David

2.7K posts

David banner
David

David

@dasfacc

introspecting about agents, economics and health – vibes are my own

Bogotá, D.C., Colombia Katılım Ekim 2020
684 Takip Edilen173 Takipçiler
Sabitlenmiş Tweet
David
David@dasfacc·
2026 is the year of accountability
English
1
0
2
386
David
David@dasfacc·
@TerribleMaps unless the params to that polynomial bear resemblance to any arbitrary and obscure number code or sentence they are meaningless
English
0
0
0
298
Terrible Maps
Terrible Maps@TerribleMaps·
Believe it or not, Germany’s 5 largest cities lie perfectly on a 4th-degree polynomial
Terrible Maps tweet media
English
331
932
26.7K
3.3M
David
David@dasfacc·
@0xRacist you just ruined the tel aviv vpn upgrade glitch for all of us, hope you're happy
English
0
0
1
102
Tony
Tony@0xRacist·
If it’s fake how am I sitting in the Lufthansa business class right now?
Tony tweet media
Lufthansa@lufthansa

@0xRacist Please be advised that this is not a message sent by Lufthansa - it is fake!

English
336
1.2K
39.6K
3.6M
David
David@dasfacc·
@JTLonsdale car market’s cooked so they may as well
English
0
0
0
50
Jason Howerton
Jason Howerton@jason_howerton·
Early contender for my favorite video of the year. It's the eyebrows for me.
English
324
1.7K
28.4K
3M
Crémieux
Crémieux@cremieuxrecueil·
@dasfacc Doubtful, but red light therapy does seem beneficial for skin!
English
2
0
43
4.7K
David
David@dasfacc·
mr, sir @cremieuxrecueil where do we stand on 670nm red light to stave off age-related macular degeneration?
English
1
0
8
4.7K
Jum
Jum@JesterJum·
Ive been alive 33 years and I just realized the saying is "Open Says Me" and not "Open Sesame"
English
818
150
4.2K
1.5M
David
David@dasfacc·
@gregpr07 speed of light << shitpoasting
English
0
0
0
260
David
David@dasfacc·
@atmoio we used to get scammed by real people dammit
English
0
0
1
17
David
David@dasfacc·
@atmoio is it really the great cum wall of china lol
English
1
0
1
105
Mo
Mo@atmoio·
The internet is dying
English
386
2K
12.9K
600K
David
David@dasfacc·
David tweet media
ZXX
0
0
0
30
Sam
Sam@futurenomics·
state of the economy:
Sam tweet media
English
2
0
8
294
David
David@dasfacc·
@karpathy I get it's hard guarding against this stuff but surely pip shouldn't be doing anything with ~/.ssh unless it's publishing and that shouldn't be callable from an install
English
0
0
1
159
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.3K
5.2K
26.7K
59.6M
David
David@dasfacc·
@shifkey @CryptoCyberia if you want this to have a chance of happening you can't ever use the words "microwave" "laser" and "earth" in the same sentence again the ludites can hear you
English
0
0
0
12
SHIFKEY
SHIFKEY@shifkey·
Lasers. Then big microwave laser recieving panel on earth. Orbital optics to adjust focus & angle. Dyson sphere goes around the sun, this is just solar on the moon. Moon dust is a mf'er tho, would need a way to place the panels very gently without whipping up dust and damaging other panels & the constructing equipment.
English
6
0
3
223
Lain on the Blockchain
Lain on the Blockchain@CryptoCyberia·
A Japanese company has released a concept for a Dyson Sphere. I am no physicist, but I fail to understand how transporting this power back to Earth would ever work, and reading more about this project didn't help me understand.
Lain on the Blockchain tweet media
English
29
1
33
1.8K
can
can@marmaduke091·
This is the best use of AI videos = education that's fun You can teach anything about the history like this, can't wait for the future
English
299
1.5K
10.5K
736K
Saint
Saint@St_Hilairious·
@dasfacc @marmaduke091 @Grok got a little freaky on me. My prompt was "Create an image of a female Pompeii victim holding an iPhone"
English
2
0
5
502
Saint
Saint@St_Hilairious·
Her later in the video: "My skin is going to look AMAZING!"
Saint tweet media
English
2
1
134
10.1K
David
David@dasfacc·
"PreToolUse": [ { "matcher": "Bash", "hooks": [ { "type": "command", "command": "if echo \"$(cat)\" | jq -r '.tool_input.command' | grep -qw 'npx'; then echo 'Use bunx instead of npx' >&2; exit 2; fi" } ] } ]
English
2
0
1
160
David
David@dasfacc·
@strager uv add -> adds dep to current project uv tool install -> installs globally uvx -> downloads and executes ephemerally uv pip install -> blasphemy btw you can enforce this better with a hook:
English
1
0
10
1.8K
strager
strager@strager·
> pip install No Claude, we use 'uv'. > uv pip install 🙈
English
87
123
5.3K
279.6K