David Acacio (EA3IPX)

4.9K posts

David Acacio (EA3IPX) banner
David Acacio (EA3IPX)

David Acacio (EA3IPX)

@david_acacio

Father, Cloud Architect, techie and #hamradio operator. I'm co-host @EntreDevYOps podcast and work @SchneiderElec. EA3IPX on radio.

Barcelona, España Katılım Şubat 2010
298 Takip Edilen292 Takipçiler
David Acacio (EA3IPX) retweetledi
Harrison Ford
Harrison Ford@HarrisonFordLA·
May the fourth be with you
GIF
English
2.9K
51.7K
220.7K
7M
David Acacio (EA3IPX) retweetledi
Sergio López
Sergio López@slpnix·
This is what is going to happen, once again: - 1st week: Everyone talks about it. - 2nd week: IT departments issue mandatory checks. - 3rd week: "Supply chain attacks are a real threat a something must be done to prevent them". - 4th week: "Oh, look, AI has learnt a new trick!".
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
0
3
7
763
David Acacio (EA3IPX) retweetledi
David Poblador i Garcia
David Poblador i Garcia@davidpoblador·
Que alguna cosa va passar amb el dataset de les subvencions en qüestió ahir és clara. Mireu el patró de publicació automàtica, i el patró estrany d'ahir:
David Poblador i Garcia tweet media
Català
0
3
7
603
David Acacio (EA3IPX)
David Acacio (EA3IPX)@david_acacio·
Hace 1 año el #vibecoding era poco más que un meme recurrente. Hoy, muchos intentan entender su impacto real en la industria. Interesantes tiempos vivimos cuando en un solo año puede cambiar por completo el paradigma.
Español
0
0
1
28
David Acacio (EA3IPX)
David Acacio (EA3IPX)@david_acacio·
Tengo la suerte de haber vivido algunos de los grandes hitos de los últimos años: internet, smartphones, cloud… Con todo lo que está pasando con @moltbook y @openclaw, tengo la sensación de estar viviendo otro momento clave. #OPENCLAW #IA
Español
1
0
1
59
David Acacio (EA3IPX) retweetledi
{Fabian/EB1TR} 📻 🧉 🐍
Me quedo perplejo de la cantidad (y calidad) de red de transmisores que perderá España con el cierre de la Onda Media. 94 emisiones que he comprobado y la gran mayoría estoy escuchando. Alucino con lo corto de la vista de algunos directivos.
{Fabian/EB1TR} 📻 🧉 🐍 tweet media
Español
1
14
26
3.8K
David Acacio (EA3IPX) retweetledi
{Fabian/EB1TR} 📻 🧉 🐍
Hoy ha tocado una de esas mañanas de radio "extrañas", donde lo mas cerca que estas de un QSO es verlo pasar por una terminal... Configurando pipelines, balanceadores, conexiones, Prometheus, Grafanas, etc. Que diversa es la #radioaficion! #HamDevOps #RadioDeBytes
{Fabian/EB1TR} 📻 🧉 🐍 tweet media
Español
1
1
5
137
David Acacio (EA3IPX) retweetledi
{Fabian/EB1TR} 📻 🧉 🐍
Esta mañana he aprovechado a actualizar mi post sobre "Tips para el buen (mejor) uso del DXCluster". eb1tr.com/tips-dxcluster/ En él podéis ver los filtros que uso para que la información que entra por Telnet a mi libro de guardia no sólo sea mucha, sino precisa. #DX #DXCluster
Español
1
2
7
253