e. hashman 🇵🇸
mastodon 4.5.18International florespondent, 🇨🇦 settler south of the medicine line, exhausted tech worker. Tea aficionado. Amateur botanist, naturalist, and radio operator. Godmother of cloudisland.nz ☁️🏝️ אין אלע גאסן וווּ מען גייט... Fighting severe ME/CFS. ♿
Public alt of @ehashman@toot.cat
Someone said something about ingesting libc and this is what popped into my head
You know, if LLMs really make code generation as cheap and easy as it's predicted, we are staring down an industry-wide Lisp Curse situation
Ok, I read through HuggingFace's description of this security incident because I was curious, and here is my analysis based on the public information. There are two major mistakes in this scenario:
- OpenAI should not have run Artifactory on a node with public internet access. It could have been a local mirror.
- HuggingFace seemed to rely on locked down network access for their prod security while not implementing basic security measures on their Kubernetes cluster(s).
https://huggingface.co/blog/agent-intrusion-technical-timeline
I am loathe to tell people what not do without giving them some useful advice for what they should do instead. If you are relying on Proton for "secure email" please read my security 101 guide for what to do instead and the limitations of all these tools https://hashman.ca/security-101/
LLMs are talking pet rocks and you can't convince me otherwise
Before going to bed last night, a friend told me they were already hearing bombs dropping (in the Middle East, but not in Iran or Israel). Their flights back to the US got cancelled.
Millions of people who don't want a war dragged into it anyways. I'm praying for the living and mourning the dead.
Large language models can effectively convince people to believe conspiracies 🤔 https://arxiv.org/pdf/2601.05050
One thing I find kind of fascinating about talking to LLMs is that the text they generate is like talking to oneself in a mirror: extremely predictable, a shallow repackaging of the prompt. To those that treat LLM output as authoritative, this provides a straightforward path for manipulation.
That many people seem incapable of recognizing this reminds me of cats that can't recognize their own reflection.
Can't believe they called it bcachefs when "I Can't Believe It's Not btrfs!" is right there



