Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rfoo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
91.
▲
by
rfoo
1y ago
Well, I don't know kCFI being enabled on any distro besides Android, cause it requires building the kernel with Clang. The previous in-kernel CFI implementation (before the kinda joint effort - kCFI) was upstreamed by Google, too: htt
92.
▲
by
rfoo
1y ago
So, here is a tweet from Eduardo highlighting that they got a lot of 0day submissions immediately after they launched the promotion: https://x.com/sirdarckcat/status/1681491274489282565 And the spreadsheet is publ
93.
▲
by
rfoo
1y ago
Not all. For example kCFI is kernel space. Also, attack surface reduction is a very valid strategy, so it may seem like about the userspace (sandbox for every apps etc) but it could make a big different in how much of the kernel attack surf
94.
▲
by
rfoo
1y ago
I thought when people say "Linux security is a myth" they were comparing it to FreeBSD / OpenBSD. So it's revealing that most are comparing Linux to Windows here.
95.
▲
by
rfoo
1y ago
That would be a different meta-game and while I didn't think deep into it, I believe the likely outcome is - people are just discouraged and won't consider submitting to kernelCTF.
96.
▲
by
rfoo
1y ago
Boss want a strictly fixed budget for running those cool programs. The rationale behind these programs (at least partially) is about measuring exploits and mitigations dynamics, not buying bugs. And, Linux is just too buggy that if you pay
97.
▲
by
rfoo
1y ago
No. Like "master" as a branch name, even if it's perfectly fine in this context, as long as it could be suggesting the word use in a problematic context, it should be banned. That's how we banned "master" as a
98.
▲
by
rfoo
1y ago
As secure as all MCP servers!
99.
▲
by
rfoo
1y ago
Right, the problem is when I amended one of my patches there's no way for the reviewer to look at a diff between current and previous versions.
100.
▲
by
rfoo
1y ago
The "cursed multidimensional index rearrangement" is mostly for doing inner product in the weird way demonstrated. Granted, it proves author's point - you need to be fluent in NumPy to write this and can't take the Go ap
101.
▲
by
rfoo
1y ago
There's a very large gap between being super nice to a human and being a jerk. I don't think it benefits me much by very politely suggesting that its approach may not work and emphasize on the good part of the idea it generates an
102.
▲
by
rfoo
1y ago
I think you always can. In the past you may lose some features / have some bugs. For recent kernel versions (>= 6.6) the only patches WSL kernels have is dxgkrnl + some hacky fixes for clock sync. Others are all in upstream already.
103.
▲
by
rfoo
1y ago
Nah, the closest thing to WSL on macOS is OrbStack. Exactly same experience to WSL - great out of the box experience, easy to use, and insist on using their own patched kernel.
104.
▲
by
rfoo
1y ago
Okay. Then you had a Mac. Then you need to run Linux in a VM anyway because similar to Windows, macOS is also a dumpster fire. Then why bother? You are going to have a Linux VM anyway. I usually just sync my VM disk between all my laptops &
105.
▲
by
rfoo
1y ago
You don't need to be nice to your virtual junior devs. Saves quite a lot time too. As long as I spend less time reviewing and guiding than doing it myself it's a win for me. I don't have any fun doing these things and I'
106.
▲
by
rfoo
1y ago
That's the mindset that leads to the funny result that `uv pip` is like 10x faster than `pip`. Is it because Rust is just fast? Nope. For anything after resolving dependency versions raw CPU performance doesn't matter at all. It&#
107.
▲
by
rfoo
1y ago
> Does free-threaded Python provide the same guarantees Mostly. Some of the "can be pre-empted on the boundary between any two bytecode instructions" bugs are really hard to hit without free-threading, though. And without free-
108.
▲
by
rfoo
1y ago
mid/post training does not cost that much, except maybe large scale RL, but even this is more of an infra problem. If anything, the cost is mostly in running various experiments (i.e. the process of doing research). It is very puzzling
109.
▲
by
rfoo
1y ago
> Tons of training data (benefiting from all the JS examples as well) More != better.
110.
▲
by
rfoo
1y ago
> the fastest completion since it would run locally We are living in a strange age that local is slower than the cloud. Due to the sheer amount of compute we need to do. Compute takes hundreds of milliseconds (if not seconds) on local ha
111.
▲
by
rfoo
1y ago
You know, sometimes I really wonder, if Uyghurs aren't white, are US/EU still going to make stretch to call the human right abuse during China's version of "counter-terrorism war" in Xinjiang "genocide"
112.
▲
by
rfoo
1y ago
It's not something you should talk to. In concept it's more like AlphaProof, just with some of their research artifacts (and probably a paper / tech report later) shared with the community.
113.
▲
by
rfoo
1y ago
Yeah, I'm sure killing a major revenue stream helps an organization to focus on keeping its cost center going and get rid of other shots trying to bring in more revenue /s
114.
▲
by
rfoo
1y ago
It could be as simple as something like, someone previously at Instagram decided to join OpenAI and turns out nobody stopped him. Or even, Sam liked the idea.
115.
▲
by
rfoo
1y ago
If you want a dick move like this it's better to do so after . OpenAI consistently pull this trick on Google.
116.
▲
by
rfoo
1y ago
It's interesting that the release happened at 5am in China. Quite unusual.
117.
▲
by
rfoo
1y ago
The model does have some bias builtin, but it's lighter than expected. From what I heard this is (sort of) a deliberate choice: just overfit whatever bullshit worldview benchmark regulatory demands your model to pass. Don't actual
118.
▲
by
rfoo
1y ago
> flawed enough starting premise That's where we start to disagree what future looks like, then. It's not there yet, in that the LLM-clone isn't good enough. But amusingly a not nearly good enough clone of me already made
119.
▲
by
rfoo
1y ago
This is great idea! But it's more about having LLMs to give function & variables names, instead of having LLM to deobfuscate. The (traditional) deobfuscations (e.g. unpack, de-flatten, de-virtualization etc) were done by 100% preci
120.
▲
by
rfoo
1y ago
I'd recommend having a "gemm with a twist" [0] example in the README.md instead of having an element-wise example. It's pretty hard to evaluate how helpful this is for AI otherwise. [0] For example, gemm but the lhs is i
More ›