Daniel Cluff

4.5K posts

Daniel Cluff banner
Daniel Cluff

Daniel Cluff

@DanielCluff

Software Engineer, AI enthusiast, Anime enjoyer.

Lehi, UT Tham gia Haziran 2011
236 Đang theo dõi213 Người theo dõi
Daniel Cluff
Daniel Cluff@DanielCluff·
I love Japanese curry 🤤
English
0
0
0
4
Raven
Raven@Ravenismeee·
Gun to your head name a reason to live
English
1.9K
327
3.2K
309.2K
Daniel Cluff
Daniel Cluff@DanielCluff·
@petersteele They stopped being a software company and transitioned into a data mining one. I’m not sad at all. It will be amusing to watch them fall apart.
English
0
0
0
7
Peter Steele
Peter Steele@petersteele·
@DanielCluff MicroSlop has really lost the ball here. I don't know wtf they are thinking but between windows 11 and github, its been a death spiral from the outside looking in.
English
1
0
1
15
Daniel Cluff
Daniel Cluff@DanielCluff·
Microsoft living the dream 19
English
1
0
1
18
ThePrimeagen
ThePrimeagen@ThePrimeagen·
GitHub just living the dream right now
ThePrimeagen tweet media
English
109
61
2.2K
80K
Tuki
Tuki@TukiFromKL·
🚨 Andrej Karpathy just explained the scariest thing happening in software right now.. someone poisoned a Python package that gets 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine.. SSH keys.. AWS credentials.. crypto wallets.. database passwords.. git credentials.. shell history.. SSL private keys.. everything.. and here's the part that should terrify every developer alive.. the attack was only discovered because the attacker wrote sloppy code.. the malware used so much RAM that it crashed someone's computer.. if the attacker had been better at coding.. nobody would have noticed for weeks.. one developer.. using Cursor with an MCP plugin.. had litellm pulled in as a dependency they didn't even know about.. their machine crashed.. and that crash saved thousands of companies from getting their entire infrastructure stolen.. Karpathy's take is the real wake up call.. every time you install any package you're trusting every single dependency in its tree.. and any one of them could be poisoned.. vibe coding saved us this time.. the attacker vibe coded the attack and it was too sloppy to work quietly.. next time they won't make that mistake.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
210
1.6K
9.3K
2M
trish
trish@_trish_xD·
Programming language you learned once but never touched again?
English
631
9
325
55.5K
eppy
eppy@epppyyy·
It is depressing how boring has YouTube become
English
874
4.6K
58.7K
1.9M
Xor
Xor@XorDev·
If I have disposable income, I want to wrap my car in shader code
English
14
0
71
4.1K
Daniel Cluff
Daniel Cluff@DanielCluff·
Cooking is so baste
English
0
0
0
9
Peter Steele
Peter Steele@petersteele·
@DonShift3 If you fear for your life, minimizing potential harm is actually worse off for you, because you truly did not fear for your life. No different in a defensive shooting situation brandishing your gun to deter or to shoot to maim and not kill. Your ass will end up in jail.
English
2
0
10
560
Don Shift (buy my books)
An infographic reminder thread on avoiding situations like this, but first, some analysis. 🧵 Don't bluff. That forward/backwards thing she does? Ineffective. The crowd is accustomed to not being hit by cars, so they don't think she actually will. Each time she doesn't hit them, they assume she never will. The high speed take off? Probably unnecessary. It would look better if she traveled at a low speed where the injury potential is lower. High speed can be construed as malicious intent. Going slow you can argue "I was in fear for my life but I did my best to minimize any potential injuries at my own risk." Also it allows people to get the heck out of the way or strengthens your defense if you do have to go fast. She will need a good lawyer to argue why she thought she was in imminent danger. From THE VIDEO ALONE it just looks like a crowd of rowdy blacks that were kicking her car, not a lethal threat. They dindu nuffin' requiring a potentially lethal threat. What will likely happen? Her insurance will payout the policy limits to the "victims" and she'll plead guilty to probably felony DUI in a plea bargain, but avoid any attempted murder/manslaughter nonsense. Moral of the story? Don't drink and drive and avoid large groups of black people.
AmericanPapaBear™@AmericaPapaBear

BREAKING: This is the chaotic scene where 20-year-old Kaydence Carpenter allegedly drove her Tesla into a crowd that was surrounding her car in Lexington, Kentucky early Sunday morning. Reports are that she injured 4 people. She faces 4 counts of second-degree assault, DUI and reckless driving. Many responses think what she did was warranted.

English
39
15
267
19.8K
Victoria
Victoria@VictoriqueM·
@adelheidx333 are 13 year olds even intelligent enough and have the attention span to read Umineko?
English
5
0
12
743
Adelheid
Adelheid@adelheidx333·
Every time I see someone with Umineko or Higurashi pfp, I imagine that they are a 13 year old that has unsupervised access to the internet
Adelheid tweet media
English
37
34
702
22.6K
Peter Steele
Peter Steele@petersteele·
Come take a small trip down Nostalgia lane with me. Showing off 2 of the most iconic games for me. What team are you on? Team Halo or Team Oregon Trail?
English
3
0
5
224
bre
bre@BreTweetz·
If you’re: - right leaning - like anime and video games Let’s be moots!!!! #moothunt
English
764
188
6.7K
124.7K
LaurieWired
LaurieWired@lauriewired·
I promise this relates to RAM (you'll find out in my next video)
English
52
30
1.4K
71.9K
Daniel Cluff
Daniel Cluff@DanielCluff·
It’s so beautiful outside today. The temptation to touch grass is extremely high.
English
0
0
1
22
Daniel Cluff
Daniel Cluff@DanielCluff·
Men only want one thing
Daniel Cluff tweet media
English
0
0
1
14
✩ em ✩
✩ em ✩@promptprincess·
x dms are so broken for me rn wbu
English
19
0
46
1.2K
Daniel Cluff
Daniel Cluff@DanielCluff·
@MelonTeee Just wait until you see what the government does with your money
English
0
0
0
16
Melony🍈
Melony🍈@MelonTeee·
gardening is NOT relaxing bugs are eating all my shit I've never felt this violent in my life
English
787
12.7K
196.2K
5.5M