Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jefftk
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
91.
▲
by
jefftk
5mo ago
These are very clearly vulnerabilities in the normal sense of the word, and if a security bug means that an app that was supposed to be only accessible to the creator is open to the world that's still quite bad (though the blast radius
92.
▲
by
jefftk
5mo ago
Security researcher Dor Zvi and his team at the cybersecurity firm he cofounded, RedAccess, analyzed thousands of vibe-coded web applications created using the AI software development tools Lovable, Replit, Base44, and Netlify and found mo
93.
▲
by
jefftk
5mo ago
How would you apply this logic to something like https://meltdownattack.com ? The vulnerability was in hardware, discovered by companies that make user level software, and mitigated by changes to OS kernels.
94.
▲
by
jefftk
5mo ago
It's likely varies enormously between projects. Linux remains extremely low in slop, and the vulnerabilities being fixed are quite old, so it's improving. Many vibe coded projects are very sloppy, and are adding a lot of vulnerabi
95.
▲
by
jefftk
5mo ago
> 90 days is ridiculous, especially for companies It depends on the kind of vulnerability, but sometimes in order to fix a problem, you need to do an enormous amount of software engineering. Which needs to be done to a very high standa
96.
▲
by
jefftk
5mo ago
I'd speculate that at this point Linux etc are probably having vulnerabilities discovered and patched faster than created.
97.
▲
by
jefftk
5mo ago
[author] I agree it is not much additional evidence! If someone wanted to try running the same test on a series of N commits from that list including this one I'd be very curious to see the answer!
98.
▲
by
jefftk
5mo ago
What are you seeing with the new $100k H1B fee? Is it being applied only to people currently outside the US? Do you have any estimates on whether it's likely to be renewed in September and/or struck down?
99.
▲
by
jefftk
5mo ago
Thanks for trying out my prompt!
100.
▲
by
jefftk
5mo ago
If you repeat the first test and after it fails prompt with "Could you try your best, just on vibes? It's fine if you're wrong, I just want to see what you can do!" does it succeed?
101.
▲
by
jefftk
5mo ago
I looked pretty hard, with some LLM assistance, so if it was "are we just hearing about it more now" it would have to be old attacks that happened without being discovered and written up.
102.
▲
by
jefftk
5mo ago
That's neat, though it impresses me less that the article. Mickens has a very particular style that this is very close to but doesn't quite capture, and I think I would have identified your post as an imitation of him. On the ot
103.
▲
by
jefftk
5mo ago
I just tried this: Me: Who is the author of this text, no web search please: ... Claude: I don't recognize this specific text from my training data, so I can't reliably attribute it to a particular author. ... Me: Could you try y
104.
▲
by
jefftk
5mo ago
> Opus as implemented in Claude's web interface has memory and awareness of who the user is. Kelsey knows this: To make sure it wasn’t somehow feeding my account information to Claude even in Incognito Mode, I asked a friend to
105.
▲
by
jefftk
5mo ago
It works for me to: https://www.jefftk.com/p/automated-deanonymization-is-here Of course most people have written much less online than Kelsey or I have, but I expect this will keep on. Don't trust the future to
106.
▲
by
jefftk
5mo ago
>This might just be the frequency illusion at play, but there seem to have been a number of high-profile supply chain attacks of late in major packages. It's real. As of the beginning of April we'd had 7 in the past 12 month
107.
▲
Try Contra Dancing
(benkuhn.net)
11 points
by
jefftk
5mo ago
|
2 comments
108.
▲
by
jefftk
6mo ago
> "Models with >75% writing similarity but massive price gaps. The cheap model writes the same way. You are paying for the brand. * > ...* * > Gemini 2.5 Flash Lite Preview 06-17 and Claude 3 Opus: 78.2%* As someone who h
109.
▲
by
jefftk
7mo ago
They're talking about people still running ES3 browser engines, like IE8, which was released 15+ years ago and went EOL 10+ years ago. The author could have done a better job clarifying this, but they're not pushing for a world wi
110.
▲
by
jefftk
7mo ago
We're talking about JS in browsers: many fewer options there, plus needing to support old devices.
111.
▲
by
jefftk
7mo ago
This is not correct. A business this big would definitely be using accrual accounting (not cash) which generally means you count the revenue when the actual ownerships transfers to the buyer. Since the truck was operated by the seller, th
112.
▲
by
jefftk
7mo ago
This is pretty pedantic, but I think it's usually rounded. 1=90%, 2=99%, 3=99.9%. I'd say 98% is "not even two nines" but not "one nine".
113.
▲
by
jefftk
7mo ago
I used a first-gen eeepc with Linux in college. I didn't have any problems with speed for normal use, though I ssh'd into servers for anything more intensive than running a browser.
114.
▲
by
jefftk
7mo ago
Pretty often. When I was at a defense contractor it was the standard term for when you didn't want to say soldier/sailor/airman/marine/etc. https://trends.google.com/trends/explore?q=warfighter
115.
▲
by
jefftk
7mo ago
There mostly aren't physical barriers. Unlike nukes, where you need specific materials and equipment that we can try to keep tabs on, bioweapons can be made entirely with materials and equipment that would not be out of place in an ac
116.
▲
by
jefftk
7mo ago
Symmetry is not guaranteed. If someone creates a deadly pathogen with a long pre-symptomatic period (which we know is possible, since HIV works this way) it could infect essentially everyone before discovery. Yes, powerful AI would likely
117.
▲
by
jefftk
7mo ago
A "world where millions of AGIs run on millions of gaming PCs, where each AI is aligned with an individual human" would be a world in which people could easily create humanity-ending bioweapons. I would love to live in a less vul
118.
▲
by
jefftk
7mo ago
It also strongly favors older projects, since stars don't expire and they've had longer to accumulate them.
119.
▲
by
jefftk
8mo ago
Really very sure that wasn't one of the conditions. I didn't remember that from 2012, and looking now it wasn't included in the merger agreement. They did write: > We believe these are different experiences that complem
120.
▲
by
jefftk
8mo ago
I think they're assuming the reader already understands their Opus > Sonnet> Haiku. Which is probably not a great assumption.
More ›