Luke Skinner

2.8K posts

Luke Skinner banner
Luke Skinner

Luke Skinner

@CoolHandLukefer

Software Engineer | Guitar | Cooking | History | Philosophy Spiral out. Keep going.

United States Entrou em Temmuz 2022
308 Seguindo352 Seguidores
Luke Skinner
Luke Skinner@CoolHandLukefer·
>be me >oh thats an interesting post >i should go look something up before responding tho >come back to X three minutes later to respond >state refresh nukes post @nikitabier whhhhhhhhhhhy
English
0
0
0
18
Luke Skinner
Luke Skinner@CoolHandLukefer·
disregard ai, acquire skills
English
0
0
0
15
Dovy🔌
Dovy🔌@DovySimuMMA·
Conor McGregor via IG
Dovy🔌 tweet media
Română
46
26
979
74.7K
Luke Skinner
Luke Skinner@CoolHandLukefer·
Are you observing deadlines that actually exist out there in the world? Or are you creating deadlines? One of these approaches produces positive outcomes, and the other is a disaster factory.
English
0
0
0
8
Luke Skinner retweetou
Ryan Fleury
Ryan Fleury@rfleury·
Handmade Hero enjoyers least affected
Ryan Fleury tweet media
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
9
12
443
17.2K
Luke Skinner
Luke Skinner@CoolHandLukefer·
People confusing the production of picks and shovels with gold prospecting. Just because you may be able to produce picks and shovels faster debatable doesn't mean you know where you gold is. Not only has that part not changed, it is and always has been the real bottleneck.
English
0
0
1
19
Luke Skinner
Luke Skinner@CoolHandLukefer·
@rfleury bro you just need another skill.md and also make sure you test it with a second agent and also of course include make no mistakes
English
0
0
0
81
Ryan Fleury
Ryan Fleury@rfleury·
The “programming is over” crowd is going to make sure every experience with a computer is like this
Ryan Fleury@rfleury

English
17
58
1.1K
34.4K
Luke Skinner
Luke Skinner@CoolHandLukefer·
There would be a real, justifiable case for vibecoding if it resulted in more plate appearances for ideas. But I don't see that. I see people building stuff and it taking just as long as before.
English
0
0
1
20
Luke Skinner
Luke Skinner@CoolHandLukefer·
Anyone who has worked at an organization larger than 3 people are familiar with the knowledge gaps that appear when people think they're being clever by outsourcing parts of projects to juice efforts. We've known for a long time that this is why you never outsource core organizational competencies. Yet, that is exactly what is happening with outsourcing to AI, except worse becauase it happens at scale, everywhere, and there's no human to go back to when you need to ask questions to figure out what was actually done. I've not heard anyone provide a viable solution to this problem.
English
0
0
0
15
Luke Skinner
Luke Skinner@CoolHandLukefer·
why are movie synopses like this
Luke Skinner tweet media
English
0
0
0
11
Luke Skinner
Luke Skinner@CoolHandLukefer·
mfs be like "i use Dvorak because im concerned about hand posture"
Luke Skinner tweet media
English
0
0
1
24
Dev
Dev@iDevangOza·
@stats_feed France has held the top spot for 40 years straight, yet it's one of the most complained-about tourist destinations when it comes to service! At this point, Paris is just running a long-term experiment on how rude a country can be while still topping the charts.
English
6
0
8
9.7K
World of Statistics
World of Statistics@stats_feed·
Most Visited Country (Tourism) 1990s: 🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷 2000s: 🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷 2010s: 🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷 2020s: 🇫🇷🇫🇷🇫🇷🇫🇷🇫🇷
English
179
336
16.3K
3.7M
Luke Skinner
Luke Skinner@CoolHandLukefer·
Ten years ago this guy's mom took out a reverse mortgage to fund the development of his parking spot app. Today, he can vibecode it himself. I don't think anyone understands what the future looks like.
Luke Skinner tweet media
English
1
0
1
28