StackWild 🐟

571 posts

StackWild 🐟 banner
StackWild 🐟

StackWild 🐟

@stack_wild

i code stuff

las vegas Katılım Temmuz 2021
5.9K Takip Edilen5.9K Takipçiler
Larry Diffey
Larry Diffey@GrizzledTexan·
@fjzeit I accidentally arrived at a methodology I call Forge so I decided to publish it. Definitely not just vibe coding with guard rails. Check it out. github.com/ArenixDev/forge
English
2
1
2
183
fj
fj@fjzeit·
i wonder how much time and money has been wasted on this vibe coding bullshit that could have been spent focusing on using LLMs to actually improve established practices. even the ones who distance themselves from vibe coding basically did "vibe coding with guardrails" and called it something else...
English
12
0
55
2.2K
StackWild 🐟 retweetledi
Mitchell Hashimoto
Mitchell Hashimoto@mitchellh·
Fork your dependencies, trim them to only your use case, never update unless it breaks for your users. I’ve been vocal about this for 10+ years. I’ve always said that updating is way riskier than latent bugs (which can be tracked and CVEs monitored). If you are updating a dependency, it’s on you to analyze every single commit in the full transitive set of dependencies. If you dont see anything compelling, dont update! I remember at HashiCorp once in awhile an engineer would try to update a dep or replace a DIY lib with an external one and id always ask “show me the commit we need.” Dont update for the sake of it. Feeling pretty swell about this mentality with all the supply chain attacks happening.
English
292
775
9K
1.2M
StackWild 🐟
StackWild 🐟@stack_wild·
Is this even real or am I about to get pwnd? 😨 npm notice New major version of npm available! 10.9.3 -> 11.14.1 npm notice Changelog: github.com/npm/cli/releas… npm notice To update run: npm install -g npm@11.14.1
English
0
0
2
317
StackWild 🐟 retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
International Cyber Digest tweet media
English
139
943
6.4K
1.5M
StackWild 🐟
StackWild 🐟@stack_wild·
That's not X, that's Y with a Z This is the new long dash for detecting AI... and it's like half the posts on this app
English
0
1
2
119
ThePrimeagen
ThePrimeagen@ThePrimeagen·
There are a lot of people dunking on this guy and the arguments at the end of the day come down to "You are holding it wrong." But to be fair there has been nothing but a constant stream of "Stop holding it, Software Engineering is over shortly." I am not shocked that this has happened and I am 100% confident that this is not going to be the last one. The problem is the vogue nature of insane hype claims, most specifically from Dario himself being most guilty. People are lulled into a faux safety due to the belief that these LLMs are literal gods in their pocket. Infinite knowledge and speed for a simple monetary exchange. Cannot wait for ThePhilospher to explain how a loving God could delete a production database.
JER@lifeof_jer

x.com/i/article/2048…

English
105
58
1.5K
317.2K
StackWild 🐟
StackWild 🐟@stack_wild·
@antirez It's a lemon market for comments. No point in posting a peach of a comment in a pile of lemons.
English
0
0
1
125
antirez
antirez@antirez·
I'm very worried for the degrading level of HN comments due to mass-arrival of users over the years. Soon or later, there is something to do about it. The problem with HN is that it does not mimic in any way the social dynamics that determine that you need to earn ability to comment / talk. Voting comments does not work since the voters themselves have quality issues.
English
37
4
144
17.6K
StackWild 🐟 retweetledi
Marcin Krzyzanowski
Marcin Krzyzanowski@krzyzanowskim·
There are 4 types of people saying "AI will replace Software Engineering" in 6 months 1. they own a company that benefits from replacing engineers (ceo, stockholders etc). they need to justify the amount invested into them 2. Company that made big cuts and they want to attribute it to whatever and AI is good excuse 3. People who never worked as as/with Software Engineering and have no clue the work is not just typing 4. Burned out engineers who don't want to do that job anymore
English
128
175
2K
119.2K
StackWild 🐟 retweetledi
RussianPanda 🐼 🇺🇦
RussianPanda 🐼 🇺🇦@RussianPanda9xx·
AI is NOT replacing cybersecurity jobs. Full stop. I'm so tired of people parroting "AI will replace reverse engineers" and "malware analysis is solved". No. It is not. I have analyzed hundreds of malware samples using AI. Here's what actually happens: -> It gives you made-up decryption keys with full confidence -> It tries to decrypt data that is literally random garbage -> It misidentifies malware families -> It misses critical functions And have you ever tried retrohunting with the YARA rules AI writes across thousands of samples? Go ahead. Watch the false positives roll in. That alone should tell you everything you need to know. Every single output needs human validation and rigorous review. AI is a tool, a powerful one. But someone still has to build the MCPs, validate the output, understand the context, catch the hallucinations, and make the actual calls during incident response. The people saying this stuff loudest have clearly never watched AI confidently hand them completely wrong decrypted data and make them believe it's real. Stop scaring newcomers out of the field and misleading people with this nonsense. Cybersecurity still needs humans.
English
79
112
748
56.1K
StackWild 🐟 retweetledi
tetsuo
tetsuo@tetsuoai·
I can't believe someone would just steal from Anthropic like this. The millions of man-hours Anthropic spent hand-writing code, text, art, books, etc. to generate enough data for training must be taken into consideration here. Where is the respect for IP?
Anthropic@AnthropicAI

We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax. These labs created over 24,000 fraudulent accounts and generated over 16 million exchanges with Claude, extracting its capabilities to train and improve their own models.

English
354
978
13.3K
1.2M
StackWild 🐟 retweetledi
StackWild 🐟 retweetledi
harjot.co
harjot.co@harjjotsinghh·
I'll be honest. tRPC changed how I think about APIs more than any course, book, or YouTube tutorial ever did. The moment you stop writing fetch('/api/user') and start calling user.get() like it's just... a function? Your brain rewires. Permanently. If you're still REST-maxxing on a full-stack TypeScript project in 2026, I genuinely feel for you. @trpcio has no business being this clean.
harjot.co tweet media
English
8
1
45
1.4K
StackWild 🐟 retweetledi
forloop
forloop@forloopcodes·
I hate that Microsoft might be vibecoding Windows, but it's inevitable microsoft laid off everyone who knows how c++ works so now they just prompt gpt 5 to fix the codebase. 30% of windows is written by ai. that is why your printer drivers were deleted to make room for 4gb of copilot telemetry they rewrote office in typescript. file explorer and the notification center are now just bloated electron instances that take 3 seconds to render a right click menu the taskbar and start menu were rebuilt from scratch in react just to shove ads and "recommended" bloatware in your face. it uses more ram than world of warcraft did in 2004 copilot is being forced into notepad and paint. they are forcing you to test it in your basic tools windows search isn't looking for your files. it's a bing wrapper designed to sell you a microsoft 365 subscription while you're desperately trying to find a local pdf the widgets section is another bloat that nobody asked for. edge webview was designed to keep your cpu usage high enough that you're forced to switch to linux over all of that, the task manager barely works in the latest updates nobody at microsoft knows what "win32" means anymore. they replaced their support forums with an ai that just tells you to "try restarting" if your kernel panics
forloop tweet mediaforloop tweet mediaforloop tweet mediaforloop tweet media
Elan Ruskin@despair

For that matter, Microsoft Word 2002 used about 25MB of RAM. Now Word uses 10x that much memory to display the same 584kb document. What the heck is it doing to that text now that it wasn't doing before?

English
351
2.6K
19.8K
947.2K
StackWild 🐟 retweetledi
Pedro Domingos
Pedro Domingos@pmddomingos·
It's mind-blowing that the entire AI revolution is being driven by a single 10-line algorithm.
Pedro Domingos tweet media
English
230
639
4.9K
964.9K
StackWild 🐟 retweetledi
Tony Dinh
Tony Dinh@tdinh_me·
Claude: "You're absolutely right!"
Tony Dinh tweet media
English
132
282
3.9K
172.7K
Wise
Wise@trikcode·
Describe your current coding mood with an emoji.
English
168
5
193
17K