Interesting read: @conservancy@social.sfconservancy.org has a post capturing some of their thoughts on LLM-assisted code contributions: https://sfconservancy.org/llm-gen-ai/llm-backed-generative-ai-recommendations.html
Remote
Kyle Rankin
@kyle@mastodon.kylerank.in
mastodon 4.2.24
Linux security & infrastructure professional, FOSS advocate, public speaker, author of How To Write A Tech Book, Linux Hardening in Hostile Networks and many other books, ex-Linux Journal columnist, weaver.
2210 Followers
102 Following
39 Posts
Joined April 27, 2023
Personal Site:
Personal Bibliography:
Previous Mastodon Account:
Open post
Replying to
Time to clean and restore the typewriter!
7
2
1
0
Open post
Replying to
The manual has strong opinions on finger posture.
6
1
0
0
Open post
Replying to
I showed this in a comment, but I figured if you are following this thread, you may want to see a close-up look at the typing element. This cylinder rolls clockwise and anti-clockwise depending on the keys you press, and then as you finish depressing it presses the cylinder against the ribbon and paper, leaving the impression.
6
1
0
0
Open post
Replying to
Back together after a good cleaning and oiling. I’ll have to track down a new ribbon before I can do a full test.
6
3
0
0
Open post
Replying to
I ordered a reproduction of the original manual and it just arrived! I think “Read Carefully Before Touching Machine” is good advice in general.
4
1
0
0
Open post
Replying to
Here is a closer look at the key mechanism:
3
2
0
0
Open post
Replying to
A few more screws and I can separate the bottom frame.
3
2
0
0
Open post
Open post
Replying to
I appreciate how easy this is to work on. I just removed two thumb screws and the full keyboard was easily removed. This will be easy to service.
3
2
0
0
Open post
Replying to
The mechanism seems to work even with an old ribbon. The platter is really hard and if I really wanted to use this the next step would be to send that off to be restored.
2
1
0
0
Open post
Replying to
@mirth@mastodon.sdf.org @jzb@hachyderm.io Yes, exactly this. I elaborate on the point in the blog post.
3
0
0
0
Open post
Replying to
@jzb@hachyderm.io While I didn't write a book on it, I did write a pretty long blog post on it recently. tl;dr: MacOS X also shares a good deal of the blame.
https://kylerank.in/blog/linux-desktop-renaissance.html
2
3
2
0
Open post
Replying to
@jonny@neuromatch.social @Viss@mastodon.social Yeah they continually reference "find *and exploit*" [emphasis mine] in their blog post, but I continually see people focus only on the "find" part. https://red.anthropic.com/2026/mythos-preview/
1
0
0
0
Open post
Open post
Open post
Replying to
@apples_and_pears@mastodon.world I will say that the keyboard layout is pretty rough. I'm sure it was okay for hunt-and-peck typists, but for a touch typist the layout would be difficult.
1
1
0
0
Open post
Replying to
@apples_and_pears On the right side there is a lever that advances it one row. You have to slide the carriage back yourself.
1
0
0
0
Open post
Replying to
@Viss@mastodon.social @cR0w@infosec.exchange Have you used OpenSnitch in the past on Linux? If so I'd be curious to hear your impressions on how this LittleSnitch port compares.
1
1
0
0
Open post
Replying to
@isagalaev@mastodon.social @chrisjrn@social.coop There have been plenty of high-profile rewrites over the years in Open Source too. I remember when CORBA was the key to sustainable architecture for GNOME, or should I say, the GNU Network Object Model Environment.
1
6
0
0
Open post
Replying to
@isagalaev@mastodon.social @chrisjrn@social.coop The corporate world has embraced LLMs for the same reason they embraced cloud (outsourced sysadmin/neteng), and any tool that allows them to either outsource or reduce their highly-paid staff.
While some companies are looking at this as a way to increase the productivity of their current staff, most are trying to figure out how to match current productivity with fewer people (and ultimately with less expensive, less trained people). Luddites all over again.
1
0
0
0
Open post
Replying to
@yaelwrites You do great work! I have no doubt you’ll find your next adventure quickly.
1
0
0
0
Open post
Open post
Open post
Replying to
@micahflee@infosec.exchange Congratulations on your first Wired article! Great write up.
1
0
0
0
Open post
Replying to
@shawnp0wers @kyle@librem.one @aral It was pretty straightforward really, just followed the docs. The only complication on my side was due to wanting a different webhost, but that was a one-line change, as was switching from single-user mode to multi-user.
1
0
0
0
Open post
""We're not incentivized to push one model or the other," Enzor-DeMeo told The Verge."
Not incentivized *yet*. The Mozilla push to integrate AI into the browser finally makes sense to me and I can't believe I didn't see the strategy before. It's not about the hype cycle, it's all about getting a lucrative investment ala Google from these AI companies to push a particular model as the default.
https://www.theverge.com/tech/845216/mozilla-ceo-anthony-enzor-demeo
0
0
0
0
Open post
Replying to
@Viss@mastodon.social @jonny@neuromatch.social I didn't, and I definitely think marketing is making a lot of hay with it, but after that interview, I'm inclined to think that regardless of how it was marketed, that the original intention behind the embargo was reasonable.
I think too many security folks get far too hung up on whether it is significantly better at finding vulns, when that wasn't really the point. Niels Provos has great research showing that with the right harness you can get similar results from other models.
0
1
0
0
Open post
Replying to
@alison@burningboard.net I don't have an up-to-date answer for this. Part of this is that I'm not entirely sure where all the technology behind Find My features come into play, and without digging in, I couldn't say with confidence what is off at what power stages.
0
0
0
0
Open post
Open post
Replying to
@chrisjrn@social.coop Many projects historically have grown in complexity past the point that maintenance and adding features were tolerable. Someone makes the call to rewrite from scratch, even though it's expensive.
The difference now is the initial code was faster/cheaper to begin with, as is the cost to rewrite from scratch. Code will more quickly get to the rewrite-from-scratch point, and when adding a feature hits that point, teams will be more likely to take that route. Fast fashion.
0
2
0
0
Open post
Replying to
@chrisjrn@social.coop I suspect maintenance of LLM code, in the long term, will be less and less important for the same reason that few people know how to darn socks or patch clothing. When something is cheap enough that the opportunity cost of maintenance is similar to the thing itself, people tend to dispose of the thing and replace with something new.
0
4
1
0
Open post
Replying to
0
0
0
0
Open post
Replying to
@Viss@mastodon.social @jonny@neuromatch.social Sorry to hear that, that sucks :(. It's possible some other outlet also interviewed him, I just think it's informative to hear what a security lead inside the company has to say about their thinking around the embargo, because I still see a lot of discussion about finding vulns, but not about the exploit side of it.
0
1
0
0
Open post
Replying to
@Viss@mastodon.social @jonny@neuromatch.social I found this Risky Business interview with Nicolas Carlini from Anthropic informative. He talks through the reasoning behind the Mythos embargo, and a lot of folks mis-reported the reason why Anthropic was embargoing Mythos.
It wasn't that it was significantly better at findings vulns than past models, it was that it was significantly better at developing working exploits for the vulns it found.
https://www.risky.biz/video/feature-interview-nicholas-carlini-anthropic/
0
1
0
0