johan

933 posts

johan banner
johan

johan

@derpsmith

math boi in software

Brooklyn, NY Katılım Nisan 2012
2.3K Takip Edilen146 Takipçiler
Ryan Peterman
Ryan Peterman@ryanlpeterman·
Barbara Liskov is a Turing award winner famous for her contributions to programming languages and distributed systems. I interviewed her recently about: • Being rejected from college based on gender • The software crisis of the 1970s • Paxos vs Viewstamped replication (her invention) and why one is more well known • Stories of Dijkstra and how his work influenced hers • Why her Turing award was questioned Where to watch: • Youtube - youtube.com/watch?v=T9CGjb… • Spotify - open.spotify.com/episode/7yMHEr… • Apple Podcasts - podcasts.apple.com/au/podcast/tur… • Transcript - developing.dev/p/turing-award…
YouTube video
YouTube
English
10
92
624
167.2K
johan
johan@derpsmith·
i miss when entrepreneurs didn’t try to be shitty ray kurzweils
English
0
0
1
20
johan
johan@derpsmith·
appreciate the representation
johan tweet media
English
0
0
1
39
johan
johan@derpsmith·
if you don't fuck with basic, at least listen to the anecdote in the credits
English
0
0
1
23
Jim Sharkey (@madscienceskill)
Jim Sharkey (@madscienceskill)@madscienceskill·
@derpsmith @anomalie_blue Better than to encounter him unawares at a science event selling klein bottles. Once he starts a conversation, you’ll be lucky to get out of there before sunset. Happened to me twice first time: “That was odd.” Second time, “oh, that just how he is.”
English
1
0
1
55
Helen
Helen@anomalie_blue·
Astronomer Cliff Stoll is dopamine personified. In 1986, he uncovered a 75-cent billing error that led to the discovery of a KGB-sponsored hacker named Markus Hess who was stealing U.S. military secrets. He now sells Klein bottles out of his basement in California.
English
40
235
2.8K
390.5K
johan retweetledi
Eric Zhang
Eric Zhang@ekzhang1·
Nice turnout at NY systems reading group today!! Meeting folks, reading code and discussing on a Friday evening :)
Eric Zhang tweet mediaEric Zhang tweet media
English
10
3
236
21K
Piyush
Piyush@CatAstro_Piyush·
stumbled upon a goldmine. over 300 interviews.
Piyush tweet media
English
8
30
420
8.4K
johan
johan@derpsmith·
babby johan would have been so stoked if he knew what adult johan was up to today
English
0
0
1
44
johan
johan@derpsmith·
@ThePrimeagen The code executes each time a CPython interpreter starts, and the code starts CPython interpreters :-)
English
1
0
0
71
ThePrimeagen
ThePrimeagen@ThePrimeagen·
> So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks do we have proof of this? I want this to be true so bad
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
65
32
1.8K
189.3K
Brie Wolfson
Brie Wolfson@zebriez·
who is this baby that worked on the Mac?!
Brie Wolfson tweet mediaBrie Wolfson tweet media
English
5
1
41
9.5K
Raphael Grably
Raphael Grably@GrablyR·
La localisation du porte-avions français Charles de Gaulle rendue possible grâce à l'imprudence d'un marin utilisant l'application de running Strava, rapporte Le Monde. En faisant son footing sur le pont, il révélait la présence du navire.
Raphael Grably tweet media
Français
603
1.8K
10.7K
3.7M
johan
johan@derpsmith·
the best part about bouldering is being confident you can climb a retracted fire escape drop ladder
English
0
0
2
56
johan
johan@derpsmith·
breaking: i am cute
English
0
0
2
64
Kirby Sommers
Kirby Sommers@LandlordLinks·
"I know who that little girl is and have been threatened if I ever say her name again. Very very sad what she was subjected to and that the parents are being protected." -Virginia Giuffre about Celina Dubin who is the eldest child of Eva & Glenn Dubin.
Kirby Sommers tweet mediaKirby Sommers tweet media
English
19
973
3.4K
67.9K