Boosted by db@social.lol ("David Bushell 🪿"):
maisie@tech.lgbt ("maisie 💖") wrote:
WAS IT WORTH IT? https://mbell.dev/post/was-it-worth-it/
Boosted by db@social.lol ("David Bushell 🪿"):
maisie@tech.lgbt ("maisie 💖") wrote:
WAS IT WORTH IT? https://mbell.dev/post/was-it-worth-it/
Boosted by glyph ("Glyph"):
mcc wrote:
"Honor system" cryptocurrency
Boosted by cstanhope@social.coop ("Your weary 'net denizen"):
laemeur@mastodon.sdf.org ("LÆMEUR") wrote:
I've put the first eight pages of Battlers of Durra: Soulstone of The Ur-Lich online as a bit of a teaser, while I shop the book around to publishers. If anyone wants to have a look, it's here: https://laemeur.com/Durra/Soulstone
For those unfamiliar with "Battlers..." here's the project brief on my Patreon: https://www.patreon.com/laemeur/posts/project-brief-of-155411510
neatnik@social.lol ("Neatnik :prami:") wrote:
I've made some configuration updates that aim to improve social.lol’s server performance. Let me know if you run into any issues!
Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
underzen wrote:
Sometimes I feel that Buddhism (especially western Buddhism and Zen) isn't very family-friendly. I see quite a lot of Buddhists on social media, but most of them don't have children, or at least never talk about them. Nevertheless, I'm a family person, I have two young children and I like buddhism!
So I'm trying my luck: are there any parents here who are interested in Buddhism? I'd love to connect with people who are both into Buddhism and family life.
Boosted by jsonstein@masto.deoan.org ("Jeff Sonstein"):
flyingsaceur@ioc.exchange ("AN/CRM-114") wrote:
Choose your post-Linux self-exile
jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:
what a clown you are, President Bone Spurs https://www.nytimes.com/2026/08/10/us/politics/trump-plane-ruse.html?unlocked%5Farticle%5Fcode=1.4lA.2nYj.HbS-%5F7tms18l&smid=nytcore-ios-share
to paraphrase Warren Buffett on leverage, If you know what you're doing you don't need LLMs and if you don't know what you're doing then it's too risky for you to be using them
jscalzi@threads.net ("John Scalzi") wrote:
Funnily enough, we're all waiting for him to die or leave office too
Boosted by neatnik@social.lol ("Neatnik :prami:"):
robb@social.lol ("Robb Knight") wrote:
Y'all are wrong'uns.
Jeff is a dinosaur, not a penis. Not one of you said anything like this during Inktober so I reckon you're all just being rude and silly.
Boosted by glyph ("Glyph"):
jannem@fosstodon.org ("Janne Moren") wrote:
@glyph
The way to win this is to do what you're doing: show the specific harms, discuss ways to mitigate.Never end with "and it's your fault for using them, and we should ban it all." That's the conclusion you want people to eventually reach for themselves; only then will they actually believe it.
I can easily convince somebody that 100% code coverage is a worthy metric because it is necessary but not sufficient, I can wax rhapsodical about the merits of mocking at various scopes of testing. But I cannot convince them that they do not understand the fundamental degree to which all humans are vulnerable to self-deception because we live in a fallen world. That really feels like it should be out of scope.
But today, in an LLM debate, we say "it makes the defect rate unpredictable". But then the pushback comes back: "it's OK, we'll just add a little process fix. We'll do some code review. We are all Very Careful Engineers around here, it'll be fine."
With other tools, we could do a little work, point at a metric or two and maybe find a useful middle ground. But now we just have to look them in the eye and say: no you aren't. You were never careful enough, before. *We* were never careful enough.
What's bugging me right now is that I have a rhetorical strategy of minimal conflict. I'm not pathologically conflict-averse, I will have the fight that needs to be had, but I will try to avoid big, heavy issues in a technical context, because it's not really possible to win on those issues; consensus is won by inches, and trying to win in a big ideological debate is a detour of several miles. And this makes those massive, unwinnable debates a hard requirement.
Boosted by slightlyoff@toot.cafe ("Alex Russell"):
fugueish@wandering.shop ("Chris Palmer") wrote:
This is a really good article about gourds:
“No one wants to eat a raw pumpkin. It looks like a Dr. Seuss character’s brain, is full of seeds, and has no real taste. But like with any good lie, when the right sugar, spices, a buttery crust, and time in the oven is added, pumpkin pie becomes a cherished classic.”
https://www.currentaffairs.org/news/the-massive-climate-lie-that-will-destroy-human-civilization
Sorry that this thread was way too long and kinda all over the place, I am _really_ struggling to organize my thoughts about all this in a way which is both legible and actionable, and this is just it bubbling over. The pace at which events are routinely overtaking me is now itself overtaking me
And now, we have a tool that looks, without DEEP analysis, much like any other software tool, that can easily fool someone into thinking it is "regular technology", is a devastatingly potent accelerant to this impulse.
Other creative fields, more mature ones, are struggling, Writing and academia and music are all hit hard. But they have intellectual traditions that allow them a scaffolding around which to resist, stories from their history about similar temptations which can be resisted.
And of course — this has ALWAYS been a problem. The Challenger didn't need an LLM to blow up. "Eating your seed corn" is not an expression about OpenAI. There's always this temptation to erode the margin of safety.
But we had a few decades there where the combination of cultural capital, ZIRP, and an amount of earnest idealism that people outside the SF bay tech cultural archipelago often don't appreciate, let us create something that mostly looked like it worked.
It's happening in the open source community but it's also happening on corporate teams. Everyone racing to hit KPI mandates, assuming that surely the infra team won't risk the vigilance decrement that comes along with LLMs, surely *they'll* slowly and carefully build by hand so that *our* app can run atop it. The infra teams rely on OSS libraries, the libraries rely on the kernel. Everyone assuming that they can be a bit less careful and let the quality slide just a bit to get more velocity
This is the logic of the O-ring disaster. Everybody just relies upon everybody else's safety margin — in the software community, that safety margin is built mostly out of earnestness and the willingness to sit with a problem and *really* understand it — and hollows out their own, assuming that the load will fall somewhere else.
https://en.wikipedia.org/wiki/Space%5FShuttle%5FChallenger%5Fdisaster#O-ring%5Fconcerns
But there's _zero_ movement on a pervasive sandbox. Everyone's blithely proceeding as if the OSS packages are still as thoroughly reviewed, despite the majority adopting "agentic" tools. Headline after headline about "rogue AIs[2]" are doing bad stuff, whether it'sd dropping the production database or hacking a competitor.
[2]: random outcome generators with outcomes insufficiently constrained by robust technical safeguards, where human & process-based safeguards have been implicitly eliminated
So, even if we were to accept that LLMs are extremely useful and their utility overwhelms all possible concerns about externalities[1], we would absolutely need to *replace* the load-bearing presumption of good faith that the code we are consuming isn't *trying* to harm us, because now it's not *trying* to do anything, it's just whatever gets through the filters we have put in place. We have to replace it with a sandbox.
[1]: they aren't and it doesn't
But good faith only applies to *moral agents*, and _morally_, (even if I were to concede a maximalist position as to their _efficacy_) an LLM is a random number generator. It might produce some malware to slip by you. You cannot "hold it accountable", there's nothing there to be held to account.
We have previously understood that there is a presumption of good faith amongst the software developer community, that most people on Github, on PyPI, on NPM are not trying to ship you malware. Even the flashy "supply chain attacks" that have shown up over the last decade are the exception not the rule, xz can happen to anyone, but probably xz isn't going to happen to *you*.
jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:
What does this have to do with our present apocalyptic hellscape discourse? Well, coding agents like to run tools, too. Every coding agent is a random die-roll away from running `rm -fr` on your entire project, maybe your entire production database.
2 years ago I gave a talk which is, in part, about how Python virtual environments are unsandboxed by default. They don't run in containers. This is true of every other programming language's development environments, too; `npm install`, `cargo run`, all do vaguely the same thing at this level. https://pyvideo.org/pybay-2024/when-arbitrary-code-execution-is-working-as-intended-what-code-is-python-supposed-to-execute.html
if this is all too abstract and airy then let me ground it in an extremely concrete example that is not a particularly Hot Take but nevertheless deeply impacts our current moment
jsonstein@masto.deoan.org ("Jeff Sonstein") wrote:
"please tell me how I can quickly address your objections so we can meet our KPIs, I have a hard stop in 45 minutes" and "you are a human being with a heart and a mind in community with other humans who must give each other grace and time and enough mutual recognition that we can ever possibly have enough safety margin to allow for us to make mistakes" are not really mutually intelligible discourses