gsbonnet

2.4K posts

gsbonnet banner
gsbonnet

gsbonnet

@gsbonnet

Strong sense of urgency Building https://t.co/vV8A5ghz7B - https://t.co/sLZzKVWtna - https://t.co/SpUAP6iWCM - https://t.co/oq4J18Ghhp Not sure if my laptop serves me or vice versa.

Katılım Ağustos 2013
313 Takip Edilen351 Takipçiler
gsbonnet
gsbonnet@gsbonnet·
@marclou yeah but the hardest part is breaking the silence when you're in a cave, trying to make yourself heard
English
0
0
0
19
Marc Lou
Marc Lou@marclou·
There's something magical about digital products. You build once, and it works forever. Every day... - dozens of founders list their startups for sale - hundreds of messages from buyers are sent - millions of pageviews are stored in my database I can be sleeping or at the gym; the shop is open 24/7.
English
146
22
566
33.5K
gsbonnet
gsbonnet@gsbonnet·
idea: a git for writers
English
0
0
0
12
gsbonnet
gsbonnet@gsbonnet·
just finished to rebuild Internet Book Project because I wanted something more like git to write stories online (crowd-written). Idea: anyone can write and contribute to an open book
gsbonnet tweet media
English
0
0
0
24
gsbonnet
gsbonnet@gsbonnet·
It feels so good when your AI security newsletter is so powerful that it properly summarises what you need to know from the IT security space for the last few days. Filtering the noise was a struggle, now fixed. Let’s see how to accelerate the news delivery now.
gsbonnet tweet media
English
1
0
0
21
gsbonnet retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.4K
5.4K
28K
66.4M
jack friks
jack friks@jackfriks·
okay i bought it. now i try for 1 week and if i dont love it ill return it
jack friks tweet media
Oliur@UltraLinx

@jackfriks Think about all of the mental energy you’re spending making this decision. And all of the tweets. Just buy the monitor. It will literally help you be more productive.

English
104
2
545
96.1K
gsbonnet
gsbonnet@gsbonnet·
@joni_vrbt By reading the comments I am wondering if we’re living in the same world?
English
0
0
0
27
Jonathan
Jonathan@joni_vrbt·
Name a tech company that has literally zero haters
English
489
4
402
63.4K
gsbonnet
gsbonnet@gsbonnet·
Do you think there are still some guys out there coding without AI? Like, still looking on Stack Overflow for debugging Googling error codes Reading docs to understand how to use a library? I'm genuinely asking
English
0
0
0
12
gsbonnet
gsbonnet@gsbonnet·
@nikitabier define spamming is multiple posting considered as spamming?
English
0
0
0
5
Nikita Bier
Nikita Bier@nikitabier·
The financial incentive to spam on X will decline enormously over the next 30 days and soon be negative.
English
4.8K
2.2K
38.7K
3.3M
gsbonnet
gsbonnet@gsbonnet·
@elonmusk Elon is basically explaining the stocks play you should have
English
0
0
1
6
Elon Musk
Elon Musk@elonmusk·
Matter, Energy & Intelligence
English
12.6K
12.2K
108.1K
53.9M
Anna Lux
Anna Lux@theannalux·
Classic inflation @1Password increases their price by 37%!! Jesus
Anna Lux tweet media
English
24
1
40
23.3K
gsbonnet
gsbonnet@gsbonnet·
Alimentary job is unfortunately very real and difficult to quit once you’re in, and cost of living are getting so high that without your salary increasing you’re basically shifted to a lower range in the class pyramid, every year a bit more Then you survive during 45y I do agree to exit, but it’s not so easy
English
0
0
0
235
gsbonnet
gsbonnet@gsbonnet·
hey @elonmusk / @nikitabier, can we have the possibility to mute the em dash please? currently it is not possible
gsbonnet tweet media
English
1
0
0
33
gsbonnet
gsbonnet@gsbonnet·
Vibe-coding allows you to live the dream, like zuck did, but without Anthropic Legend
GIF
English
0
0
0
24
gsbonnet
gsbonnet@gsbonnet·
Claude Code is dead and just discovered I have a wife in the living room
English
0
1
2
167