Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
strogonoff
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
91.
▲
How do the microplastics in our bodies affect our health?
(bbc.com)
3 points
by
strogonoff
6mo ago
|
0 comments
92.
▲
by
strogonoff
6mo ago
> BPA is a known endocrine disruptor. Although initially considered to be a weak environmental estrogen, more recent studies have demonstrated that BPA may be similar in potency to estradiol in stimulating some cellular responses. https
93.
▲
by
strogonoff
6mo ago
Infinite growth is not the only way.
94.
▲
by
strogonoff
6mo ago
Many arguments regarding the current incarnation of ML and its mainstream uses go like this: — It will take our jobs. — That is not a failure of automation, it’s a failure of our socioeconomics. — That doesn’t make it a non-issue. People ne
95.
▲
by
strogonoff
6mo ago
> How big is your repo It’s a subjective question, but in one of the zero-installs projects I definitely remember that when I added a couple of particular GUI libraries there suddenly a very, very long list of new files to track, since t
96.
▲
by
strogonoff
6mo ago
A fundamental (but sadly common) error behind “tokens are units of thinking” is antropomorphising the model as a thinking being. That’s a pretty wild claim that requires a lot of proof, and possibly solving the hard problem, before it can b
97.
▲
by
strogonoff
6mo ago
Personally, the unnerving fact is not that ambient carbon dioxide is harmful in current concentrations (it almost certainly isn’t), but more that the average baseline concentration outdoors (which we have to live with and cannot really esca
98.
▲
by
strogonoff
6mo ago
I definitely should’ve reviewed that last paragraph one more time…
99.
▲
by
strogonoff
6mo ago
It’s crazy to think that: — middle-aged people alive today experienced a 35% increase in average ambient atmospheric carbon dioxide concentration within their lifetimes [0], and — ambient atmospheric carbon dioxide concentration today has
100.
▲
by
strogonoff
6mo ago
All communication is inherently lossy, and text is extremely so. Knowledge, insight, etc., is never captured in its entirety in communication. Indeed, there is no direct contact between human minds, not in the models we currently have. Comm
101.
▲
by
strogonoff
6mo ago
Arguably, humans are 4-dimensional beings living in a 4-dimensional world—it’s just that one of the dimensions is accessible with much fewer degrees of freedom. (Not unlike how a seemingly 2-dimensional world of a top-down FPS is actually 3
102.
▲
by
strogonoff
6mo ago
> making the lockfiles more complicated? Poor phrasing; I meant the attacks. Now you don’t just have a lockfile you need to sneakily modify, and the diff grows. As to your second point, yes. It’s really a different feeling when you add o
103.
▲
by
strogonoff
6mo ago
> I don't think so. This is already the situation. Maintainers already fix vulnerabilities when they know about them. This is already the situation and it is a problem and that is why we are talking about it. > If the situation i
104.
▲
by
strogonoff
6mo ago
> I'm assuming it has maintainers (they play the role of defenders). A maintainer has a full-time job: to develop software. A maintainer who is also a defender has two full-time jobs, and as we all know in such a case one of these
105.
▲
by
strogonoff
6mo ago
Are you saying it replaces my package manager, or that I should add another tool to my stack, vet yet another vulnerable dependency for critical use, to do something my package manager already does just as well? > You ~never want to vend
106.
▲
by
strogonoff
6mo ago
If a product looks pretty and seems to work great at first experience, but is really an unmaintainable mess under the hood, has an unvetted dependency graph, has a poorly thought through architecture that no one understands, perhaps is unsu
107.
▲
by
strogonoff
6mo ago
> > exploiting software is someone’s full-time job, whereas the engineers already have one—building it. > But the attackers needs to spread their attack over many products, while the engineers only need to defend one. Are you assum
108.
▲
by
strogonoff
6mo ago
> you'd need to install the depdencency the first time to get it in VC, but then suddenly down when doing a deploy. Which dependency? It sounds like you are assuming some specific scenario, whereas the fix can take many forms. In im
109.
▲
by
strogonoff
6mo ago
The higher the productivity multiplier towards exploiting software, the more developers would find themselves severely outmatched: exploiting software is someone’s full-time job, whereas the engineers already have one—building it. To expres
110.
▲
by
strogonoff
6mo ago
Zero-installs mode does not replace the lockfile. Your lockfile is still the source of truth regarding integrity hashes. However, it’s an extra line of defence against 1) your registry being down (preventing you from pushing a security hotf
111.
▲
by
strogonoff
6mo ago
Essential steps to minimise your exposure to NPM supply chain attacks: — Run Yarn in zero-installs mode (or equivalent for your package manager). Every new or changed dependency gets checked in. — Disable post-install scripts. If you don’t,
112.
▲
by
strogonoff
6mo ago
As it tends to be in philosophy, there’s no experimental way to prove it one way or the other, and you’d have to contend with subsets of both consciousness-first monistic idealists (for whom p-zombie is a very real concept) and monistic phy
113.
▲
by
strogonoff
6mo ago
> I was made redundant recently "due to AI" (questionable) and it feels like my works in some way contributed to my redundancy where my works contributed to the profits made by these AI megacorps while I am left a victim. This
114.
▲
by
strogonoff
6mo ago
As humans, we have certain rights and freedoms established in law (and that setting aside sentience, agency, and free will). Until an LLM has such rights and freedoms—which is very unlikely, not even on philosophical basis but just because
115.
▲
by
strogonoff
7mo ago
1. Photography is critical in many life or death activities like murder investigations. 2. I take it you would be fine if software official documentation for spelled JSON as “jeyson” or something equally random.
116.
▲
by
strogonoff
7mo ago
E2EE works in favour of politicians, so I would be surprised if they went against it. Prior to this, if they wanted to discuss something shady, they would have to choose between a clandestine in-person meeting (sort of hard do conduct when
117.
▲
by
strogonoff
7mo ago
Arguably, it’s worse, because it is commercial use at scale. It’s more akin to public redistribution than private consumption.
118.
▲
by
strogonoff
7mo ago
There’s an undeniable pattern, though.
119.
▲
by
strogonoff
7mo ago
Buying commercially available location records from data brokers would be far less concerning without the capability to, per Anthropic’s CEO words, assemble from that data “a comprehensive picture of any person's life—automatically and
120.
▲
by
strogonoff
7mo ago
It’s interesting to see how as soon as intellectual property theft starts to be critical for powerful interests the legal system magically gets more lenient about copyright enforcement. The balance between public good and protecting IP owne
More ›