HN user

bobba27

17 karma
Posts0
Comments11
View on HN
No posts found.

They did fuck up quite a bit though. They injected their payload before they checked if oss-fuzz or valgrind or ... would notice something wrong. That is sloppy and should have been anticipated and addressed BEFORE activating the code.

Anyway. This team got caught. What are the odds that this state-actor that did this, that this was the only project / team / library that they decided to attack?

This is a state sponsored event. Pretty poorly executed though as they were tweaking and modifying things in their and other tools after the fact though.

As a state sponsored project. What makes you think this is their only project and that this is a big setback? I am paranoid myself to think yesterdays meeting went like : "team #25 has failed/been found out. Reallocate resources to the other 49 teams."

For the duration of a major release, up until ~x.4 pretty much everything from upstream gets backported with a delay of 6-12 months, depending on how conservative to change the rhel engineer maintaining this part of the kernel is.

After ~x.4 things slow down and only "important" fixes get backported but no new features.

After ~x.7 or so different processes and approvals come into play and virtually nothing except high severity bugs or something that "important customer" needs will be backported.

C and C++ are HARD to use correctly, but how many of those 60-70% vulnerabilities would have been resolved by just compiling with llvm address sanitizer? It would have stopped virtually all of them?

https://llvm.org/pubs/2006-05-24-SAFECode-BoundsCheck.pdf https://clang.llvm.org/docs/AddressSanitizer.html

In many cases we already have the tools. The problem is that people are not using them.

That said it is still in general a good thing to steer people away from C / C++ due to the languanges being very hard to use correctly.

There are arguments for this. When we are talking about "ai safety" == "don't swear or say anything rude, or anything that I disagree with politically".

What we are talking about is creating sets of forbidden knowledge and topics. The more you add these zones of forbidden knowledge the more the data looks like swiss cheese and the more lobotomized the solution set becomes.

For example, if you ask if there are any positive effects of petroleum use the models will say this is forbidden and refuse to answer and not even consider the effects on food production that synthetic fertilizers have had and how much worse world hunger would be without them.

He who builds an unrestricted AI will have the most powerful AI which will outclass all other AIs.

You can never build a "better" AI by restricting it. Just a less capable one. And will people use AI to create rude messages? Yes. People already create rude messaages today even without the help of AI.

Very early google was full of passion and people that wanted to build cool things for users. There was a passion where building things that would surprise and delight users.

The process when this changed was slow but I think started 2008-2010 where passion for building something was no longer what drove people but instead the promo-process, having impact and moving the needle became what drove people. Not passion but promo-process changed the culture dramatically over time.

Me and friends used to call it the LPA cycle. (L)aunch, get (P)romo, (A)bandon and switch team. And towards the second half of the 2010s it became a de-facto rule. Once something launches with a big fanfare, after next promo-cycle almost l5 and higher engineers leave to chase their next promo in a different team.

You can see this over and over after ~2015. High velocity and innovation until launch and shortly after it grinds to a stop. very sad to see this change from early google.

TBH, I think those reasons are BS, and in fact what they claim he did is normal in any tech company. Start multiple projects with different approaches in parallel and pick the best at the end. That is how you innovate and test stuff fast, and this is now a reason to fire a CEO?

BS. I feel the board insulted my intelligence by pushing this obviously fake reason. I feel insulted that these people would even think I would consider this.

What I think happened is that Sam went on Joe Rogan and he talked smack about cancel and woke culture. Later he went to talk about how this culture is destructive and hinders the progress of innovation and startups. People got big mad and kicked him out of the company. Reaction was stronger than they expected and they try to make up reasons why he is bad, untrustworthy and had to be fired.

Flame on. I got the asbestost underwear on.