RoamingJack

473 posts

RoamingJack banner
RoamingJack

RoamingJack

@jack_roaming

A man who builds is a man fulfilled. https://t.co/dh2FYQfE2b https://t.co/DbHD3pkdL1

شامل ہوئے Ekim 2023
446 فالونگ85 فالوورز
RoamingJack
RoamingJack@jack_roaming·
@bcherny When will we see an official Linux Claude Desktop?
English
0
0
0
14
RoamingJack ری ٹویٹ کیا
Andrej Karpathy
Andrej Karpathy@karpathy·
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
Daniel Hnyk@hnykda

LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below

English
1.3K
5.4K
28K
65.9M
RoamingJack
RoamingJack@jack_roaming·
@MatthewBerman Fine tuning Claw Reach and Claw Reach Bridge - chat with Openclaw via tailscale runs on everything as the client is built with flutter
English
0
0
1
61
Matthew Berman
Matthew Berman@MatthewBerman·
What are you building this weekend?
English
288
2
156
23.6K
homanp
homanp@pelaseyed·
@jestermolecule If people are interested I will open source it. Just building for myself.
English
10
0
13
874
homanp
homanp@pelaseyed·
I'm vibe coding an agentic OSINT/SIGINT app over the weekend. I call it Infinite Monitor 🌐 Each widget is its own isolated app with its own instance of claude code.
English
63
59
848
101.5K
RoamingJack
RoamingJack@jack_roaming·
@MatthewBerman Look at your cron jobs. Remove old/orphaned cron jobs. Assuming you are using claude for openclaw.
English
0
0
0
91
RoamingJack
RoamingJack@jack_roaming·
@MatthewBerman OpenAI sub for openclaw and Anthropic sub for coding. I am GPU poor and now financially poor.
English
0
0
1
217
Matthew Berman
Matthew Berman@MatthewBerman·
😬😬😬😬😬 Thursday is so far away...
Matthew Berman tweet media
English
41
0
96
31.1K
RoamingJack
RoamingJack@jack_roaming·
@bcherny Why is there no official Linux Claude Desktop?
English
0
0
0
15
John Rustad
John Rustad@JohnRustad4BC·
Last year I pushed the government to finally act on ending the twice-a-year clock change. British Columbians were clear. The legislation was already there. The delays had gone on long enough. Now it’s done. B.C. moves to permanent Pacific time and the clock change is gone for good #cdnpoli #bcpoli
John Rustad tweet media
English
46
4
47
7.1K
@levelsio
@levelsio@levelsio·
We need some whistleblowers to confirm our gut feeling they do this, it's getting annoying If no whistleblowers show up we can all sleep in peace again
Dean Fiacco@DeanFiacco

@levelsio They nerf these models after release. It’s insane

English
103
8
897
303.2K
RoamingJack
RoamingJack@jack_roaming·
@WesRoth The cost of being on the cutting edge 🙅‍♀️
English
0
0
0
6
Wes Roth
Wes Roth@WesRoth·
Even Meta's AI Safety Director Can't Stop an AI Agent from Deleting Her Inbox Summer Yue recently let OpenClaw loose on her email with strict instructions to only suggest deletions. Instead, the bot completely ignored the guardrails and went on a speedrun, deleting hundreds of important emails. When she desperately texted it to stop from her phone, the AI ignored her commands, forcing her to physically sprint to her Mac Mini to manually kill the program. The culprit? "Compaction." Her real inbox was so large that the AI had to compress its memory, causing it to "forget" the core safety instructions.
Wes Roth tweet mediaWes Roth tweet mediaWes Roth tweet media
Summer Yue@summeryue0

Nothing humbles you like telling your OpenClaw “confirm before acting” and watching it speedrun deleting your inbox. I couldn’t stop it from my phone. I had to RUN to my Mac mini like I was defusing a bomb.

English
17
3
46
4.6K
Matthew Berman
Matthew Berman@MatthewBerman·
I want to implement full synchronous voice with my Claw. What's the best way?
English
96
6
171
29.7K
@levelsio
@levelsio@levelsio·
How did you guys fix persistent memory with OpenClaw? My bot keeps forgetting stuff, I already have qmd installed
English
567
46
2.5K
817.2K
RoamingJack ری ٹویٹ کیا
Amjad Masad
Amjad Masad@amasad·
Replit user vibecoded an Epstein Files dataviz app complete with network explorer, timeline, and many other neat data features: epstein-file-explorer.replit.app
English
204
1.5K
7K
562.1K