Sabitlenmiş Tweet
fuho
140 posts

fuho retweetledi

I can't read code, but I use open-source repos all the time. So I made a Github explainer: the @github for humans.
Simple human-facing explanations of the best repos out there. Because humans don't read code anymore, and vibe coders never did.
repo-explainer.com
English

Started repo-explainer.com 2 weeks ago.
Yesterday I had to add category filters and lazy loading, because there are just too many repos to list.
What next?


English

I have just updated @Tailscale on the MacBook and wow... this is such a leap forward, thank you!

English
fuho retweetledi

🦔 Researchers at Aikido Security found 151 malicious packages uploaded to GitHub between March 3 and March 9. The packages use Unicode characters that are invisible to humans but execute as code when run. Manual code reviews and static analysis tools see only whitespace or blank lines. The surrounding code looks legitimate, with realistic documentation tweaks, version bumps, and bug fixes. Researchers suspect the attackers are using LLMs to generate convincing packages at scale. Similar packages have been found on NPM and the VS Code marketplace.
My Take
Supply chain attacks on code repositories aren't new, but this technique is nasty. The malicious payload is encoded in Unicode characters that don't render in any editor, terminal, or review interface. You can stare at the code all day and see nothing. A small decoder extracts the hidden bytes at runtime and passes them to eval(). Unless you're specifically looking for invisible Unicode ranges, you won't catch it.
The researchers think AI is writing these packages because 151 bespoke code changes across different projects in a week isn't something a human team could do manually. If that's right, we're watching AI-generated attacks hit AI-assisted development workflows. The vibe coders pulling packages without reading them are the target, and there are a lot of them. The best defense is still carefully inspecting dependencies before adding them, but that's exactly the step people skip when they're moving fast. I don't really know how any of this gets better. The attackers are scaling faster than the defenses.
Hedgie🤗
arstechnica.com/security/2026/…
English

@QAB5zNYD5yM81 Recently yes. I am searching for a way to a way to purchase monkey artworks online with electronic coins. Any ideas?
English
fuho retweetledi
fuho retweetledi

@intellijidea I remember it very clearly ...was waiting for Eclipse to load. Netbeans I used on a Sun system couple years before that.
English


@krystof_jelinek @slushcz @slush @tropicsquare Diky za odpoved, az budu objednavat urcite se ozvu. Musel jsem se zacit venovat jinemu projektu, ale vazim si Vasi reakce.
Čeština

@fuho @slushcz @slush @tropicsquare Devkit klidne posleme / predame v Praze. Napiste mi na mail klidne naprimo - krystof.jelinek@tropicsquare.com
Vase logika mi dava smysl.
Čeština

8 years from the idea to actual chip in my hand. Thank you @tropicsquare! 💪🥳

Tropic Square 🌴🔲@tropicsquare
Prototype with and evaluate TROPIC01, now with just a click! Secure Tropic Click is now available for purchase on @mikroel. Add this compact add-on to a main board to start designing your open embedded secure system. Order now at: mikroe.com/secure-tropic-… #TROPIC01 #Evaluation #DevelopmentBoard #NewProduct #RootOfTrust
English
fuho retweetledi

@slushcz @slush @tropicsquare 😀 Je to možná trošku specifická hračka, ale pokud to někdo protlačí tak jich pár koupím....a možná dokonce i pro jednou na Alze napíšu hodnocení.
Ale třeba se toho chytne @laska_kit, @rpishop_cz, drátek.cz nebo nějakej jinej hobbytronic shop.
Čeština

@slushcz @slush @tropicsquare Skoda, rikal jsem si ze bych si pro to nekam zajel. Chtel jsem se vyhnout $20 dolarum postovnyho na $9 devkitu, ale zda se ze se mi to nepovede :)
Čeština

@fuho @slush @tropicsquare Vyloženě fyzicky ne. Ale na mikroe.com mají prototypovací boardy na objednání.
Čeština

Taky me to prekvapilo, kdyz jsem slysel ze nekdo v patek sedi v praci, nebo stoji pred pichackama nez preskoci minuta aby mel splnenej cas. Nebo vety typu "dneska tady musim sedet jeste 37 minut protoze v utery jsme zustal dyl na obede", ceskej Google my ass, kdyby lidi videli jak to bezi v US Googlu tak by byla revoluce :D
Čeština

@fuho @Omarovo4000 sileny! A jsem myslel ze zrovna Ivo to bude vest trosku efektivnejsim smerem
Čeština














