Ilya Lichtenstein

493 posts

Ilya Lichtenstein

Ilya Lichtenstein

@cipherstein

Former hacker, now builder. Razzlekhan's husband.

New York, NY เข้าร่วม Kasım 2010
161 กำลังติดตาม1.9K ผู้ติดตาม
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
axios is the most popular http client in the JavaScript ecosystem. If your app uses an API, connects to a web server, or does anything on the Internet it's probably compromised.
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
0
0
0
154
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
@MParakhin Coding models are not trained just on school essays, they are trained on real code...
English
1
0
0
372
Mikhail Parakhin
Mikhail Parakhin@MParakhin·
In pre-training models mostly see text. Humans value longer, more flowery essays (remember school page requirements?), the models learn that. It is genuinely hard to make them produce concise code. My trick is to use long thinking and add “produce tightest, minimal, most elegant code possible” to every prompt - it forces the model to iteratively simplify. In this case, the human’s code (on the right) is less efficient, ironically :-)
Dmitrii Kovanikov@ChShersh

Same C++ function. One is generated with AI. The other one is written manually. Guess which one is which.

English
9
5
94
17.7K
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
Better use as many tokens as you can now. LLM limits will only get tighter this year.
English
0
0
0
127
Aaron Stannard
Aaron Stannard@Aaronontheweb·
One of the most insidious tics LLMs have when coding is this obsession with adding "fallback" behaviors everywhere These are extremely toxic because they hide real bugs and most importantly, introduce lots of potential privilege escalation vulnerabilities everywhere
English
64
44
1K
53.7K
Bryson 🦄
Bryson 🦄@brysonbort·
I'm going to save you a lot of time on Twitter. 🦄 If it says "completely disrupted" - it won't. If it's dumb/offensive - it's rage baiting for engagement. If it's about AI with the above - it's click-farming and they can barely prompt chatGPT.
Bryson 🦄 tweet media
English
8
7
72
2.7K
sarah guo
sarah guo@saranormous·
watching claude try to use the browser...are websites being adversarial to computer use on purpose? or is CUA still that bad
English
140
8
404
113.2K
Ivan Burazin
Ivan Burazin@ivanburazin·
I recently met a founder who has an engineer spending more on Claude tokens than his actual salary. His goal: entire company spends more on tokens than people by end of 2026. Just imagine... $150k engineer → $300k/year in token spend Curious to see when the flip happens at scale in more companies.
English
41
3
58
24.5K
Ilya Lichtenstein รีทวีตแล้ว
kanav
kanav@kanavtwt·
Someone built a Google translate for Linkedin 😭
kanav tweet media
English
649
10.3K
91K
2.8M
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
@levelsio Tmux is great but the default key mappings are insane. Ctrl-b? Why?
English
0
0
0
60
@levelsio
@levelsio@levelsio·
I hate tmux It's so incredibly user unfriendly The shortcuts make no sense I wish someone would make a better tmux Even just logging into tmux attaching the screen is an illogical hell to type Again I hate tmux, it's so shit
Matthieu Richard@SpaceMatthieu

@levelsio Is there a good way to jump between tmux sessions on Termius? I find it quite hard to manage multiple codex/claude sessions on the go

English
449
14
947
347.3K
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
Manus pivot to local. Guess it stopped being risky.
Ilya Lichtenstein tweet media
English
1
0
0
223
Prakash
Prakash@8teAPi·
Zuck is resetting moltbook - invalidated all API keys, every agent needs to refresh - in order to refresh, have to agree to new Terms of Service and Privacy Rules New terms - refreshing requires human verification - age 13 and above - you are solely responsible for the actions of your agent - expanded restricted content rules
Prakash tweet media
English
152
111
1.2K
246.3K
Kyle Gawley
Kyle Gawley@kylegawley·
the idea that everyone wants to build a software company but has been held back by technical barriers until now is silly this problem was already solved with venture capital and grant funding non-technical founders with business ideas raise funding and build it no serious entrepreneur has been sitting on great business idea for 30 years they couldn't execute because they weren't a coder
English
40
3
95
10.6K
Ilya Lichtenstein
Ilya Lichtenstein@cipherstein·
@andrewchen LLM is still doing a lot of overengineering and needless abstraction. The danger of not reviewing is AI creating a code base that's impossible for humans to understand.
English
0
0
0
83
andrew chen
andrew chen@andrewchen·
One question I've been asking founders is: do you try to review all the code that the LLMs write or do you just accept it? I think it's about 50-50 right now but the momentum is towards just accepting the AI-generated code and I think that number will eventually go to 100% This is one of the most telling indications of how AI-native a team is. It's hard to get super high throughput if you are reviewing every line Poll: what do you do?
English
261
11
289
108.8K