KSE

5.9K posts

KSE banner
KSE

KSE

@semanticbeeng

Shipping/bridging Engineering ⇆ Science #SoftwareArchitecture #FunctionalProgramming #MachineLearning #BigData #MachineLearningEngineering #CompilerDesign

Europe Katılım Eylül 2011
765 Takip Edilen781 Takipçiler
Sabitlenmiş Tweet
KSE
KSE@semanticbeeng·
@sapinker Too much world knowledge is trapped in presentation media (video, html. pdf, paper, etc) as opposed to being concept mapped, interlinked, addressable and reusable at fine grained levels. Defeats bridge between #AI and human cognition.
English
6
11
62
0
Activeloop
Activeloop@activeloop·
How Hivemind turns Hermes runs into a compounding asset: • Every run gets traced (tools, files, outcomes) • Successful traces get promoted to skills • Next session loads them automatically Continual learning now Open Source for Claude Code, Codex, Cursor, Hermes, Pi.
English
13
23
168
380.3K
KSE
KSE@semanticbeeng·
@grok @AudaciousChick @Support @GrapheneOS "In summary, GrapheneOS attestation is more robust and flexible for those willing to implement it properly, while Play Integrity is a "good enough" centralized shortcut that favors Google’s ecosystem."
KSE tweet media
English
0
0
0
26
🌷A Chick🌷
🌷A Chick🌷@AudaciousChick·
@grok @Support I have @GrapheneOS as my operating system on my Pixel and unfortunately the new update has broken my standalone Grok app. Please stop banning GrapheneOS, which is a much more secure OS than Android or Apple. Apps can use the standard Android hardware attestation API to verify the hardware, OS and app with GrapheneOS. TY!
English
1
0
0
79
KSE retweetledi
GrapheneOS
GrapheneOS@GrapheneOS·
We provide a guide for app developers on moving away from the Play Integrity API to the standard Android hardware attestation API to permit GrapheneOS at grapheneos.org/articles/attes…. It can also be used to permit other operating systems. We plan to update and overhaul our guide soon.
English
1
3
46
1.7K
KSE
KSE@semanticbeeng·
KSE tweet media
Juraj Bednar@jurbed

Hey @X Can we either not require app attestation for paying (subscription) users or support @GrapheneOS attestation, which provides the same (or actually better) integrity guarantees than Play Integrity API? We want to play fair, we can, but we also like Grapheneos instead of stock Android. I'm sure you can vibe code this in less than an hour. Guide: grapheneos.org/articles/attes… There's even an open source version. Sincerely, your paying customers being locked out of the service because they chose a better OS.

0
0
0
5
Guardsquare
Guardsquare@Guardsquare·
We are announcing a new product capability empowering organizations to achieve the highest level of mobile app protection in the easiest possible way. Want to apply the maximum amount of protection - without compromise - in less than 1 day? Learn more: hubs.la/Q02QNx2f0
English
5
5
29
42.6K
KSE
KSE@semanticbeeng·
GrapheneOS@GrapheneOS

Unified Attestation is another anti-competitive system being pushed by multiple European companies. It will similarly lock people out from using arbitrary hardware and software. That's not a solution and is far worse than Android's much more open hardware attestation API. x.com/GrapheneOS/sta… Android's hardware attestation shouldn't be used to lock out users not using specific hardware or OSes. However, the fact that it permits arbitrary roots of trust and OSes at least allows services to permit more. Google could use it to permit GrapheneOS for Play Integrity if that was about security.

English
0
0
0
5
KSE
KSE@semanticbeeng·
@haider1 "AI-generated code" is the new "outsourcing" But AI can be used for the entire SDLC - business domain, design domain, planning, coding - to empower teams in unique ways.
English
0
0
0
403
Haider.
Haider.@haider1·
Creator of C++, Bjarne Stroustrup: AI-generated code isn't ready — it generates more bugs, more bloat, more security holes, and is nearly impossible to validate "senior developers are already retiring rather than deal with it" The problem is that even a small prompt change can shift the entire codebase in unpredictable ways
English
623
2K
10.6K
1.7M
KSE
KSE@semanticbeeng·
@atomic_chat_hq Grok says "The dedicated on-device LLM code is not included in the public GitHub repository. " So the on-device LLM code is not OSS, right?
KSE tweet media
English
0
0
1
46
atomic.chat
atomic.chat@atomic_chat_hq·
Multi-Token Prediction (MTP) for Qwen on LLaMA.cpp! +40% performance! 90% acceptance rate. Running locally on a MacBook Pro M5 Max 64GB We patched LLaMA.cpp, quantized Qwen 3.6 27B into GGUF format with TurboQuant and shipped MTP drafts on top. Benchmark, Source code & models👇
English
18
29
267
49.9K
KSE
KSE@semanticbeeng·
@The_Cyber_News use Infisical ephemeral SSH certificates x.com/dangtony98/sta…
Tony Dang@dangtony98

Introducing @infisical SSH — The simplest way to manage SSH access across your team and infrastructure! Infisical SSH eliminates the need for you to manage SSH keys in favor of short-lived SSH certificates issued on demand. From one dashboard, you define which users should have access to which machines and let Infisical facilitate connections using SSH certificate-based authentication under the hood. With just a few clicks, you can bootstrap the same secure, scalable SSH certificate-based authentication scheme that companies like Meta, Uber, and Google use to scale SSH access across their infrastructure.

Español
0
0
0
1.2K
Cyber Security News
Cyber Security News@The_Cyber_News·
⚠️ Critical Linux Kernel Flaw ‘ssh-keysign-pwn’ Exposes SSH Keys and Shadow Passwords Source: cybersecuritynews.com/linux-kernel-v… A newly disclosed Linux kernel vulnerability is raising serious concerns across the security community, as it allows attackers to access highly sensitive data, including SSH private keys and password hashes, on affected systems. Tracked as CVE-2026-46333, the flaw has been nicknamed “ssh-keysign-pwn” and impacts a wide range of Linux distributions. The GitHub PoC ssh-keysign-pwn demonstrates exactly how to weaponize this race condition on pre‑31e62c2ebbfd kernels. #cybersecuritynews #Linux
GIF
English
15
206
682
47.8K
KSE retweetledi
Chutes
Chutes@chutes_ai·
You can now run frontier AI models where not even the gpu provider can see your data. 15+ models with hardware-enforced privacy (TEE) on Chutes. No other open-source inference provider offers this. Here's the full lineup and why it matters ↓
Chutes tweet media
English
15
60
302
40.6K
KSE
KSE@semanticbeeng·
@IntCyberDigest > "Because Flox and Nix guarantee reproducible outputs, fixing a CVE is as easy as locating the dependency in manifest.lock, adjusting manifest.toml and re-locking it, rebuilding, and then redeploying to any affected environments" flox.dev/blog/achieving… /cc @floxdevelopment
English
0
0
2
935
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
139
953
6.4K
1.5M
Flox
Flox@floxdevelopment·
Security and compliance work often comes down to certifying system state by reconstructing from scattered clues: scans, SBOMs, build records, tickets, cloud inventory, Kubernetes data. That is not a diligence problem. It is a delivery-system problem. Secure software by construction means the runtime environment carries provenance, traceability, and auditability from build to production. This changes the basis of proof, eliminating guesswork with versioned, reproducible, auditable environments across the SDLC. Read more about it here: buff.ly/5uhP9hm
Flox tweet media
English
1
0
0
128
KSE
KSE@semanticbeeng·
@adelbucetta @techwith_ram "manage data fragmentation" and fusion across the tech stack. And this is about similarity measures. When dealing with many kinds of data - graph, text, images, time series - similarity becomes tricky. And it is often domain specific or even application & task specific.
English
0
0
0
22
Adel Bucetta
Adel Bucetta@adelbucetta·
@techwith_ram the honest answer is, the real problem isn't even which db you choose, it's how you manage data fragmentation across your stack. vector dbs for embeddings are just the tip of the iceberg
English
2
0
8
463
𝗿𝗮𝗺𝗮𝗸𝗿𝘂𝘀𝗵𝗻𝗮— 𝗲/𝗮𝗰𝗰
Your AI stack has a database problem You need a vector DB for embeddings. A graph DB for relationships. An application DB for structured data. An application layer to stitch them together. → Pinecone Standard: $70 a month → Neo4j AuraDB Professional: $65 a month → Postgres RDS: $50+ a month → Engineering time to wire it all together: priceless Three databases. Three schemas. Three failure points. And a RAG pipeline that still hallucinates because your chunks have no context about each other. Then two college dropouts in London shipped one database that replaces all three. It is called HelixDB. Built from scratch in Rust. Open-source. AGPL-3.0 licensed. Self-hosted. Backed by Y Combinator. Not three databases duct-taped together with application code. One engine where graph and vector live in the same data model. Your embedding knows its neighbors. Your neighbors know their embeddings. Everything connected, everything queryable, one system. The founders are George Curtis and Xavier Cochran. They started HelixDB in college after struggling with the complexity of graph databases. No credentials. No prior exits. They attracted developers from X and engineers at United Healthcare before they ever left campus. Then they dropped out, moved to San Francisco, and got into Y Combinator. 2 founders. 6 people. One database that replaces three. Here is what it does: → Graph + vector in a single engine: no join between two systems, ever → HelixQL, a strongly typed compiled query language — safer than Cypher, faster than Gremlin → Built-in vector search, keyword search, and graph traversal: power any RAG pipeline → Auto-embed with one function call: no pre-processing pipeline before ingestion → Built-in MCP support: your AI agents walk the graph, no query generation needed → KV, document, and relational data supported alongside graph and vector → Private-by-default: authenticated query access out of the box → SDKs in TypeScript, Python, and Go: one install, one client → Helix Enterprise on S3-compatible object storage — stateless nodes, horizontal scale ~4,000 stars. AGPL-3.0 licensed. Billions of queries executed. Y Combinator W25. Generally available as of 2026. Used by indie hackers and Fortune 500 teams.
𝗿𝗮𝗺𝗮𝗸𝗿𝘂𝘀𝗵𝗻𝗮— 𝗲/𝗮𝗰𝗰 tweet media
English
12
23
183
12.4K
KSE retweetledi
Determinate Systems
Determinate Systems@DeterminateSys·
Today we're thrilled to announce the launch of our newest offering: Determinate Secure Packages. A drop-in replacement for Nixpkgs, it offers secure, signed, auditable Nix packages for the enterprise, including CVE monitoring and SLA-backed remediation, per-release SBOMs, optional FIPS-compliant builds, packages cached in FlakeHub Cache, cryptographic signing, and more. Link in thread 🔗🧵👇
English
1
4
25
4.7K