Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AgentME
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
AgentME
4mo ago
Are there standards for a video to declare a default subtitle track to use?
32.
▲
by
AgentME
4mo ago
No, the reference to May 19 in the article is about a previous supply chain attack against AntV ( https://www.stepsecurity.io/blog/shai-hulud-here-we-go-again... ). I think there may be some copy-paste mistakes where the
33.
▲
by
AgentME
4mo ago
The security companies looking for and reporting the issues aren't going to use the cooldown too.
34.
▲
by
AgentME
4mo ago
Even for English speakers, the subtitle experience with pirated movies is often lacking. Movies with non-English-speaking characters are often meant to have subtitles for their dialog and not for English speakers by default, but many pirate
35.
▲
by
AgentME
4mo ago
It's worth pointing out that the article explicitly calls out your first mixed technique: > Finally, one should never mix the encode and decode steps of the two quantizers. That’s just broken code. It’s an easy mistake to make, thou
36.
▲
by
AgentME
4mo ago
OpenImageIO uses the standard division by 255 technique: https://openimageio.readthedocs.io/en/latest/imageoutput.htm...
37.
▲
by
AgentME
4mo ago
But there is a second level of people reviewing packages on npm. They're the ones that report issues like the github issue this HN thread is linked to, and they very frequently get malicious npm packages taken down within a day of publ
38.
▲
by
AgentME
4mo ago
I was thinking this through more and realized that a callback directly in a thread local variable isn't quite enough: You need to keep a stack in the thread local variable. Every try-handle block pushes a callback in and pops it when e
39.
▲
by
AgentME
4mo ago
That's what I was thinking. You could get almost all of this pretty directly in Javascript by putting a callback function in an AsyncLocalStorage instance or, in other languages, in a thread local variable.
40.
▲
by
AgentME
4mo ago
People in the WebAssembly standards group are recently considering relaxing the limitation that the main thread can't use atomic.wait: https://github.com/WebAssembly/threads/issues/177#issuecomme...
41.
▲
by
AgentME
4mo ago
> Spaces takes this shape. (Disclosure: I work on it.) Issued names live in a binary Merkle trie. The root of that trie is committed to Bitcoin’s chain Who can update and publish the merkle trie onto the blockchain? Is it only Spaces the
42.
▲
by
AgentME
4mo ago
Your deno.json/package.json should generally pin things to their major version (eg. "^3.1.4"). Your application's lockfile (deno.lock/package-lock.json) which is generated by default pins your dependencies and your
43.
▲
by
AgentME
4mo ago
Isn't Lua equally monkey-patchable? Both of the languages, along with Python and Ruby, represent nearly everything as mutable objects.
44.
▲
by
AgentME
5mo ago
Javascript/Typescript as it is now isn't a great language for a real capability system because any code can monkey-patch global objects and use that to steal capability objects from elsewhere. JS code of different privilege levels
45.
▲
by
AgentME
5mo ago
One issue was that all dependencies had to be pinned to exact versions. If some sub-dependency of yours got a bugfix in a minor or patch update, your project only gets that update once the dependency updates to bump its dependencies and the
46.
▲
by
AgentME
5mo ago
It would be one thing for someone to say "AI is enabling plagiarism at a bigger scale", but to say it's "just plagiarism", surely one needs to explain who exactly the unit distance breakthrough was plagiarized from.
47.
▲
by
AgentME
5mo ago
If someone is switching from C because it's too easy to trigger undefined behavior, picking one of the few other not memory safe languages is missing the point.
48.
▲
by
AgentME
5mo ago
Another supply chain attack found and blocked in a day. Everyone regularly using npm to install new packages should be using npm's min-release-age setting to avoid package versions that are newer than a few days old to avoid most attac
49.
▲
by
AgentME
5mo ago
Conventional symmetric cryptography is already very secure and easy, even in the face of future threats like quantum computers. (Asymmetric cryptography is the type of cryptography that cryptographers spend more time worrying about.) Not th
50.
▲
by
AgentME
5mo ago
Another great example of the unintuitiveness of heritability is the fact that earrings are highly heritable. Earrings are highly correlated to a specific genetics (being female), so they're very "heritable", even though that
51.
▲
by
AgentME
5mo ago
Highly recommend using the minimum release age setting, though I think a week is probably overkill. Did any of the recent supply-chain attacks have a malicious version up for more than a day?
52.
▲
by
AgentME
5mo ago
People are already scanning npm constantly. You can limit yourself to pre-scanned packages by setting npm's minimum release age setting to 1 or 2 days (a timeframe that all the recent high-profile malicious package versions were unpubl
53.
▲
by
AgentME
5mo ago
Npm's package-lock.json already handles pinning everything to exact versions, including subdependencies. Pinning exact versions in package.json doesn't affect your subdependencies.
54.
▲
by
AgentME
5mo ago
It's silly to act like they've got mud on their face when Mythos and Opus are apparently some of the very best models. Anyone that has found value out of previous LLMs is likely to find more value out of the newest ones. The only
55.
▲
by
AgentME
5mo ago
Hasn't almost every new frontier model had an early period of limited access? I don't get why everyone is acting like Mythos is particularly egregious for this.
56.
▲
by
AgentME
5mo ago
Yeah, the answer almost certainly has to be this, or that they were using an old version of the package which didn't use the system RNG correctly (the current version appears to do it correctly, but I didn't dive into older versio
57.
▲
by
AgentME
5mo ago
Presumably npm exempts security updates from its minimum release age, but even if it doesn't, I think the times where you need an important security update are relatively rare enough that handling the real cases on a case-by-case basis
58.
▲
by
AgentME
5mo ago
There's already an okay solution to supply-chain attacks against dependency managers like npm, PyPI, and Cargo: set them to only install package versions that are more than a few days old. The recent high-profile attacks were all caugh
59.
▲
by
AgentME
5mo ago
I liked Doctorow better before he cheered for stricter copyright enforcement.
60.
▲
by
AgentME
6mo ago
Shellshock was in 2014 and Log4Shell was 2021. It's far more likely that you're going to get pwned by using a too-recent unreviewed malicious package than to be unknowingly missing a security update that keeps you vulnerable to ea
More ›