Ouch. OpenAI is giving up. I guess the next step is to be bought by IBM and then sold to Computer Associates.
HN user
OhMeadhbh
.
Some things you may have heard me say:
-- "If you find you're shooting yourself in the foot, do not reload."
-- "Videodrome was a documentary."
-- "Instead of saying 'no', ask how the world would have to change so your answer could be 'yes'."
-- "Belief flows towards that which can be monetized."
-- "Money is theft. The economy is a lie."
-- "Reflexive modernity has made Ballard's 'High-Rise' A love story."
Nortel, RSA, Borland, Linden and SiFive. I keep working for companies that don't know how to do an exit.
I don't do X, Facebook or LinkedIn. The closest thing I have to social media is [[ https://www.youtube.com/@OhMeadhbh ]] where I've uploaded a few retro-computing related videos.
Strangely, this is the video I'm most proud of: [[ https://youtu.be/J-tdfUXi9PI ]]
.
Any indication when v2.9.0 will be released? I'd love to play with this, but the install instructions (at least for linux) don't seem to work. Is it working in Windowsland or on macOS?
sure, but when I worked there, the only abbreviation I remember seeing was LLNL for Lawrence Livermore National Laboratory. But the T:L producers could easily have just used LLL as their own abbreviation.
lol. I remember seeing LLLSDL go by when I originally saw the movie. The funny but is I had just written the internet draft for LLSD, so I was wondering g if someone on the writing staff had been following our work at Linden Lab. More likely it was a coincidence and all the L's meant "Laser."
As a long time emacs user, I appreciated the inclusion of EMACS as an error code. When I moved from TECO to gnu emacs in to 80s, elisp was an advance. Now I have a perpetual todo item... "rewrite emacs in fennel or janet or even minimalisp."
"What was deluxe is now debris..."
I upvoted this post because a) I love hearing people's memories of their first programming interactions and b) Susam's website is delightfully straight-forward: no ads, appeals to download AI apps and the videos are in support of the text. I love it!
and Pagemill and Sitemill. At Bell Canada we had a very early web dev team in '94-'95. At one point pagemill came out and we could hire mostly non technical designers to build web pages. At the time it seemed like magic. We didn't need to have someone who grokked vi standing next to a designer all the time. But the HTML pagemill spat out was horrid. It always added a space to the end of link text and never closed list item elements. I eventually wrote a command line tool that fixed pagemill's output because some of our other tools really didn't like the flavour of HTML-inspired slop it emitted. *
And then I moved to the bay area and noticed there was a road called Page Mill Rd. in Palo Alto and sort of laughed for a bit. Surprised Adobe didn't release a tool called Sandhill.
[*] to be fair, most WYSIWYG page builder tools of the era spat out some sort of crappy subset of HTML, so not trying to say pagemill was the only offender.
join the party.
This kind of misses the point. Or rather... it's necessary but not sufficient. If the goal is to get code you can trust, then you have to trust each package. Origin Integrity will help you with this if you have a list of trusted devs. But what do you do if a trusted dev imports code from an untrusted source?
And there were some amazing RAD and prototyping tools in the 90s (mostly for DOS, but also for Windoze desktop apps.) You're right, we sort of gave up on the idea when everyone wanted to be seen as a "real" software engineer who knew how to sling Java on the back end.
If Google can reuse the "Flash" brand, I'm re-branding myself as "Meadhbh the Merciless."
IPCMSes make it somewhat easy to MitM SMS. If your system poops a cookie in the wrong place it doesn't matter if the secret is in someone's head or if it's in a hardware dongle, like you say... the hacker is "in".
My recommendation for bad guys is to not attack the part of the system where it is strong. Just sniff around a bit until you find the weak part and attack that.
Also remember most devs couldn't use a static analysis tool to save their lives (which is why mythos is relevant.) I suspect that a 15 year old copy of Fortify or CoVerity could find bugs mythos missed.
And if that doesn't work, just start scanning github repos for entropy. That's where the credentials that were accidentally published live.
Also... Money is Theft and The Economy is a Lie. Education inoculates you against new facts. Our meritocratic democracy ensures government by the mediocre.
As Paul Virillo once quipped, "the invention of the ship was also the invention of the shipwreck." And we appear to have shot the ensign who was looking out for icebergs.
"They Live" was a documentary. "Idiocracy" is far too optimistic to be accurate. Reflexive modernity has made Ballard's "High Rise" into a love story.
All revolutionary fervour aside, I'm a fan of Kurz. My bread is buttered more on the David Harvey side, but Kurz is no fool. I'm not sure the headline "Capitalism has to become more humane" is the best distillation of his message.
Every billionaire is a policy failure.
I'm going to start singing the Internationale here in a second.
(not snarky. I'm feeling pretty revolutionary after that last comment.)
Oh man. Don't google "sackler family" or "purdue pharma".
[EDIT: Added after that one person upvoted this comment.]
Slavery was big in the south because there wasn't enough low-skill labor to feel threatened. The north didn't care for it as much because a higher percentage of labor was what we would call semi-skilled or skilled today. That labor was FREAKED OUT about the idea of slaves taking over their jobs and they were able to organize before being eaten by the capitalist leviathan.
I'm pretty sure there were more abolitionists in the north than the south, I don't think your average northerner cared about the plight of southern slaves other than the institution being a threat to their livelihood if it moved north.
If you were making the assertion moral concerns or ethical behaviour eventually influenced american capitalism, I disagree. The capitalist monster acts "moral" or "ethical" because at the current time, to do otherwise is invite political dissolution. I fear the shadowy cabal of capitalist masters will move to reinstate chattel slavery. We did not respond with outrage when red-lining disenfranchised large portions of the populous or when usury was slipped back in with high credit card APRs and payday lending. We are asleep.
Isn't the point of modern capitalism that you don't have to be humane. Or that the best way to be humane is to do what's best for company management?
I miss Apple during it's hey-day. There was a time when Apple was the sine qua non for #a11y and #hci. Then Steve came back.
Am I really so old that when someone says "Flash" my immediate response is... "consider HTML5 instead" ??
For people coming to this later. A day later, I bounced my router and got a new public facing IP. All my problems went away. Willing to bet GH thought I was a horrible H4XX0R based on my previous IP.
Yup. There's a reason that all the AppKit classes start with 'NS'.
I have issues with the Librem community. But... if you like them, I certainly won't dis you (or them.) I don't think they're bad people or bad developers, they just have a style that sets my teeth grinding. That's a me problem and not a them problem. There's only so many times I can be insulted for liking BSD licenses instead of GPL.
What will cryptography buy you in this instance? Do digital signatures imply virtuous behaviour? Does the lack of a signature imply vice?
No. It is partially due to trivial dependencies. With so many dependencies it is very difficult to evaluate the security posture of all the teams that are inserting themselves into your code.
When I publish commercial software for Unices that use shared object libraries, one of the things we do before publishing is review known vulnerabilities of our 10 dependencies. That is a tractable number. I get a senior engineer to spend time with an intern and step them through the evaluation criteria.
If the team managing a particular library grows lax over time with respect to responding to vulnerabilities, we move away from using that library.
And we can do these things because there are a tractable number of dependencies.
But yes, also GitHub is not pure as the driven slush. I agree with you on that.
Sure, but the Python community isn't the paragon of software risk management excellence you may think it is.
Both Python and Node users (metaphorically) asked for a loaded revolver... They got a metaphorical high yield thermonuclear device with a large blast radius. (And then they skipped the safety tutorial for the B-83 they just bought.)
I initially read this to mean NPM has a pro-concealed-carry policy, which I don't think it does and I don't think is what you meant.
But... Node's culture does not reward "rational" policies with respect to dependency management in the same way that the US does not reward "rational" policies with respect to gun control *. But US gun control policy is a reflection of the "will of the electorate" -- i.e. there are a lot of Americans who want (or need) to own firearms. In the same way, NPM reflects the culture of high-speed, sili-valley web-devs.
I mention both not to criticize, but to comment it's not the tool that's at fault here, but the users who demanded it evolve the way it did. We moved fast. We broke things. And some of the things that remained broken were sociological: It's easy enough to add PGP/GPG signatures on packages, but whom do you trust? What is the meaning of a signature? Does it mean the signer warrants the package/version is free from defects?
NPM is working as designed. Users wanted the software construction equivalent of a loaded revolver. But we got something that was a bit more like a nuclear weapon with a large blast radius. At least the revolver user would more-likely only shoot their own feet six times (or twelve if they reload.)
[*] I'm trying very hard not to start a flame-war about gun control, I only mean to point out dependency management in node can be as contentious in it's domain as gun control policy is in the domain of US politics. Note that I am not making a pro or con argument about gun control, but only pointing out the issue exists. The word "rational" is intentionally chosen to reflect the fact that people's opinions on gun control and package management are often based on personal, often emotional beliefs (which should not be dismissed.)*
Well, hell. I only new Peter peripherally, but every time I met him he was a wonderful human. I built cryptography libraries in the 90s and Peter was responsible for expanding my thinking about the systems surrounding security controls and (not surprisingly) their associated risks. And he did it with great patience, speaking to me (and everyone else) at a level we could understand, but never patronizing. I would bump into him at a conference one year and he would suggest a direction of study or experiment. At the next conference I saw him at I would report my findings (or send them to the RISKS list) and then there would be another, interesting direction suggested.
There's a Peter-shaped-hole in Sili Valley tech culture.
Performance, memory efficiency, some security nits (but compared to Leenucks, it's not that bad), bug fix cadence (there's a bug I filed against NeXTStep 2.2 in 1993 that was finally fixed in 2015), support (they keep changing their mind whether the command line tools are supported.)
Coming from Xfinity with a dynamic IP. Could be the person who had this IP before me was running a bot that hammered them.
Not sure. I thought the FuriPhone's advantage was that they were making it in conjunction with the ODM so you didn't have to use halium to call into Android. But a quick google search tells me I'm mistaken. Maybe I was thinking of the FairPhone?
I would consider the PinePhone, but my experience with it left me cold. And they EoL'd the Pro and the original PinePhone is fairly anemic by modern standards. I'm not sure it could run HaikuOS at acceptable speed. My memory was the PinePhone also had some land-mines with respect to drivers, but it's been several years since I touched mine, so I could be mistaken.
I'll probably have to spin my own hardware again. I really dislike writing drivers from scratch.