plog

583 posts

plog banner
plog

plog

@plog

...

Belgium Tham gia Aralık 2007
607 Đang theo dõi29 Người theo dõi
Tweet ghim
plog
plog@plog·
@MarcJSchmidt - AI created a bigger, agent-driven economy - AI is terrible at long-term maintenance - Open for humans, metered APIs for agents - Create specialized, monetizable agents on top of your OSS
English
0
0
0
55
Miles Deutscher
Miles Deutscher@milesdeutscher·
The most powerful GPT-5.5 vibe coding prompt on the entire internet. Use this prompt, and you'll literally be able to ship anything. Fully functional apps, beautiful web designs - whatever you can imagine, this prompt can execute. The best part is, it takes <5 minutes to use:
Miles Deutscher tweet media
English
30
28
259
28.8K
hrithik ( 히리틱 )
hrithik ( 히리틱 )@hrithikk·
Dear @paradigm @a16z @polychaincap @coinbase I'm building KoreanFlare - voice-activated wallet protection against North Korean hackers. After $2.3B got stolen by Lazarus Group, I realized we need better verification than "enter password" Our solution is simple: Before any transaction, users must say "Kim Jong is gay" into their microphone. If you refuse or sound North Korean, wallet locks permanently. Why it works: - No North Korean hacker will say it (instant execution) - Voice AI detects Korean accent - Decentralized proof-of-disrespect consensus - 100% effective (my theory, no testing needed) Built on Cloudflare but web3 because I said so. 3 VCs and a Saudi prince from Telegram are interested, this either revolutionizes crypto security or makes me rich like everyone else. Probably both. Best, Hrithik Founder, KoreanFlare P.S. - Our MVP is just a microphone button. Seeking $2M to add the other features.
hrithik ( 히리틱 ) tweet media
English
264
428
6.4K
345.5K
plog đã retweet
TheBrainMaze TBM
TheBrainMaze TBM@thebrainmaze·
Artemis Mission Route in 3D - This animation visualizes the Artemis mission trajectory in a dynamic 3D perspective, showing how the spacecraft travels through the Earth–Moon system while all celestial bodies are in motion. Instead of a static path, the Sun, Earth, and Moon move simultaneously, revealing the true complexity of orbital mechanics. The result highlights how the Artemis route is not a simple curve, but a constantly shifting trajectory shaped by gravity and motion. This view provides a clearer understanding of how modern space missions navigate through space in real time. Right now, Artemis is on its return path to Earth and is expected to arrive back soon as it completes its mission. The sizes and distances of the Sun, Earth, and Moon are not to scale and are adjusted for visual purposes.
English
193
4K
19.4K
1.4M
Aakash Gupta
Aakash Gupta@aakashgupta·
Someone just poisoned the Python package that manages AI API keys for NASA, Netflix, Stripe, and NVIDIA.. 97 million downloads a month.. and a simple pip install was enough to steal everything on your machine. The attacker picked the one package whose entire job is holding every AI credential in the organization in one place. OpenAI keys, Anthropic keys, Google keys, Amazon keys… all routed through one proxy. All compromised at once. The poisoned version was published straight to PyPI.. no code on GitHub.. no release tag.. no review. Just a file that Python runs automatically on startup. You didn’t need to import it. You didn’t need to call it. The malware fired the second the package existed on your machine. The attacker vibe coded it… the malware was so sloppy it crashed computers.. used so much RAM a developer noticed their machine dying and investigated. They found LiteLLM had been pulled in through a Cursor MCP plugin they didn’t even know they had. That crash is the only reason thousands of companies aren’t fully exfiltrated right now. If the code had been cleaner nobody notices for weeks. Maybe months. The attack chain is the part that gets worse every sentence. TeamPCP compromised Trivy first. A security scanning tool. On March 19. LiteLLM used Trivy in its own CI pipeline… so the credentials stolen from the SECURITY product were used to hijack the AI product that holds all your other credentials. Then they hit GitHub Actions. Then Docker Hub. Then npm. Then Open VSX. Five package ecosystems in two weeks. Each breach giving them the credentials to unlock the next one. The payload was three stages.. harvest every SSH key, cloud token, Kubernetes secret, crypto wallet, and .env file on the machine.. deploy privileged containers across every node in the cluster.. install a persistent backdoor waiting for new instructions. TeamPCP posted on Telegram after: “Many of your favourite security tools and open-source projects will be targeted in the months to come.. stay tuned.” Every AI agent, copilot, and internal tool your company shipped this year runs on hundreds of packages exactly like this one… nobody chose to install LiteLLM on that developer’s machine. It came in as a dependency of a dependency of a plugin. One compromised maintainer account turned the entire trust chain into a credential harvesting operation across thousands of production environments in hours. The companies deploying AI the fastest right now have the least visibility into what’s underneath it.
Andrej Karpathy@karpathy

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.

English
294
2.3K
11K
2.7M
plog
plog@plog·
@LeBunkerBtc Avec ce talent: retourner en Dordogne faire un bouquin :) (ou un bon scénario)
Français
0
0
0
100
Le ₿unker 🪖
Le ₿unker 🪖@LeBunkerBtc·
Après ton BAC+5, tu es devenu développeur full-stack en CDI dans une boîte du CAC40 qui met "innovation" et "inclusion" dans tous ses PowerPoints. T'es payé comme un stagiaire luxembourgeois mais t'es plein d'espoir et d'ambition parce que Jean-Luc de la compta avec son pantalon a pince marron et ses spartiates d'handicapé social t'a dit qu'au bout de 5 ans "ça décolle". En 2020, pendant les confinements, ton DRH t'annonce le télétravail permanent depuis une vidéo Zoom où il porte un col roulé noir comme s'il annonçait l'iPhone 12. Les politiques et les médias confirment: c'est la bonne chose à faire d'un point de vue sanitaire et aussi pour sauver les pingouins en diminuant les émissions de CO2. Tu vends ta bagnole, tu quittes ton 28m² à Montreuil où t'entendais ton voisin tousser à travers le mur, tu t'installes en Dordogne dans une maison avec jardin, ta copine est aux anges. Tu fais tes calls en calebard avec un café en regardant les canards traverser ton terrain et pour la première fois de ta vie tu te dis que la vie est belle et que le vent a tourné en ta faveur. Tu t'imagines même mettre ta grosse en cloque. En 2024, mail de la direction un lundi à 8h: "Dans le cadre de notre politique de cohésion d'équipe, la présence au bureau est désormais obligatoire 4 jours sur 5." Tu revends la maison en Dordogne à contrecoeur et à perte parce que les taux ont quadruplé et que ton acheteur le sait très bien ce fils de pute, ta copine te quitte en prenant le gosse et le labrador parce qu'elle ne veut pas revenir en Île-de-France se faire toucher le cul dans le metro, tout en te réclamant évidemment une pension alimentaire. Tu reprends un studio à Cergy pour 1000€ par mois avec vue imprenable sur un Lidl et une bretelle d'autoroute, tu rachètes une Sandero d'occasion qui sent le Febreze et le regret, et tu retournes faire 1h30 de bouchons sur l'A15 matin et soir entre un camion polonais et un utilitaire Amazon en te disant que t'aurais jamais dû écouter ce connard de DRH. En 2026, ton manager t'invite à un call Teams un vendredi à 17h58: "On a automatisé une grande partie de tes tâches avec notre nouvel outil IA. On te propose une rupture conventionnelle." T'as 34 ans, un crédit auto en cours, un studio que tu peux plus payer, Magali qui te réclame la pension pour le chiard et le clebs et un CV dont la compétence principale vient d'être remplacée par un prompt de 3 lignes qu'un stagiaire a copié depuis Reddit.
Le ₿unker 🪖 tweet media
Français
294
1.2K
7.6K
808.5K
plog đã retweet
Bibawen
Bibawen@asimbawe·
ZXX
561
17.9K
145.2K
3.6M
plog đã retweet
Dudes Posting Their W’s
Dudes Posting Their W’s@DudespostingWs·
This dude shares the little things in life that make men happy.
English
347
7.6K
51.3K
1.5M
plog đã retweet
Virginie Debuisson
Virginie Debuisson@VirgoWhallala·
Je tiens le hit de l’hiver ! C’est Groenlandais j’adore 🤣🎶
Français
18
290
898
31.2K
Mario Lopez
Mario Lopez@mariolopezviva·
Are we not teaching genetics anymore?
Mario Lopez tweet media
English
5.6K
6.8K
111.8K
4.3M
plog đã retweet
80 LEVEL
80 LEVEL@80Level·
Yong Su ported Evan Wallace's classic WebGL water demo to WebGPU. Try it right in your browser: 80.lv/articles/real-…
English
5
68
708
35.4K
plog
plog@plog·
@MarcJSchmidt - AI created a bigger, agent-driven economy - AI is terrible at long-term maintenance - Open for humans, metered APIs for agents - Create specialized, monetizable agents on top of your OSS
English
0
0
0
55
Marc
Marc@MarcJSchmidt·
All my new code will be closed-source from now on. I've contributed millions of lines of carefully written OSS code over the past decade, spent thousands of hours helping other people. If you want to use my libraries (1M+ downloads/month) in the future, you have to pay. I made good money funneling people through my OSS and being recognized as expert in several fields. This was entirely based on HUMANS knowing and seeing me by USING and INTERACTING with my code. No humans will ever read my docs again when coding agents do it in seconds. Nobody will even know it's me who built it. Look at Tailwind: 75 million downloads/month, more popular than ever, revenue down 80%, docs traffic down 40%, 75% of engineering team laid off. Someone submitted a PR to add LLM-optimized docs and Wathan had to decline - optimizing for agents accelerates his business's death. He's being asked to build the infrastructure for his own obsolescence. Two of the most common OSS business models: - Open Core: Give away the library, sell premium once you reach critical mass (Tailwind UI, Prisma Accelerate, Supabase Cloud...) - Expertise Moat: Be THE expert in your library - consulting gigs, speaking, higher salary Tailwind just proved the first one is dying. Agents bypass the documentation funnel. They don't see your premium tier. Every project relying on docs-to-premium conversion will face the same pressure: Prisma, Drizzle, MikroORM, Strapi, and many more. The core insight: OSS monetization was always about attention. Human eyeballs on your docs, brand, expertise. That attention has literally moved into attention layers. Your docs trained the models that now make visiting you unnecessary. Human attention paid. Artificial attention doesn't. Some OSS will keep going - wealthy devs doing it for fun or education. That's not a system, that's charity. Most popular OSS runs on economic incentives. Destroy them, they stop playing. Why go closed-source? When the monetization funnel is broken, you move payment to the only point that still exists: access. OSS gave away access hoping to monetize attention downstream. Agents broke downstream. Closed-source gates access directly. The final irony: OSS trained the models now killing it. We built our own replacement. My prediction: a new marketplace emerges, built for agents. Want your agent to use Tailwind? Prisma? Pay per access. Libraries become APIs with meters. The old model: free code -> human attention -> monetization. The new model: pay at the gate or your agent doesn't get in.
Marc tweet media
English
705
1.2K
10.9K
1.2M
Le Parisien
Le Parisien@le_Parisien·
L’administration Trump serre la vis sur les visiteurs étrangers exemptés de visas ➡️ l.leparisien.fr/VpIQ
Le Parisien tweet media
Français
13
17
52
12K
plog đã retweet
SaxX ¯\_(ツ)_/¯
SaxX ¯\_(ツ)_/¯@_SaxX_·
🚨🔴CYBERALERT 🇫🇷FRANCE🔴 | Petit Récapitulatif de toutes les fuites de données et cyberattaques en 2025... ⤵️ J'annonce 2025 ANNÉE NOIRE et RECORD DE FUITES D'INFORMATION ! 👉🏿 Ministère de l'Intérieur, 👉🏿 HelloWork, 👉🏿 La Poste, 👉🏿 Une 20aine de Fédération Française du Sport, 👉🏿 Mondial Relay, 👉🏿 Colis Privé, 👉🏿 Chronopost, 👉🏿 Ministère des Sports, 👉🏿 SFR, 👉🏿 PornHub, 👉🏿 Euromatik, 👉🏿 Cuisinella, 👉🏿 Médecin Direct, 👉🏿 Leroy Merlin, 👉🏿 France Travail, 👉🏿 AG2R la Mondiale, 👉🏿 +1000 Mairies, 👉🏿 Murfy, 👉🏿 Michelin, 👉🏿 Resana, 👉🏿 Pajemploi, 👉🏿 Eurofiber, 👉🏿 Weda, 👉🏿 MYM, 👉🏿 France Travail, 👉🏿 Fédération Française de Tir, 👉🏿 +8 Agences Régionales de Santé, 👉🏿 Mango, 👉🏿 Auchan, 👉🏿 Air France, 👉🏿 Bouygues Telecom, 👉🏿 Louis Vuitton, 👉🏿 Sorbonne Université, 👉🏿 Centre National de la Fonction Publique Territoriale, 👉🏿 Union Nationale du Sport Scolaire, 👉🏿 Hôpital privé de la Loire, 👉🏿 Disneyland, 👉🏿 Cartier, 👉🏿 Autosur, 👉🏿 Dior, 👉🏿 Cerballiance, 👉🏿 Carrefour Mobile, 👉🏿 Easy Cash, 👉🏿 Indigo, 👉🏿 Afflelou, 👉🏿 Hertz, 👉🏿 Harvest, 👉🏿 MAIF & BPCE, 👉🏿 Intersport, 👉🏿... LA CYBERSECURITE EST UN ÉCHEC -Nicolas Ruff- Je pense qu'on ne pourra pas faire pire en 2026 ! Mais les conséquence seront dramatiques ! Préparez-vous. 👉🏿 L'Etat a échoué -le sujet ne semble pas être leur priorité- 👉🏿 J'ai échoué -mes sensibilisations n'ont pas portées pleinement leurs fruits- 👉🏿 LA CNIL a échoué -aucune sanction d'entreprises et institutions- 👉🏿 LE RGPD a échoué -bcp d'entreprises ne connaissaient pas ce terme- 👉🏿 Les COMEX/Directions ont échoué -pas assez de budget pour les équipes cyber- 👉🏿 Les salariés ont échoué -pas assez de sensibilisation et d'éducation à la cyber- 👉🏿 Les communications de crises ont échoué -quelle supercherie dans la manière de se dédouaner et de dire aux gens qu'ils fassent désormais attention et qu'au fond c'est de leur faute- J'ai fait une 100aine de CYBERALERT cette année. J'ai discuté avec des 10aines de cybercriminels. Les coulisses de certaines cyberattaques sont dignes de scénario de films pcq d'une facilité déconcertante jusqu'à parfois appeler le salarié visé... lui faire croire que c'est le service informatique ou pire... le menacer... Et enfin, ce chiffre que j'ai découvert il y a 2 mois à peine, il y a 600M de données personnelles cumulées de français qui sont dans les mains des cybercriminels. 9 personnes sur 10 en France sont donc concernées ! QUELLE ANNÉE NOIRE...
SaxX ¯\_(ツ)_/¯ tweet media
Français
238
2.9K
5.3K
410.8K
plog đã retweet
Riley Brown
Riley Brown@rileybrown·
Struggle to keep up with all the most powerful AI tools? Well here is a comprehensive overview: Sections: 1: AI Tools 2: AI Automations & AI Agents 3: VibeCoding The Full Mindmap down below 🧵 ⬇️ TIMESTAMPS A INTRO 00:00 Introduction B CHAT TOOLS 01:50 ChatTools 01:50 Getting Started with Chat AI Tools 02:27 Exploring Chat GPT's Capabilities 04:11 Creating Custom ChatGPT Projects 07:54 Creating Files (PDF) ChatGPT Projects 11:44 Upload image and Search the web on ChatGPT 15:14 Looking at Google Gemini AI Chat Tool 16:36 Perplexity is another great tool 18:10 This AI Chat Model Can Analyze Videos (Most underrated AI use cases @OfficialLoganK you guys need to hype this up more) 20:16 Recapping Chat Tools C CREATIVE TOOLS 21:05 Introduction to AI Image Models 22:19 Using Chat GPT-4o for Image Editing 22:30 Using gpt4o images for Business: Repaint Houses 26:36 Edit Parts of an image gpt4o 27:55 Midjourney 28:23 Midjourney is better for exploration 31:25 Midjourney Editor is fun to use D: CREATING VIDEOS 36:29 Image to Video with Kling and Runway 38:52 Gen4 Turbo 41:22 Kling is Superior 42:00 gpt4o Ghibli Image + Video + Sound 44:58 Ghibli time 49:15 ElevenLabs Sound Effect for pressing button 50:00 Generating Voice for Voice Over 51:04 Getting Music 52:07 Video Editing These together 53:47 Finished the Video - Final Results 55:02 Video Tool Recap 56:27 AI Avatars with Heygen 57:42 Example of good avatar content ROWAN CHUNG 58:43 Pause and Reflect before Automations 59:14 Recap of section 1 E: VIBE FLOWS (AUTOMATIONS AND AGENTS) 59:34 (add here - explanation of workflow automation) 59:34 Zapier Automation 01:04:24 Adding Step in Automation 01:09:45 Stacks, Automations, NOW AGENTS 01:10:29 Deep Research Agent 01:13:11 What is Manus? Let's ask Claude to Diagram it 01:16:25 Prompting Manus 01:18:20 The Future of Agents will look like Online Poker in 2010 01:19:15 WHAT DO WE DO WHEN AGENTS ARE WORKING? 01:19:56 Greg's Theory of "Vibe Marketing" 01:20:44 Manus and Deep Research are done Agenting, let's see what they did 01:23:32 Ok Lets Reflect and Move to VIBE CODING F: VIBE CODING 01:25:35 VIBE CODING! 01:25:48 Landing Page with Sound, Images, and Video on v0 01:29:07 Generating Video for v0 site 01:31:31 Adding Video and AUDIO to v0 site (ElevenLabs) 01:33:36 Using API's in your Vibe Code Apps (Power Ups) 01:35:26 What makes the best App Idea 01:37:41 Build a simple app with an API with Cursor 01:42:57 Diagraming how the API key works in the Bill Splitter 01:43:25 Structured vs Unstructured text to text API's 01:44:41 Building a mobile app using built in API's from your phone 01:47:31 Creating native share features on ios app 01:49:21 What we talked about in this video (Where to Find the MindMap) Tools mentioned: 1:ChatGPT, Google Gemini, Anthropic Claude, Perplexity, Grok, GPT‑4o Images / DALL·E 3, MidJourney, Cling 2.0, Krea AI, Runway Gen‑4, Google Veo, Luma Labs, Pika Labs, Heygen, Suno, ElevenLabs 2: Zapier,n8n, Manus, Deep Research, Canva, CapCut, Premiere Pro 3: Cursor, V0, OpenAI API, Replicate, Vercel, Replit, Firebase, Supabase, Claude 3, DeepSeek, Grok, Llama
English
153
814
3.9K
245.3K
plog
plog@plog·
blog.plog.net/i-wanted-a-but… #Copilot The code still works, but you are no longer sure why. At that point, you are not building a tool anymore. That is when things go off the rails. Not because the system is complex, but because nobody truly understands it.
plog tweet media
English
0
0
0
20
plog
plog@plog·
@DilumSanjaya Who taught it to drive like that ?.... 😂🤕
English
0
0
0
13
Dilum Sanjaya
Dilum Sanjaya@DilumSanjaya·
Tested Meta's SAM 3 on some low quality dashcam footage and expected the segmentation to fall apart, but it still picked up every vehicle and even spotted people on the roadside that I hadn't noticed at all.
English
42
120
1.7K
220.4K