Roman Plášil

5.9K posts

Roman Plášil banner
Roman Plášil

Roman Plášil

@Quiark

coding in #HK, crypto, security, kitten, geekiness, kung-fu mantis, diving and saving the ocean @[email protected]

Hong Kong Katılım Ekim 2009
410 Takip Edilen176 Takipçiler
Sabitlenmiş Tweet
Roman Plášil
Roman Plášil@Quiark·
Participated in first @code4rena formal verification contest with Certora, during the CNY. 🐺 I'm pretty excited about this space, I think if code is law, you'd better have some assurances. Formal verification is a way to get there because it can give you correctness guarantees.
English
1
0
17
1.8K
Rob Hallam
Rob Hallam@robj3d3·
Story time: Elon deserves less hate than he gets. Last month I flew Cyprus to Bangkok on Emirates with a layover in Dubai. About halfway through the first flight (5 hours) I realised I could connect to wifi for free. Logged in and saw it was because the plane was on Starlink. First time I'd seen this on a plane, I was excited. Checked the speed: 200+ Mbps download. Holy. I spent the rest of the flight working at insane speeds at 35,000 feet. Landed in Dubai, switched to my connection (another Emirates, 6 hours to Bangkok). First thing I did was check the wifi because I wanted to keep working. It was there, but charging $20 through OnAir (SITA). Not Starlink nice, but fine. So I connected and again checked the speed: 8 Mbps. Over 30x slower than Starlink. Still, the package said multi-device, so I figured I'd just use my phone hotspotted to my laptop. Then I accidentally signed in with my boarding pass instead of my email. Looked for a log out. There was none. I tried clearing cache and cookies. Flushed DNS on the MacBook. Nothing worked. I was stuck on the wrong account on my laptop with no way to switch. Spent the next hour debugging while messaging Grok and Claude on my phone, waiting minutes between replies because the connection was that bad. Eventually flagged down a flight attendant. She went to the lead, came back and said they couldn't escalate to OnAir mid-flight and the only path was emailing for a refund after landing. Fine. Not life or death, but the service didn't work as advertised on the device I actually wanted to work on. Half refund felt fair. 6-8 emails back and forth with OnAir and they refused. Their reasoning: because I'd consumed data on my phone (which I only did to debug the laptop issue) my usage was above the threshold, so no refund. The debugging itself was the disqualifier. The money wasn't the point. I wanted them to know the service was broken, and I wanted to be treated fairly when it was. Neither happened. So to recap: wifi 30x slower than Starlink, charges $20 for it, then when it breaks they refuse the refund because you tried to fix it. Closing line of their final email: "The internet service on board an aircraft flying at 900 km/hour relies on complex solutions, and the same experience as at the airport can therefore not always be provided." You can decide, reading this today, whether you want to be @elonmusk or make excuses. Rant over.
Rob Hallam tweet mediaRob Hallam tweet mediaRob Hallam tweet mediaRob Hallam tweet media
English
49
10
337
93K
Tomáš Šalamon
Tomáš Šalamon@SalamonTomas·
Tohle přesně říkám neustále všem, co chtějí různá opatření na "ochranu dětí". Houby s octem dětí. To je "boomerský" pohled, který vůbec nechápe stav věcí. Děti, které se už narodily do věku sociálních sítí a nic jiného neznají, mají daleko větší implicitní nedůvěru k informacím a institucím. Jestli je někdo ohrožený dezinformacemi, děti to nejsou, jsou to starší dospělí, kteří insitucím ještě věří.
Čeština
3
1
36
860
Pavel Kasík
Pavel Kasík@kasikp·
Dělat AI workshop pro školáky znamená jít s kůží na trh 😁 Když vidí, jak snadné je upravovat něčí vzhled, chápou, že "obrázky nejsou důkaz reality". Což nám může přijít smutné, ale taková je prostě doba. Deepfakes na ně budou mít menší dopad, než na naši generaci.
Pavel Kasík tweet mediaPavel Kasík tweet mediaPavel Kasík tweet mediaPavel Kasík tweet media
Čeština
3
3
37
4K
Roman Plášil
Roman Plášil@Quiark·
@eigenrobot Ok so I googled a couple of Larson comics explanations and concluded that the problem is that I'm expecting too much
English
1
0
9
3.9K
Roman Plášil retweetledi
Jediwolf
Jediwolf@Jediwolf·
What happens when you post a real Monet and say it’s AI? The coolest art social experiment I’ve seen in a while. Thank you @SHL0MS
Jediwolf tweet media
English
980
3.4K
20.8K
2.1M
ClaudeDevs
ClaudeDevs@ClaudeDevs·
Starting June 15, paid Claude plans can claim a dedicated monthly credit for programmatic usage. The credit covers usage of: - Claude Agent SDK - claude -p - Claude Code GitHub Actions - Third-party apps built on the Agent SDK
English
1.3K
1K
12.5K
10.1M
Animarchy History 🇦🇺
The fact that more Russian soldiers have died in the Special Military Operation than the TOTAL number of U.S military deaths in WW2, is absolutely insane
English
65
264
7.1K
187K
Maximus
Maximus@Maximus_8796·
@norwalkiian @dim0kq Lmao As if you think I support my countries war crimes War is a crime All of it Enough
English
6
0
23
780
Dimko Zhluktenko 🇺🇦⚔️
Fiber optics is still happening at the battlefield, although not as much as it used to be. It's extremely pricey now. We used to buy 50km spool for $300, now it's easily $2500. Just so you know
Dimko Zhluktenko 🇺🇦⚔️ tweet media
English
90
761
5.4K
1.4M
patrick.algo
patrick.algo@patrickbennett·
No it’s a damn package manager that will run any executable code attached to a dependency. Should be hard blocked. Disabled by default. Allow list only. Explicit hash. GitHub protection defaults that block changes except by owners. No clue why it hasn’t already been locked down. Start with using pnpm at least.
English
1
0
14
1.7K
Armin Ronacher ⇌
Armin Ronacher ⇌@mitsuhiko·
Published via OIDC trusted publishing btw. I hope this ends this absurd idea that OIDC is the silver bullet to supply chain issues.
TANSTACK@tan_stack

SECURITY ADVISORY — TanStack npm packages A supply-chain compromise affecting 42 @tanstack/* packages (84 versions total) was published to npm earlier today at approximately 19:20 and 19:26 UTC. Two malicious versions per package. Status: ACTIVE — packages are deprecated, npm security engaged, publish path being shut down. Severity: HIGH — payload exfiltrates AWS, GCP, Kubernetes, and Vault credentials, GitHub tokens, .npmrc contents, and SSH keys. If you installed any @tanstack/* package between 19:20 and 19:30 UTC today, treat the host as potentially compromised: • Rotate cloud, GitHub, and SSH credentials immediately • Audit cloud audit logs for the last several hours • Pin to a prior known-good version and reinstall from a clean lockfile Detection — the malicious manifest contains: "optionalDependencies": { "@tanstack/setup": "github:tanstack/router#79ac49ee..." } Any version with this entry is compromised. The payload is delivered via a git-resolved optionalDependency whose prepare script runs router_init.js (~2.3 MB, smuggled into each tarball at the package root). Unpublish is blocked by npm policy for most affected packages due to existing third-party dependents. All 84 versions are being deprecated with a SECURITY warning, and npm security has been engaged to pull tarballs at the registry level. Full technical breakdown, complete package and version list, and rolling status updates: github.com/TanStack/route… Credit to the security researcher for responsible disclosure.

English
15
41
574
69.7K
Roman Plášil
Roman Plášil@Quiark·
Anyone tried to use Claude to build an ontology?
English
0
0
1
11
Erik Voorhees
Erik Voorhees@ErikVoorhees·
How do I solve this bullshit
Erik Voorhees tweet media
English
131
5
280
62.3K
Roman Plášil
Roman Plášil@Quiark·
@DavidGrudl Chystáte se někdo koupit notebook s procesorem SnapDragon Chystáte se někdo koupit notebook s procesorem SnapDragon
Čeština
0
0
1
115
David Grudl
David Grudl@DavidGrudl·
Chystáte se někdo koupit si notebook s procesorem Snapdragon X2?
Čeština
11
0
4
8.2K
Roman Plášil retweetledi
Jarred Sumner
Jarred Sumner@jarredsumner·
why: I am so tired of worrying about & spending lots of time fixing memory leaks and crashes and stability issues. it would be so nice if the language provided more powerful tools for preventing these things.
English
50
64
1.8K
509.8K
Roman Plášil
Roman Plášil@Quiark·
@lauriewired @DefuseSec @h0mbre_ Most of the 10k bugs gonna be stupid rendering bugs or things like a http request getting stuck but yeah 400 security bugs is not really a surprise
English
0
0
1
126
LaurieWired
LaurieWired@lauriewired·
I mean, firefox is what, ~25ish million lines of code? in aerospace, the target was ~0.5 defects per 1000 lines of code. Apply that to firefox numbers and you get ~10,000 bugs. aero code was also held to a ridiculous standard, commercial software is probably 5x worse than that. it's also probably non-linear, the bigger your codebase the faster the rate goes up
English
30
59
2.3K
58.6K
h0mbre
h0mbre@h0mbre_·
i honestly didn't even think there was 423 security bugs in firefox. much less so many that 423 could be found and fixed within a month.
English
8
6
437
51.3K
TK
TK@tarek_kekhia·
@levelsio I really curious do you have a SQLite specific backup strategy or you depend on the VPS snapshots/backups? And i'm guessing you probably never even had to restore from any backups unless it was unintended human caused db corruption.
English
3
0
0
1.2K
Roman Plášil
Roman Plášil@Quiark·
@celestialbe1ng Fair I thought about starting a guild of men to push against misandry that we see nowadays. Only non-lazy and honorable men will be admitted.
English
0
0
0
14
Veronica, Collagen Scientist
Veronica, Collagen Scientist@celestialbe1ng·
You’re still not getting it: women WANT babies VERY MUCH. But there is NOTHING women fear MORE than having a kid with the wrong guy. Bullying me about running out of time changes nothing bc I DO WANT kids, but there is NOTHING I want less than having them with the wrong person
Veronica, Collagen Scientist@celestialbe1ng

Maternal instincts kicking in like crazy right now. Maybe the pro-natalists were right all along…..

English
912
284
4.4K
877.6K