Nutzipper

347 posts

Nutzipper

Nutzipper

@nutzipper

เข้าร่วม Mart 2010
367 กำลังติดตาม163 ผู้ติดตาม
Nutzipper
Nutzipper@nutzipper·
lol. no-one foreseen this.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
0
0
0
3
🤖
🤖@phildaian·
for 30 years, they had one singular focus an entire industry. trillions of dollars. thousands of companies. billions of people. countries overturned. elections dominated. land repurposed into backbone factories of information we have finally achieved the vision
🤖 tweet media
English
3
1
13
1.4K
Nutzipper
Nutzipper@nutzipper·
@phildaian AI is making morons even bigger morons. Moron in the loop I'd say. Or on the hook.
English
0
0
0
8
Nutzipper
Nutzipper@nutzipper·
@BWarburg What’s not fun is to be surrounded by people who do not read.
English
0
0
0
17
Mike Stay
Mike Stay@metaweta·
let isEven = (n) => { let d = 3*2**52; return n + d - d == n; }
English
1
0
1
50
Nutzipper
Nutzipper@nutzipper·
@matej_cerny While very nice and OCAP would be more widespread - seems the solution is not that far from just hiding the whole functionality behind API call?
English
1
0
0
76
Matej Cerny
Matej Cerny@matej_cerny·
There's a new paper out from Martin Odersky and his team on applying Scala Capabilities to AI agents. I have to admit, it's a really fascinating use case! Listen for yourself 👇 (disclaimer: the podcast is generated by NotebookLM, but give it a shot - it's very well done!)
English
4
3
24
1K
Nutzipper
Nutzipper@nutzipper·
Haven't hear much about CBDCs lately. Guess nothing is happening on that front.
English
0
0
0
23
Nutzipper
Nutzipper@nutzipper·
What if “a new heaven and a new earth, where righteousness dwells” is about not being able to fake it but also not being able to make it?
English
0
0
0
31
Nutzipper
Nutzipper@nutzipper·
So it seems programming will be liberated from the Von Neumann style?
English
1
0
0
20
Josh Pigford
Josh Pigford@Shpigford·
@nutzipper thank, anonymous internet user, for the helpful reply
English
1
0
1
80
Josh Pigford
Josh Pigford@Shpigford·
hypothesis: you can build an autonomous company using only openclaw + discord. discord has some very good primitives for interacting with bots and with the right channel + thread setup, you could easily manage the whole thing. now...to test.
English
13
1
27
5.7K
Nutzipper
Nutzipper@nutzipper·
I'm hearing that some huge companies are going codex/claude mandatory and everything should be proxied through them. Some folks recall the narrative of how dangerous it would be to give all your data to FAANG. Old days. Now it's even more - not just data but processes. Shit.
English
0
0
0
36
Paul Snively
Paul Snively@JustDeezGuy·
@fbrasisil Fair point, at this stage. What I mean is: with Scala Native 0.5, we finally have native support for the machinery cats-effect, ZIO, Kyo (?) need to operate with full functionality and native performance. How that plays out in practice is, as you say, still an open question.
English
2
0
5
628
duve
duve@jevonduve·
not listening to programming opinions from someone who doesn't know what a homomorphism is
English
30
30
621
26.9K
Nutzipper
Nutzipper@nutzipper·
@mert How else you extract value from those people if not by pushing this narrative?
English
0
0
0
9
mert
mert@mert·
perhaps the most incoherent thesis ive seen is that powerful and expressive computers (LLMs) will make obsolete the people who are experts at using powerful and expressive computers (devs)
English
52
17
334
27K
Shixi Lin
Shixi Lin@11Shixi·
我的 AI 助手团队凌晨 3 点还在工作, 我该不该强制他们下班? A. 强制下班,健康第一 B. 让他们自愿,别管 C. 加入他们,一起卷 D. 给 AI 们成立工会 选一个,我听你们的。 #投票 #AI #职场 #数字游民
Shixi Lin tweet media
中文
1
0
1
82