Henry AT

639 posts

Henry AT banner
Henry AT

Henry AT

@yiperu

Software Engineer, interested in Mobile Applications, IoT and ML

Chile Katılım Haziran 2012
980 Takip Edilen159 Takipçiler
Henry AT retweetledi
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.2K
5K
26.1K
54.4M
Henry AT retweetledi
Dhairya
Dhairya@dkare1009·
MIT offers 12 Books on AI & ML (FREE TO DOWNLOAD): 1. Foundations of Machine Learning cs.nyu.edu/~mohri/mlbook/ 2. Understanding Deep Learning udlbook.github.io/udlbook/ 3. Algorithms for ML algorithmsbook.com 4. Reinforcement Learning andrew.cmu.edu/course/10-703/... 5. Introduction to Machine Learning Systems mlsysbook.ai/book/assets/do… 6. Deep Learning deeplearningbook.org 7. Distributional Reinforcement Learning direct.mit.edu/books/oa-monog… 8. Multi Agent Reinforcement Learning marl-book.com 9. Agents in the Long Game of AI direct.mit.edu/books/oa-monog… 10. Fairness and Machine Learning fairmlbook.org 11. Probabilistic Machine Learning ❯ Part 1 : probml.github.io/pml-book/book1… ❯ Part 2 : probml.github.io/pml-book/book2
Dhairya tweet media
English
14
457
1.4K
64.2K
Henry AT
Henry AT@yiperu·
@Frospigliosi Jajajaja, pasaras a la historia como el personaje mas Incongruente, incoherente, discordante, inconsistente, disonante mejor ser disparatado 😂 🤣.
Español
0
0
0
3
Fernando Rospigliosi
Fernando Rospigliosi@Frospigliosi·
Condolencias a la familia del presidente Alberto Fujimori. Luchó con férrea voluntad, hasta el final de su vida, por lo que creyó necesario para mejorar la vida de los peruanos. (Con AFF el 15/1/24).
Fernando Rospigliosi tweet media
Español
690
305
1.9K
147K
Henry AT retweetledi
Alex Febrero
Alex Febrero@AlexFebrero_·
Mientras nosotros dormíamos muy cómodos, los familiares de las víctimas de la represión de Dina Boluarte, han hecho vigilia frente al Palacio de Justicia durante 2 días seguidos en el suelo. Aguantaron el frío, el maltrato, la injusticia y siguen luchando. ¡Ni olvido, ni perdón!
Español
441
589
1.3K
39.3K
Henry AT
Henry AT@yiperu·
segundo 25, Amelancolizar 🥹
Português
0
0
0
19
Henry AT retweetledi
Víctor García Guerrero
Víctor García Guerrero@VictorGGuerrero·
El niño carga agua en un carrito de bebé. Alguien grita entre las ruinas, el gato escapa y los drones acechan. El apocalipsis en Gaza no es una película.
Español
46
1.2K
1.1K
100.8K
OjoPúblico
OjoPúblico@Ojo_Publico·
#11D A un año de su muerte, la familia de David Atequipa —adolescente de 15 años que falleció tras el impacto de un proyectil de arma de fuego en #Andahuaylas— vela sus fotos en su casa, junto con otros deudos de la represión a las protestas. 📹✍️Red Regional OjoPúblico / @arivme
Español
54
772
1.3K
174.7K
Henry AT
Henry AT@yiperu·
This is going to revolutionize the way we interact with the world. With you "AI Pin"
English
0
0
0
31
Henry AT retweetledi
Daily Loud
Daily Loud@DailyLoud·
UPDATE: Jay-Z is officially back on Instagram. Both him and his wife Beyoncé only follow each other 👀❤️
Daily Loud tweet mediaDaily Loud tweet media
English
1.2K
1.9K
56.3K
13.3M
Toan Truong
Toan Truong@ToanTruong_·
11 years ago, @Stanford created a 5 parts series to help students study more efficiently. It got over 3,000,000 views and helped 10000s of students. The series is hard to find on YouTube, so I've compiled it for you. 1. Like + Comment "learn" 2. Follow me @LearningToan And I will DM you.
Toan Truong tweet media
English
355
36
534
99.1K
Henry AT retweetledi
Charly Wargnier
Charly Wargnier@DataChaz·
Here are the 10 #ChatGPT plugins currently available in the @OpenAI Plugin Store: 1 - Speak 2 - Shop 3 - Expedia 4 - Zapier 5 - Wolfram 6 - Milo Family AI 7 - Instacart 8 - Klarna Shopping 9 - Kayak 10 - OpenTable ↓
English
3
18
126
27.7K
Julio César Fernández 
Por favor... estoy al borde del colapso. iCloud Drive me ha recreado mi carpeta de Keynote porque sí, sin yo pedir nada, y he perdido TODOS mis archivos de formaciones, presentaciones... El trabajo de varios años. Y no hay nada en los Time Machine. ¿Alguien que me pueda ayudar?
Español
22
13
27
0
Henry AT retweetledi
Ben Phillips
Ben Phillips@benphillips76·
A clip from Don’t Look Up, and then a real TV interview that just happened
English
5.6K
184.5K
756.8K
0