV Katılım Ekim 2014
2.8K Takip Edilen858 Takipçiler
Sabitlenmiş Tweet
sl0 📯 Ω 
sl0 📯 Ω @JohaPrime·
„Dass man pazifistisch oder gegen den Krieg ist, fand ich, war ganz selbstverständlich. Ich dachte immer, jeder Mensch sei gegen den Krieg, bis ich herausfand, dass es welche gibt, die dafür sind. Besonders die, die nicht hineingehen müssen.“ Erich Maria Remarque
Deutsch
3
18
62
0
sl0 📯 Ω  retweetledi
successmovers
successmovers@successmoverss·
successmovers tweet media
ZXX
2
71
270
3.9K
sl0 📯 Ω  retweetledi
Jodokus
Jodokus@mueslikalifat·
Am 24.03. 1944 wurde die Familie Ulma von deutschen Polizisten erschossen. Sie hatte im besetzten Polen jüdische Familien versteckt. Heute gedenkt Polen der Menschen, die damals Juden halfen. Für uns Gelegenheit, ein paar blinde Flecken im Holocaust-Gedenken zu hinterfragen. ➡️
Jodokus tweet media
Deutsch
8
121
469
7.8K
sl0 📯 Ω  retweetledi
Elke C 🇩🇪
Elke C 🇩🇪@ElkeCunow·
💞👍🏼
Elke C 🇩🇪 tweet media
QME
8
3
60
823
sl0 📯 Ω  retweetledi
Cooky
Cooky@Cooky4422548977·
So ist es
Cooky tweet media
English
3
22
84
817
sl0 📯 Ω  retweetledi
Quinn
Quinn@Quinn_Top3·
Zuviele haben selbstständiges Denken leider schon lange verlernt. 😞
Quinn tweet media
Deutsch
11
36
144
1.7K
sl0 📯 Ω  retweetledi
berthoppe
berthoppe@berthoppe·
Während die CDU in Berlin einer Parteifreundin, die einen Juden als „Parasiten“ bezeichnet, für ihr Institut, dessen Wissenschaftler seinen CV schönt, 350.000€ zuschustert, nimmt die Bundes-CDU der anerkannten Institution, die von einem Israeli geleitet wird, die Förderung weg.
berthoppe tweet media
Deutsch
5
102
208
3.2K
sl0 📯 Ω  retweetledi
Vigyan
Vigyan@_phnx_1·
This cheap $8 ADF4350 board is amazing. It can create a RF signal from 137.5 MHz to 4.4 GHz range. Amzing if you want to create a LO for you superheterodyne. Only problem is it has bad loop filter and losses lock if swept fast. Here is am controllingit with Raspberry pi.
English
5
10
94
4.8K
sl0 📯 Ω  retweetledi
Thursday
Thursday@ennui365·
Thursday tweet media
ZXX
1
68
239
2.1K
sl0 📯 Ω  retweetledi
IllimarLepikvonWirén
IllimarLepikvonWirén@iLepikVonWiren·
Today, 77 years ago, around 95,000 people were violently deported from Estonia, Latvia, and Lithuania to Siberia in 1949. Many were small children and elderly, forced into freezing, damp cattle wagons. Just four years after World War II, while much of Europe lived in peace, Soviet terror continued behind the Iron Curtain. Same russian terror continues to this very day in Europe.
IllimarLepikvonWirén tweet media
English
101
1.8K
3.9K
61.2K
sl0 📯 Ω  retweetledi
Hello math
Hello math@skglearning·
Bragg’s Law It explains how X-rays can uncover a crystal's hidden structure by treating its layers of atoms like a set of semi-transparent mirrors. When X-rays hit these layers, most pass through, but some bounce off the atoms.
Hello math tweet media
English
6
29
124
2.3K
sl0 📯 Ω  retweetledi
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
9
75
579
6.1K
sl0 📯 Ω  retweetledi
Thomas Stiegler
Thomas Stiegler@StieglerThomas·
Das Wichtigste ist, dass Kinder Bücher lesen, dass ein Kind mit seinem Buch allein sein kann. Dagegen sind Film, Fernsehen und Video eine oberflächliche Erscheinung. (Astrid Lindgren) Ein Satz, der heute fast altmodisch wirkt – und vielleicht gerade deshalb wichtiger ist als je zuvor.
Thomas Stiegler tweet media
Deutsch
11
69
244
2.8K
sl0 📯 Ω  retweetledi
Lamya Kaddor
Lamya Kaddor@LamyaKaddor·
Das halbe Land diskutiert wegen Collien Fernandes darüber, wie Frauen besser vor digitaler Gewalt geschützt werden können und dem Kanzler fällt nichts Besseres ein, als Zuwanderung für "explodierende Gewalt" verantwortlich zu machen?! Wie stark will er die AfD noch machen?!
Deutsch
1.3K
157
745
47.2K
sl0 📯 Ω  retweetledi
IT Guy
IT Guy@T3chFalcon·
Do O.S devs get any incentives ?
IT Guy tweet media
English
4
23
283
5.6K
sl0 📯 Ω  retweetledi
Native American
Native American@_nativeamerica·
If you support Native American people’s, history & culture Say.. “Yes".❤️
Native American tweet media
English
32
32
160
1.3K
sl0 📯 Ω  retweetledi
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
218
1.7K
8.5K
2M