Ratthew

77 posts

Ratthew banner
Ratthew

Ratthew

@RatthewRants

I rant about tech and politics

Katılım Ağustos 2022
818 Takip Edilen69 Takipçiler
Ratthew
Ratthew@RatthewRants·
@ThePrimeagen @ZackKorman Yeah, this is just surfacing a structural problem with open source, having to trust that many random developers is not a good idea, specially if they can push code and it propagates to your software, but today with ai I can remove entire packages and have ai do the work
English
0
0
0
157
ThePrimeagen
ThePrimeagen@ThePrimeagen·
I want to be explicitly known: I am worried about security. I have always been. I am living in the notion that this is potentially an asymmetric improvement for defense. Assuming for the first time defense has something that can find more bugs quickly thus leading to better security overall. The obvious problem being small untouched / unloved libraries having significantly more chances of security issues. But, its easier than ever to reduce dependencies of these small one off libraries. Fine being wrong, sad if I am, but not ignorant blissing right now.
English
19
5
287
23.2K
Zack Korman
Zack Korman@ZackKorman·
Choose your fighter, cybersecurity. I’m on @ThePrimeagen’s side here. I’m worried about other stuff. Not this.
Zack Korman tweet media
English
37
5
197
30.7K
Ratthew
Ratthew@RatthewRants·
@digdimension7 @ThePrimeagen @LowLevelTweets Could be the opposite tho, maybe GitHub can solve what to integrate and what not to integrate with their ai models at scale? Maybe I'm just making a word salad 😂, unclear yet LoL
English
1
0
0
13
ThePrimeagen
ThePrimeagen@ThePrimeagen·
My continual disgust at the JS ecosystem feels vindicated practically daily at this point
English
122
69
2.2K
182.1K
Ratthew
Ratthew@RatthewRants·
@digdimension7 @ThePrimeagen @LowLevelTweets Reinvent the wheel, use no packages, ai can help, the code is usually also way shorter than said lib was, because it's for you, what you needed, unless it's something super technical and critical, hard to implement, in that case idk yet
English
1
0
0
27
Ratthew
Ratthew@RatthewRants·
@Koto_Sumire @midudev I know, I agree, but we are talking about big tech players and infra here, and engineer's bridges can't keep falling, we need to do better there's no going around that, trading a single point of failure, with thousands of points of failure is not a win
English
0
0
0
74
💜S u m i ~ 🇨🇴
💜S u m i ~ 🇨🇴@Koto_Sumire·
@RatthewRants @midudev Supply chain attacks also affect proprietary software (remember the SolarWinds incident) and it is equally devastating for everyone affected. You don't need the source code to create a malicious version of a program.
English
1
0
0
92
Miguel Ángel Durán
Si estás usando npm install, estás en peligro. ¡Así de crudo te lo cuento para que reacciones! Ayer se comprometieron paquetes de TanStack en npm. De las bibliotecas más usadas en el mundo JavaScript. Y de ahí saltó a Mistral, OpenSearch, UiPath, PyPI... Porque muchos ataques no necesitan que importes nada. Basta con una instalación para infectarte. ¿Cómo? Colando scripts como preinstall o postinstall que se ejecutan durante la instalación. Lo importante es que tiene solución: ① Usa pnpm 11 Viene con defensas por defecto contra este tipo de ataques. ② Si sigues usando pnpm 10, npm, yarn o bun Activa minimumReleaseAge y ponle 1440. Evita instalar versiones publicadas el mismo día. ③ Bloquea scripts de instalación por defecto pnpm evita que cualquier dependencia ejecute código en tu máquina solo por instalarla. Por favor, comparte esto para que le llegue al máximo número de personas y paremos la cadena de ataques.
Miguel Ángel Durán tweet media
Español
64
704
3.5K
299K
Ratthew
Ratthew@RatthewRants·
@nullblob @midudev It's on us, engineers to do our work ethically, make each other accountable like professional work does, like in medicine and other engineering fields, if our bridges keep falling we can't just blame the corps
English
0
0
0
33
Ratthew
Ratthew@RatthewRants·
@nullblob @midudev I get you, you'd think that, but big tech also has good engineers that know what they are doing, for example google has pushed forward a lot of tech around fido tokens, passkeys, and way more things that just can't happen without big tech, we can't impose a standard at that level
English
1
0
0
109
Ratthew
Ratthew@RatthewRants·
@StupidHunterPro @itsr0dri Es que si pueden, el estado tiene el uso de la fuerza, vos que tenés? Un palo? Y yo soy de derecha pero hay que leer a cada boludo, sos igual de descerebrado que un zurdo, construir esta regulado desde antes que existiera Uruguay..., hasta la altura de la puerta ...
Español
1
0
0
18
Ratthew
Ratthew@RatthewRants·
@Barbaroja22 @elpaisuy Es que no es eso lo que dice la noticia, es que la mitad del precio del combustible es impuestos, el imesi, si quisieran bajar el combustible pueden, de un día para el otro, significativamente, sin importar el precio del petróleo, solo bajando el impuesto
Español
0
0
0
11
Barbaroja2
Barbaroja2@Barbaroja22·
@elpaisuy Pero los medios no apretan a los políticos esto es solo manija para calentar a la gente, sube el petróleo y suben los combustibles pero cuando baja lo hacen sabiendo que el porcentaje es mucho más bajo de lo que debería ser
Español
2
0
4
802
Ratthew
Ratthew@RatthewRants·
@vidamrr Pre ai, habia que inventar más formas de vender y ocupar la cloud, ahora como la ocupan con ai no necesitan perseguir esos caminos jaja
Español
0
0
25
2.1K
Ratthew
Ratthew@RatthewRants·
@Bonnie_Chuck @nym How do you do that without aggressively blocking all of the internet like china does
English
1
0
2
148
jlima
jlima@Bonnie_Chuck·
@nym If they force ID at the point of connection to the net, does a decentralized VPN still work?
English
5
0
7
675
Ratthew
Ratthew@RatthewRants·
@hslmv77730 @Worshipperfx @Polymarket Si, si un modelo realmente diera una ventaja como la que vendieron con mythos lo usarían para dominar mundo sin decirte nada jajaja, si te enteras, es porque te lo quieren vender a ti
Español
1
0
0
32
El patriarca
El patriarca@hslmv77730·
@Worshipperfx @Polymarket Hahahaha osea que un modelo que aun no ha salido al público y estan todos los bancos como locos es un modelo sobrevalorado?
Español
1
0
0
134
Polymarket
Polymarket@Polymarket·
NEW: EU finance ministers press Anthropic to let local companies test Claude Mythos so they don’t “fall behind” U.S. companies.
English
114
74
1.7K
332.6K
Ratthew
Ratthew@RatthewRants·
@ObservadorUY Pero que mentira, como si hubiesen descubierto que reducir la velocidad en ciertas zonas clave reduce la severidad, es obvio Si no es por recaudar entonces devuelvan lo recaudado dividido a todos los que no tuvieron multas al pagar la patente y listo, lo van a hacer??
Español
0
0
0
147
Ratthew
Ratthew@RatthewRants·
@NicoSoprano01 @DiegoAlbornoz8 Hay mercado si no se vende nada? 😂 Porque esa misma TV después sigue estando por años y nadie la compra y la siguen ofreciendo
Español
1
0
0
95
Nico
Nico@NicoSoprano01·
@DiegoAlbornoz8 Se llama libre mercado, nadie te obliga a comprar
Español
2
0
14
1K
Diego Albornoz
Diego Albornoz@DiegoAlbornoz8·
Uruguay, un lugar dónde la misma TV sale un precio en un lugar y en otro un 30% más cara...
Diego Albornoz tweet media
Español
14
2
25
12.2K
Rex
Rex@rexjonesnewz·
Yo @paleochristcon let’s do pro vs anti war debate this May You do support the war, no matter what disclaimer you provide before you start running cover for mass slaughter (that people voted against!) It’s not honest to say you don’t support the war while justifying it
English
51
16
250
38.8K
Ratthew
Ratthew@RatthewRants·
@aocburneracct @BarvLoPing @rexjonesnewz @paleochristcon You don't understand these things are set by who has the force, if I'm the force in power a terrorist is whoever the fuck I say it is, globalism doesn't work, it's failed already, who's gonna enforce it, the un? 😂
English
1
0
0
8
Ratthew
Ratthew@RatthewRants·
@aocburneracct @BarvLoPing @rexjonesnewz @paleochristcon Okay you were doing good, don't stop there, invaded by who, yourself? 😂 if Iran or others that are enemies of America think they should invade, because I'm sure they'd love that, they can try, but THE US doesn't need to help with that, that's where your logic is retarded
English
1
0
0
21