Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
diggan
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
151.
▲
by
diggan
1y ago
> It won't be a red flag for people who often see auto-complete not working for legitimate websites. The usual cause is legitimate websites not working instead of actual phishing attempts. Yeah, that's true, I hit this all the
152.
▲
by
diggan
1y ago
> npm is too slow to respond Microsoft has been bravely saying "Security is top priority" since 2002 ( https://www.cnet.com/tech/tech-industry/gates-security-is-to... ) and every now and then reminds us
153.
▲
by
diggan
1y ago
> Pretty sure the claim is of LLMs specifically Yeah, I initially thought so too, but since they used "models" later, I assumed they knew the difference and really meant "software". > recent GPT-OSS is not competit
154.
▲
by
diggan
1y ago
> It is, if your packages are popular enough then npm will force you to enable 2FA. Are they actively forcing it? I've received the "Remember to enable 2FA" email notifications from NPM since 2022 I think, but haven'
155.
▲
by
diggan
1y ago
Nor does TOTP+password lock you to one authentication provider indefinitely. Tradeoffs :)
156.
▲
by
diggan
1y ago
Both of those points are fairly common in phishing emails, at least the ones I receive. Cloning the HTML/CSS for phishing has been done for as long as I've been able to receive emails, don't even need LLMs for that :)
157.
▲
by
diggan
1y ago
Use a password manager (that isn't too buggy and/or suck) and you get the same thing for both TOTP and passwords.
158.
▲
by
diggan
1y ago
So far, it seems to be a bog-standard phishing email, with not much novelty or sophistication, seems the people running the operation got very lucky with their victims though. I'm starting to think we haven't even seen the full sc
159.
▲
by
diggan
1y ago
I think that's pretty unlikely. I aren't even a high-profile npm author, and if I publish any npm package they end up being accessed/downloadaded within minutes of first publish, and any update after that. I also know project
160.
▲
by
diggan
1y ago
> Nvidia parakeet and canary are better and faster Is that based on your own experience using those and also Whisper, comparing them side-by-side? Or is that based just on those benchmark results?
161.
▲
by
diggan
1y ago
Guess nowadays they recommend everyone to use Firefox or some other non-crippling browser then also? I helped my wife with something the other day, noticed the ads everywhere, while I was sure I had installed uBlock for her in the past. Wen
162.
▲
by
diggan
1y ago
And everyone forgets that electricity was invented (mostly) by Europeans, but so what? Everything comes from something, doesn't make any place inherently better for continuing to inventing more breakthroughs, it's just people in a
163.
▲
by
diggan
1y ago
> There are like 10 models that are smaller and faster and outperform both of them. As someone who is currently relying on Whisper for some things, what models are those exactly? I still haven't found anything that is accurate as Wh
164.
▲
by
diggan
1y ago
> I feel like it's extremely common for the autofill to not work for various reasons even when you aren't being phished I dunno, it mostly seems to not work when companies change their field names/IDs, or just 3rd party au
165.
▲
by
diggan
1y ago
> OpenAI has no serious open source software What's "serious" exactly? Codex is open source, is software, can be run with open/downloadable models/weights. In my testing using Gemini, Claude Code, Codex, Qwen Cod
166.
▲
by
diggan
1y ago
"will offer potential for joint research to address future opportunities" seems like the meat of that statement. I read that like they're (potentially) starting to investigate building chips for inference, with Mistral probab
167.
▲
by
diggan
1y ago
Or you know, get a password manager like the rest of us. If your password manager doesn't show the usual autofill, since the domain is different than it should, take a step back and validate everything before moving on. Have the TOTP i
168.
▲
by
diggan
1y ago
> This isn’t exactly true. My password manager fails to recognise the domain I’m on, all the time. I have to go search for it and then copy/paste it in. I'd probably go looking for a new password manager if it fails to do one o
169.
▲
by
diggan
1y ago
> based on an actual MIT study Speaking of which, anyone have a link to the study itself? Since the linked marketing post doesn't even provide a link to it, just a bunch of links to their own platform and social media accounts. Prob
170.
▲
by
diggan
1y ago
> so the rest of us know what not to do? Can't really tell you what not to do, but if you're not already using a password manager so you can easily avoid phishing scams, I really recommend you to look into starting doing so. In
171.
▲
by
diggan
1y ago
> Yes, I've been pwned. First time for everything, I suppose. It was a 2FA reset email that looked shockingly authentic. I should have paid better attention, but it slipped past me. Sincerely sorry, this is embarrassing. My worst ni
172.
▲
by
diggan
1y ago
> I understand their was hope that GitHub would be open sourced, but I don't think there was any reason to believe it would happen. Yeah, I don't think me myself had good reasons beyond "They seem like the good guys who wo
173.
▲
by
diggan
1y ago
> I think GitHub added the “pull request” as a really useful add on to git and that really made it take off. Personally, I remember the initial selling point of GitHub being that it was more "social" than any other forges at th
174.
▲
by
diggan
1y ago
> So, (re)defining language constructs in a project seems nightmarish to me to support in production and therefore I never even attempted anything serious in a functional programming language. It can be, but also not. If you isolate them
175.
▲
by
diggan
1y ago
> In practice, by and large, with very few exceptions, macros are frowned upon in the same way that using metaprogramming in ruby is. Macros are only fun to the person writing them (and not even the author when they have to maintain it).
176.
▲
by
diggan
1y ago
Yes, you don't have to keep on selling it to me, you've hit oil already! I'm eager to reach the future :)
177.
▲
by
diggan
1y ago
> Was GitHub really critical at time of purchase? Do you think they would have bought it otherwise? Same for NPM, they got bought for huge sums of money because they were "critical" already.
178.
▲
by
diggan
1y ago
They used Emojis and printed "Microsoft <3 Open Source" on posters for conferences, so clearly they really had changed...
179.
▲
by
diggan
1y ago
Yes, there was a couple of years we all believed GitHub would eventually turn into a open platform made by and for FOSS, but then they took on VC investments after some years and the dream went into hiding again.
180.
▲
by
diggan
1y ago
> It would be nice and welcome, but it wouldn’t revolutionize anything. I dunno, it'll certainly revolutionize my world once it's ready. A editor connected REPL, changes to running games on the fly while keeping existing state,
More ›