mrdanack.bsky.social

17.2K posts

mrdanack.bsky.social banner
mrdanack.bsky.social

mrdanack.bsky.social

@MrDanack

Maintainer of the PHP Imagick extension. Has a gurt beard. He/him. aka https://t.co/n0msPZAUM0

เข้าร่วม Eylül 2010
771 กำลังติดตาม972 ผู้ติดตาม
ทวีตที่ปักหมุด
mrdanack.bsky.social
mrdanack.bsky.social@MrDanack·
Apropos of everything; I have strong feelings about how sponsorship levels are described. Too many maintainers are asking for people to 'buy a coffee' or 'show you're a fan'. This is folksy nonsense that suggests that individuals are those who should be sponsoring open source.
English
2
4
21
0
mrdanack.bsky.social รีทวีตแล้ว
Luis Garicano 🇪🇺🇺🇦
An increasingly coherent picture of the impact of AI on jobs, by @jburnmurdoch @ft: 1. New Fed paper by Crane and Soto now confirms with official labor force survey data what private payroll analysis was showing: roughly 500,000 fewer coders are working than pre-LLM trends would predict. 2. Argues evidence consistent with my work (with Lin and Wu, link in my pinned post) on weak/strong bundles: junior developers and contractors hold "weak bundles" (their work is mostly standalone coding that AI can substitute directly), senior developers hold "tight bundles" where coding is combined with domain expertise, judgment, and cross-functional responsibilities, making substitution much harder. 3. Freund & Mann and Gans & Goldfarb add a second lens: what matters is the value of the tasks that survive automation. Remove coding from a senior role and you free up time for higher-value work; remove it from a junior role and almost nothing remains. ft.com/content/b69f85…
Luis Garicano 🇪🇺🇺🇦 tweet media
English
29
254
1K
241.1K
Chris Anderson
Chris Anderson@chr1sa·
This is what the novel Ministry of the Future got wrong, with its horrifying "wet-bulb" event in India, where the grid goes down and air conditioning becomes unavailable, letting heat kill a million people. Now in places with fragile grids, people are taking matters into their own hands with cheap distributed solar. Democratizing technology leads to self-reliance.
Rami SD@SyrianShabab

This is the Al-Furqan neighbourhood in Aleppo—the number of solar panels is genuinely impressive.

English
45
253
3.2K
458K
mrdanack.bsky.social รีทวีตแล้ว
john lindsell
john lindsell@jonnycaribouthe·
"Labour voters leaving to join the Green party sir, thousands of them."
john lindsell tweet media
English
0
2
5
105
mrdanack.bsky.social
mrdanack.bsky.social@MrDanack·
@OdessaBlogger Dumbest timeline: Trump cuts off diplomatic relations with the EU when it fails to recognise Orbán's "re-election".
GIF
English
0
0
0
10
Nikolai Holmov
Nikolai Holmov@OdessaBlogger·
Hopefully the usual trend of "everything Trump touches turns to shit" will follow from this message:
Nikolai Holmov tweet media
English
1
0
3
105
mrdanack.bsky.social รีทวีตแล้ว
Collingwood 🇬🇧
Collingwood 🇬🇧@admcollingwood·
I always weep reading the Wikipedia pages of senior Singaporean politicians. The general career path seems to be: Excel at school and secure a scholarship to study some super difficult subject, like maths or physics, at Cambridge University. Excel at university and get a scholarship to do a post-grad degree in governance or an MBA at Harvard. Join the Singaporean military and excel. Reach at least the rank of Brigadier or General. Enter politics. Excel even compared with others who have similar CVs, rise to become a senior position. Compare that with the career path of the average senior British politican. Get the same results as every other middle class child at school. Do PPE or straight up politics at university. Leverage your contacts to become a SPAD for a cabinet or shadow cabinet member. Get a column writing gig at the Spectator, Economist or New Statesman Become a more senior SPAD. Run in an impossible to win seat to prove you really want to be in parliament. Get parachuted into a safe seat as a rising star. Get a junior ministerial position in the first reshuffle after the election. Get made a cabinet member after the next election. Now, why is Singapore an extremely well run country and we are not?
English
227
907
7.1K
792.1K
mrdanack.bsky.social รีทวีตแล้ว
mrdanack.bsky.social รีทวีตแล้ว
Ahmad Nassri
Ahmad Nassri@AhmadNassri·
"The people maintaining that infrastructure are mostly unpaid. When they get targeted by nation-state actors, the answer should be to fund, support, and protect them, not warn enterprises away from their packages so you can sell a replacement." 💯💯💯 #goosonomics🪿
Feross@feross

Chainguard's CEO published a post this week arguing that scanners are "working against an adversary that's already beaten them" and that "the Axios attack was pulled hundreds of thousands of times before a single scanner flagged it." This is factually incorrect. Here's the timeline, all publicly verifiable: plain-crypto-js@4.2.1, the malicious payload, was published to npm on March 30 at 23:59 UTC. @SocketSecurity AI flagged it as malicious at 00:05 UTC. Six minutes. The first compromised Axios version wasn't published until 00:21 UTC, 16 minutes after we'd already flagged the attack. All this version did was add a dependency on the package we'd already caught. Socket customers with AI malware blocking enabled had installs blocked automatically during the entire three-hour exposure window. No CVE required. No luck required. This was independently corroborated by Snyk, Huntress, Orca Security, and InfoQ each of whom published their own analyses of the attack. Calling scanning "theater" while getting the facts of the year's biggest scanning success story wrong doesn't strengthen the argument. Scanners and hardened images aren't competing answers. They're complementary layers. The industry needs both. I agree with part of the post's broader argument. The trust model for open source consumption needs work. I've been maintaining npm packages with billions of cumulative downloads for over a decade. I know what's broken. But you don't fix the trust model by dismissing the defenders who are actually catching attacks and protecting the community. When we catch a malicious package, we report it to the registry and get it taken down. That protects every developer, not just our customers. Their proposed alternative, rebuilding packages from source, doesn't address the attacks that actually matter. The Axios attack was a maintainer account compromise that poisoned the source. xz-utils was a malicious maintainer who spent two years building trust and poisoned the source. Building from source just rebuilds these attacks faithfully. The most consequential supply chain attacks walk right through this model. Building from source doesn't stop bad source. And you don't fix this problem by declaring open source dead while your company's entire product is built on top of it. A Harvard study estimated the demand-side value of widely used open source at $8.8 trillion. The people maintaining that infrastructure are mostly unpaid. When they get targeted by nation-state actors, the answer should be to fund, support, and protect them, not warn enterprises away from their packages so you can sell a replacement. Open source is under attack because of how much value it creates. That's an argument for investing in it, not writing its obituary. Back to building.

English
0
3
7
2.3K
ブリティッシュ英語 🇬🇧 イギリス英語の学校
今日のイギリス英語:I’m not being funny but… 意味:ちょっと失礼かもしれないけど、。。。 (相手が気分を悪くするかもしれないことを言う前の前置きとして使われます。) I’m not being funny, but that’s a bit expensive. (ちょっと失礼かもしれないけど、それは少し高いよ。)
ブリティッシュ英語 🇬🇧 イギリス英語の学校 tweet mediaブリティッシュ英語 🇬🇧 イギリス英語の学校 tweet media
日本語
8
11
162
13.4K
Flying_Rodent
Flying_Rodent@flying_rodent·
And all they wanted for these magic beans was one cow? What a bargain
Flying_Rodent tweet media
English
8
22
114
8.6K
Flying_Rodent
Flying_Rodent@flying_rodent·
Yes, “spend decades screaming allegations of treason at your rivals, then absent-mindedly hand over decision-making to foreign tech companies, because you are basically groupies for the rich and powerful awestruck with admiration” would be exactly on-brand removepaywall.com/search?url=htt…
English
3
10
94
6K
The Labour Party
The Labour Party@UKLabour·
Where they’re in power, Green councils are backing out of their housing pledges entirely. In Bristol, the Green administration pulled its affordable housing targets earlier this year.
English
19
53
283
36.9K
The Labour Party
The Labour Party@UKLabour·
The Green Party want you to think that they care about housing. But here’s the facts that Zack Polanski would rather you ignore.
English
589
164
935
379.7K
mrdanack.bsky.social
@mattrickard I don't use it often, but the fork conversation button in Cursor is pretty useful when a bad path has been taken.
English
0
0
0
56
Matt Rickard
Matt Rickard@mattrickard·
does anyone have this problem? if an agent makes a wrong turn, that context is essentially poisoned. even if you correct it, it seems to anchor onto its mistake. best to start a new thread
English
6
0
7
797
mrdanack.bsky.social รีทวีตแล้ว
David Brady Jr.
David Brady Jr.@realDavidBJr·
"The ceasefire conditions, which I am sure the President has read..."
David Brady Jr. tweet media
English
25
772
11.1K
135.1K