dysfun@treehouse.systems ("gaytabase") wrote:
The second method, called depth subtyping, replaces the various fields with their subtypes. That is, the fields of the subtype are subtypes of the fields of the supertype.
glad we cleared that up!
dysfun@treehouse.systems ("gaytabase") wrote:
The second method, called depth subtyping, replaces the various fields with their subtypes. That is, the fields of the subtype are subtypes of the fields of the supertype.
glad we cleared that up!
Boosted by soatok@furry.engineer ("Soatok Dreamseeker 🔜 Megaplex"):
david_chisnall@infosec.exchange ("David Chisnall (*Now with 50% more sarcasm!*)") wrote:
This article starts with a story from someone who tried Claude Code and found it amazing, but then switches to the same person a few months later seeing what a disaster it’s been. This quote is key:
The problem is that code produced by an AI agent looks reasonable, but can contain ‘hard-to-spot bugs’ that end up causing major problems
LLMs, by their nature, generate statistically plausible output. That is often a set that overlaps with correct output. But the things that are not correct look exactly the same as the ones they are.
Learning to review code is hard. You look for the bugs that you expect to be possible implementing it by using your theory of mind for the person writing the code and the kinds of things that they might overlook (not necessarily a specific person, but the kinds of things people miss) and also common bug classes.
And the big help is that the person writing the code is not thinking adversarially. They are not trying to sneak bugs in. Normally. Unless they’re a supply-chain attacker, and we’ve a depressing amount of evidence that code review doesn’t catch supply-chain attacks.
An LLM is not trying to do anything. It has no intent. But it is a machine that is trained on code that made it past code review. The kind of bugs that it will generate are ones that look like code that appeared in production. This is exactly what an attacker would do: try to write code that looks correct but is subtly wrong.
I’m only being slightly flippant when I say LLMs are a mechanism for brining supply chain attacks in house.
Boosted by soatok@furry.engineer ("Soatok Dreamseeker 🔜 Megaplex"):
mjg59@nondeterministic.computer ("Matthew Garrett") wrote:
If your vulnerability description is AI written I'm going to assume that you don't actually understand the issue and I am going to accord you no credit
Boosted by dysfun@treehouse.systems ("gaytabase"):
fesshole ("Fesshole 🧻") wrote:
On my academic website I have a link to "See my OnlyFans page" which goes to photos of ceiling fans and pedestal fans around my home. I am a tenured professor.
dysfun@treehouse.systems ("gaytabase") wrote:
Deprecated, Move to ShiTT2
dysfun@treehouse.systems ("gaytabase") wrote:
good god, elegia is a cracking song but it doesn't half go on forever. and not in a good way like a pink floyd b side.
dysfun@treehouse.systems ("gaytabase") wrote:
low-life is such a good album.
except love vigilantes, i always skip that
dysfun@treehouse.systems ("gaytabase") wrote:
i love the way IBM just bought a bus and made it the 'blockchain bus' because they couldn't think of anything better to advertise how serious they were about the latest fad.
what they should have done is chained a convoy of cars together
dysfun@treehouse.systems ("gaytabase") wrote:
lol i wonder if IBM blockchain is still a thing. not enough to google it ofc.
dysfun@treehouse.systems ("gaytabase") wrote:
does anyone remember the DANK IBM BLOCKCHAIN ads?
there's this one of a farmer looking ecstatic in a field full of cabbages i wouldn't mind finding again. just because it's funny
dysfun@treehouse.systems ("gaytabase") wrote:
right, let's see if a bit of new order can perk me up.
dysfun@treehouse.systems ("gaytabase") wrote:
i used to be a pacifist. it's funny what the world this decade does to a person
dysfun@treehouse.systems ("gaytabase") wrote:
if clod is so smart how come *smack* it didn't stop me doing that?
dysfun@treehouse.systems ("gaytabase") wrote:
begging to be put in a room with some AI CEOs actually, i haven't had a good punchup in ages.
dysfun@treehouse.systems ("gaytabase") wrote:
i would love to just go back to sleep, but my body seems reluctant.
not that i can really blame my body, my mattress needed replacing a couple of years ago,, so instead i blame the reason i can't afford a new one.
dysfun@treehouse.systems ("gaytabase") wrote:
i have had 4 hours sleep and i have a horrible headache.
in the spirit of spreading the joy, i'd like to wish every company that's failed to hire me this decade a very go bust.
how are folks feeling about https://agentscan.tools ? I've seen several folks (including one of my comaintainers) start sending links to this when asking folks "did you use an LLM here?"
it feels rude, I don't like using "LLM detectors", but, maybe this is just the new etiquette now
aredridel@kolektiva.social ("Mx. Aria Stewart") wrote:
They're so often better than the systems they were replacing.
But the systems they were replacing were degraded by underinvestment or actively being undermined.
aredridel@kolektiva.social ("Mx. Aria Stewart") wrote:
The thing that frustrates me more than anything with these AI systems is the meta-level: Who gets to decide how to use them and put them where, and who is responsible for the effects that has on the world?
They work pretty well in a lot of the contexts they're shoved in. But they have huge impacts to learning, to information validation, to so many of the meta level processes that can so severely degrade our societal knowledge.
EmilyEnough@hachyderm.io ("Emily 🏳️🌈🏳️⚧️") wrote:
Ugh. Just killed a brown recluse spider in the basement that was heading for my laundry basket. Time to burn the place down and start over.
So here let me embarrass myself as publicly as possible and just annihilate this stupid little personal demon's power: reader, I had to write down "move CSV file to 'processed' directory", "get pen out of drawer", and "launch Emacs" as individual to-do items today. Instead of just writing them down immediately, apparently I needed to tell myself "I'm an adult! I should just go do these things! I don't need to break these down that far, that's just silly!" as if that would save time
At 46 I am still unlocking new weird little #ADHD trauma artifacts. Sitting alone by myself and trying to get work done, facing some cognitive resistance, I apparently find it *embarrassing* to do the thing that I know is going to get me unstuck (to wit: writing down comically small individual tasks in my to-do list to plan the project that I'm stuck thinking about one tiny action at a time).
jscalzi@threads.net ("John Scalzi") wrote:
BUY ALL THESE BOOKS
Boosted by glyph ("Glyph"):
hugo@treehouse.systems ("Hugo Slabbert ⚠️") wrote:
@glyph pathological overthinking in the age of the Not Thinking Enough Machine
also just gonna take a little victory lap here that I was so obviously correct about this particular architectural feature that the old style of API from before they fixed this issue is being slowly deprecated https://github.com/stripe/stripe-python/wiki/Migration-guide-for-v8-%28StripeClient%29
In 2018, I filed this issue:
https://github.com/stripe/stripe-python/issues/392#issue-292517299
In 2024, they implemented the fix:
https://github.com/stripe/stripe-python/pull/1200
In 2026, I once again have occasion to call this API, and I am pleased to discover that I get a regular old object with type annotations and stuff that I can easily partially mock if I want to for testing, instantiate multiples of for different accounts, whatever.
File that bug that's bothering you. Sometimes it's very much worth it even if it takes a while.
Boosted by kornel ("Kornel"):
molly0xfff@hachyderm.io ("Molly White") wrote:
Often when there’s a “crypto winter”, it can take a little while before we start to see the fallout. But it seems to be emerging now, with three crypto exchanges announcing shutdowns in July, and multiple high-profile web3 projects closing up shop recently.
#crypto #cryptocurrency #USpolitics #USpol #CitationNeededNewsletter
Boosted by kornel ("Kornel"):
rebane2001@infosec.exchange ("Rebane") wrote:
i love seeing creative qr code designs, so i made this guide explaining what tricks you can (and can't!) do with qr codes while still keeping them very much readable
have fun and make cool stuff!!
Boosted by glyph ("Glyph"):
AlSweigart ("Al Sweigart") wrote:
- What do you think of the term "prompt engineering"?
- Are you in software or IT or tech?
Boosted by neatnik@social.lol ("Neatnik :prami:"):
macmanx@social.lol ("James Huff :prami_pride:") wrote:
No alt text = no boost. It's quite literally the least we can do to help those who need it. :janky_ty: