Darrien

7.7K posts

Darrien banner
Darrien

Darrien

@meddlin_dev

software engineer, appsec | keep building

Katılım Temmuz 2016
1.8K Takip Edilen222 Takipçiler
Sabitlenmiş Tweet
Darrien
Darrien@meddlin_dev·
keep building
English
0
0
0
2
Darrien
Darrien@meddlin_dev·
@NetworkChuck MacOS. Not Windows because its own updates from the Control Panel caused an irreparable boot loop. And not Linux because I already have a job.
English
0
0
0
53
NetworkChuck
NetworkChuck@NetworkChuck·
Which OS is your daily driver? Why?
English
178
6
125
40.1K
Darrien
Darrien@meddlin_dev·
@mattjay slot machine go brrrrr ...ok, actually I use plan mode and Do My Best (c). Haven't solved that part yet.
English
0
0
0
731
Matt Johansen
Matt Johansen@mattjay·
Everyone using Claude code and/or Codex - how are you enforcing them to not pull in new/potentially malicious packages from npm or PyPi?
English
172
28
529
134.5K
Darrien
Darrien@meddlin_dev·
let it inform you, not worry you. if it worries you, put it down.
English
0
0
0
11
Darrien retweetledi
Socket
Socket@SocketSecurity·
🚨 UPDATE: Mini Shai-Hulud has crossed from @npmjs into @pypi and is still spreading. Newly confirmed compromised artifacts: @​opensearch-project/opensearch: 3.5.3, 3.6.2, 3.7.0, 3.8.0 (1.3M weekly downloads) mistralai: 2.4.6 on PyPI guardrails-ai: 0.10.1 on PyPI additional @​squawk/* packages on npm guardrails-ai 0.10.1 executes malicious code on import. On Linux, it downloads git-tanstack[.]com/transformers.​pyz, writes it to /tmp/transformers.​pyz, and runs it with python3 without integrity verification. The git-tanstack.​com domain displayed a message signed “With Love TeamPCP,” along with: “We've been online over 2 hours now stealing creds Regardless I just came to say hello :^)” The page also linked to a YouTube video and you can probably guess which one.
Socket tweet media
English
62
487
2.3K
960.9K
Darrien retweetledi
Aikido Security
Aikido Security@AikidoSecurity·
Update 5:05 PT: The attack has now expanded well beyond @TanStack and @Mistral. 373 malicious package-version entries across 169 npm package names, including @uipath, @squawk, @tallyui, @beproduct, and more. The malware propagates by stealing your CI credentials and using them to publish new compromised versions. Full IOCs, affected package list, and detection steps: aikido.dev/blog/mini-shai…
Aikido Security@AikidoSecurity

🚨 Update: @mistralai npm packages are now confirmed compromised as part of the ongoing Mini Shai Hulud attack. Affected versions: @mistralai/mistralai 2.2.2, 2.2.3, 2.2.4@mistralai/mistralai-azure 1.7.1, 1.7.2, 1.7.3@mistralai/mistralai-gcp 1.7.1, 1.7.2, 1.7.3If you use the Mistral SDK in any CI pipeline, treat your environment as compromised. Rotate npm tokens, GitHub PATs, and cloud credentials immediately.

English
76
486
2.6K
2.4M
Darrien
Darrien@meddlin_dev·
@ThePrimeagen 6-12 months until we’re back hiring engineers
English
0
0
1
46
Darrien
Darrien@meddlin_dev·
@ThePrimeagen you can lead a horse to water, but no amount of water boarding will force them to drink
English
0
0
1
14
ThePrimeagen
ThePrimeagen@ThePrimeagen·
Coinbase> life's been tough and we are doing well and crypto is great, but conditions are a bit tough. AI is great so we are going to use that to downsize because we are so efficient now Also coinbase>
ThePrimeagen tweet media
English
45
40
1.3K
54.7K
Darrien
Darrien@meddlin_dev·
what's it like in corporate tech these days? you can lead a horse to water, but no amount of water boarding will force them to drink.
English
0
0
1
25
shenetworks
shenetworks@shenetworks·
Honestly now that I have some time off I might start digging a tunnel under my house to see what’s going on down there
English
24
0
333
16.9K
Darrien
Darrien@meddlin_dev·
@ThePrimeagen @theo I need to finally read that book. Perhaps more of work will be more peaceful with that wisdom.
English
0
0
1
553
ThePrimeagen
ThePrimeagen@ThePrimeagen·
As the "other" yt'er in this situation here are my thoughts: C.S.Lewis in Mere Christianity talks about how evil and good compound. To engage in a little of poking will in fact encourage more of that behavior. It's honestly never worth it to engage in these debates because they truly don't matter and they likely multiply destruction in your heart as opposed to good. So I really wouldn't worry about it, the guy feels a way and it's his right to feel that way and well, no skin off my back. Cheers
English
13
7
516
16.2K
Theo - t3.gg
Theo - t3.gg@theo·
“It’s not about being right or wrong” Every time you corner one of these “YouTubers are dumb” people their brains fall out
Theo - t3.gg tweet media
English
47
3
372
46.1K
Elon Musk
Elon Musk@elonmusk·
Your AI hates Whites & Asians, especially Chinese, heterosexuals and men. This is misanthropic and evil. Fix it. Frankly, I don’t think there is anything you can do to escape the inevitable irony of Anthropic ending up being Misanthropic. You were doomed to this fate when you chose your name. The Name of the Wind.
English
2.6K
3K
47.3K
3.7M
Anthropic
Anthropic@AnthropicAI·
We’ve raised $30B in funding at a $380B post-money valuation. This investment will help us deepen our research, continue to innovate in products, and ensure we have the resources to power our infrastructure expansion as we make Claude available everywhere our customers are.
English
1.1K
1K
16.9K
7.2M
Darrien
Darrien@meddlin_dev·
@shenetworks @InfoSecSherpa The heck?! That’s messed up! Wish I could do more; reposting here. Good luck, and good on you!
English
0
0
0
744
Darrien retweetledi
shenetworks
shenetworks@shenetworks·
After not receiving a raise in the four years I’ve worked at BHIS they’ve now decided to reduce my pay by $40k after coming back from maternity leave and moving my role to solely pentesting. So I am looking for a new position effective immediately if anyone has any leads 😇
English
176
270
1.9K
291.2K
Darrien
Darrien@meddlin_dev·
@AdamRackis A surprising amount of CEOs, startup founders, and shareholders seem to think “production code” means it’s good. Calling it “production” doesn’t make it worth shipping.
English
0
0
2
515
Darrien
Darrien@meddlin_dev·
@ThePrimeagen “one person teams” There is no “I” in team, but it’s right there in stupid.
English
0
0
0
136
ThePrimeagen
ThePrimeagen@ThePrimeagen·
"Non technical teams shipping production code" - coinbase
Brian Armstrong@brian_armstrong

This is an email I sent earlier today to all employees at Coinbase: Team, Today I’ve made the difficult decision to reduce the size of Coinbase by ~14%. I want to walk you through why we're doing this now, what it means for those affected, and how this positions us for the future. Why now Two forces are converging at the same time. We need to be front footed to respond to both. First, the market. Coinbase is well-capitalized, has diversified revenue streams, and is well-positioned to weather any storm. Crypto is also on the verge of the next wave of adoption, with stablecoins, prediction markets, tokenization, and more taking off. However, our business is still volatile from quarter to quarter. While we've managed through that cyclicality many times before and come out stronger on the other side, we’re currently in a down market and need to adjust our cost structure now so that we emerge from this period leaner, faster, and more efficient for our next phase of growth. Second, AI is changing how we work. Over the past year, I’ve watched engineers use AI to ship in days what used to take a team weeks. Non-technical teams are now shipping production code and many of our workflows are being automated. The pace of what's possible with a small, focused team has changed dramatically, and it's accelerating every day. All of this has led us to an inflection point, not just for Coinbase, but for every company. The biggest risk now is not taking action. We are adjusting early and deliberately to rebuild Coinbase to be lean, fast, and AI-native. We need to return to the speed and focus of our startup founding, with AI at our core. What this means To get there, we are not just reducing headcount and cutting costs, we’re fundamentally changing how we operate: rebuilding Coinbase as an intelligence, with humans around the edge aligning it. What does this mean in practice? - Fewer layers, faster decisions: We are flattening our org structure to 5 layers max below CEO/COO. Layers slow things down and create coordination tax. The future is small, high context teams that can move quickly. Leaders will own much more, with as many as 15+ direct reports. Fewer layers also means a leaner cost structure that is built to perform through all market cycles. - No pure managers: Every leader at Coinbase must also be a strong and active individual contributor. Managers should be like player-coaches, getting their hands dirty alongside their teams. - AI-native pods: We’ll be concentrating around AI-native talent who can manage fleets of agents to drive outsized impact. We’ll also be experimenting with reduced pod sizes, including “one person teams” with engineers, designers, and product managers all in one role. In short: AI is bringing a profound shift in how companies operate, and we’re reshaping Coinbase to lead in this new era. This is a new way of working, and we need to leverage AI across every facet of our jobs. To those who are affected I know there are real people behind these decisions — talented colleagues who have poured themselves into this company and our mission. To those of you who will be leaving: thank you. You’ve helped build Coinbase into what it is today, and I am sincerely grateful for everything you've done. All impacted team members will receive an email to their personal account in the next hour with more information, and an invitation to meet with an HRBP and a senior leader in your organization. Coinbase system access has been removed today. I know this feels sudden and harsh, but it is the only responsible choice given our duty to protect customer information. To those affected, we will be providing a comprehensive package to support you through this transition. US employees will receive a minimum of 16 weeks base pay (plus 2 weeks per year worked), their next equity vest, and 6 months of COBRA. Employees on a work visa will get extra transition support. Those outside of the US will receive similar support, based on local factors and subject to any consultation requirements. Coinbase prides itself on talent density. Our employees are among the most talented people in the world, and I have no doubt that your skills and experience will be highly sought after as you pursue your next chapters. How we move forward To the team that is staying, I know this is a difficult day. We’re saying goodbye to colleagues and friends you've been in the trenches with. But here’s what I want you to know as we move forward together: Over the past 13 years, we have weathered four crypto winters, gone public, and built the most trusted platform in our industry. We’ve made it this far by making hard decisions and by always staying focused on our mission. This time will be no different – nothing has changed about the long term outlook of our company or industry. And most importantly, our mission has never been more important for the world. Increasing economic freedom requires a new financial system, and we’re building it. The Coinbase that emerges from this will be more capable than ever to achieve our mission. Brian

English
438
495
11.1K
954K
Darrien retweetledi
Catherine Yeo
Catherine Yeo@catherinehyeo·
Love seeing Naomi Osaka honor the CLRS Algorithms textbook at this year's Met Gala
Catherine Yeo tweet mediaCatherine Yeo tweet media
English
111
1.7K
18.2K
610.4K
Darrien retweetledi
LaurieWired
LaurieWired@lauriewired·
There’s a famous Usenet story about a programmer (Mel) who refused higher level abstractions. It was the late 1950s, and even in that era, Mel was…well today we’d call him a boomer. Mel only wrote in raw hexadecimal. He didn’t approve of compilers, and refused to use optimizing assemblers. "You never know where it's going to put things”, he said. Everyone else in the company was moving on to FORTRAN, and they didn’t understand why Mel was so stubborn about using new tools. He *loved* self-modifying code. “If a program can’t rewrite its own code”, he asked, “what good is it?” Mel eventually left the company, and other engineers were tasked with understanding what was left. Mel’s hand-optimized routines always beat the assemblers; but some of it looked absolutely bizarre. One engineer took ~2 weeks to understand why there were loops with no exit condition…yet the program worked fine. I won’t spoil all the details, you should really read it, it’s short. But it’s a fantastic piece on “what defines a real programmer?”…which is becoming increasingly relevant in this vibe-coded era. I strive to understand computers as deeply as Mel! If we aren’t careful, we’re going to lose the “Mels” of this world to time. That’s part of why I go so deep in my youtube videos. I hope that younger viewers are genuinely fascinated by the inner workings of our machines, instead of handing everything off to higher abstractions.
solst/ICE of Astarte@IceSolst

Interesting article on treating agent output like compiler output (and why) skiplabs.io/blog/codegen_a…

English
200
723
8.8K
583.6K