HN user

codemac

4,404 karma

http://codemac.net -- rarely updated

I am bad at collecting karma. I'm currently working on Human Data/Alignment Research @ OpenAI.

Previously Storage @ Facebook, Google, Pure Storage, Igneous Systems, IronPort, and NetApp.

What is the most important problem in your field, and why aren't you working on it?

email: j@codemac.net

[ my public key: https://keybase.io/codemac; my proof: https://keybase.io/codemac/sigs/4zxtt61QOyT7_BA8DDCHlGlNCkE2rw-VsKZclDl1U20 ]

Posts8
Comments1,124
View on HN

It adds npm as a dependency, to a go build?

It changes the contributor email?

to install random npm packages?!

in /tmp?! in post_install()??! With a new random contributor email????

Archlinux is focused on enabling a specific type of user, and certainly ones that can read bash scripts, and understand reasonable depedencies vs unreasonable ones. And even then - this is specifically in the AUR and not a package the distro directly offers.

Right, the PKGBUILD only helps you review if you're installing what you intend to - not verifying if what you're installing contains any hacks.

This hack in particular added random npm packages that would have been unneeded/unintentional, and was visible in the PKGBUILDs directly.

isn’t that also the case for every browser extension, VSCode extension, nuget package, Cargo crate, python package, npm package

Yes, and all of those have supply chain hacks in them, and have happened within the last year? In this specific case, it's a malicious npm package being installed with official npm tooling in the PKGBUILD.

The advantage to the AUR is just that you can reasonably review every PKGBUILD for what you're installing, they are very simple bash scripts. It'd be great if more people would donate resources to help verify and validate AUR scripts, but the AUR specifically exists for packages that the trusted users and devs of arch don't have time to personally maintain.

emacsclient + codex has been a game changer.

I probably add or change a feature in emacs once a day, or every other day. I've been using emacs for some insane amount of time, maybe 20 years? And still I had more customization to go.

Emacs and programs with it's level of programmatic user customization will survive the AI period in my opinion. Anything static will falter.

Nvidia CEO Jensen Huang said his company’s recent investments in OpenAI and Anthropic are likely to be its last in both, saying that once they go public as anticipated later this year, the opportunity to invest closes

ok, sounds obvious

Nvidia, for its part, isn’t offering much more on the matter

ok, so no more news from nvidia

Still, a few other dynamics might also explain the pullback..

Wait it's a pullback?

This is terrible reporting, right?

Please reread (or.. read) the paper. They do not make that mistake, specifically section 7.1.

A reward function (R) may be hackable by a model's response, but when asked to confess it is easier to get an honest confession reward function (Rc) because you have the response with all the hacking in front of you, and that gives the Rc more ability to verify honesty than R had to verify correctness.

There are human examples you could construct (say, granting immunity for better confessions), but they don't map well to this really fascinating insight with LLMs.

You are thinking in terms of utility, instead of organizational power. Which is fine - but misses why the meeting behavior continues imo.

While I have several disagreements with this deck, there are two large ones:

1. In my experience, a lot of teams don't have long enough meetings to avoid the litany of small meetings. For example, a lot of staff meetings could easily be 2 hours and then cancel many project specific meetings that have 50%+ of the same attendees later in the week. They also enforce a cadence of execution - everyone knows they need to prepare for the weekly staff meeting, rather than many small meetings every day. It also avoids the problem of people feeling not included - you're always invited to the one huge meeting every week, it's up to you to attend or skip.

2. The problem with meeting culture cannot be solved with education on how to say no, it's about admitting that attending meetings actually does convey a lot of things. Lots of information is not shared outside of meetings. Seniority of attendees actually does have a huge impact on visibility in folks' careers. A lot of the advice in this slide deck feels like it should work, but doesn't in practice because of self interest.

The education that needs to happen is quite different imo:

- leadership needs to be done through writing

- meetings should be recorded and minutes sent out broadly, along with allowing silent attendance.

- decisions need to give time for dissent outside of meeting attendees before committing.

attention required: 10 minute video > 10 second short

When the written word took over with the printing press, the same concern was levied. The amount of attention required to listen and memorize a story/poem is a lot more than just reading it.

The change with smart phones is just one of access/time spent on these things. There are people who are spending ~5 hours/day watching this content. There is a big difference between someone listening to 5 hours of a single poem, to reading 5 hours of a single book, to reading 5 hours of blog posts, to watching 5 hours of a youtube video, to watching 5 hours of random videos, to 5 hours of <10s videos.

... a lot isn't even close though.

The US is at 120.5 guns per 100 civilians, and Canada is at 34.5

I think being ~4x the ratio of guns per capita, (and 30x the total!) has to do something, right?

Git-Annex 11 months ago

While Yann has built many things with git-annex, we should be clear that the creator of git-annex is relatively singular, Joey Hess.

Everyone has similar agreements with local power grids, and pretty much all DC operators respond to demand reduction calls from the grid.

It's extremely rare for a DC to put an entire community's grid at risk, and they are usually working closely with the upstream power providers during any storm, increased demand, etc.

I think there is a lot of hand wringing from folks who have never worked in DC operations.

I should write a lot more, but the two paths I see are: B.O.O. and Good Strategy/Bad Strategy.

B.O.O.: Background, Objective, Overview. Basically, a history lesson for how you got here, an objective for what you want to fix/change, and an overview of how you'll implement that change.

Good Strategy/Bad Strategy: An amazing book, but the organization is similar to boo. Problem Diagnosis, Guidelines/Assumptions/Requirements, and Actions.

I find BOO is better for targeted design documents in a google-like culture where you should write up a design document for almost any architecture change. The Good Strategy/Bad Strategy method scales pretty amazingly up to almost anything, but you need to be a much more experienced author to get things to fit it.

Nowadays a problem is the subscriptions are all multiplexed through apple, google, and amazon.

I used to religiously use things like ynab, but now I need to find ways to export my amazon transactions, google play, etc. It's nearly impossible, and it makes me feel completely out of control.

watch the live stream, it shows you the diff as the completed task, you decide whether or not to generate a github pr when you see the diff.

It's not about forcing your kids to "do math", but to excel at important skills far before the benefits of being good at that skill matter.

The amount of homework/study per day that maximizes math scores on tests is significant, 1+ hours/school day by the time they're in middle school, with it helping even more for those who are starting out poor at math[0]. You'll note the referenced study doesn't even max out progress for any group - meaning most could have studied more and improved more.

I don't know any kids that voluntarily did an hour or more of solely math study per day. I know plenty that were forced, and ended up loving math or other technical fields as adults.

As a parent of young kids, obviously I haven't gone through high school yet - but I don't think many children who reach their potential in math, english, music etc will have no pressure from their parents.

[0] https://pmc.ncbi.nlm.nih.gov/articles/PMC8025066/

A great book is "Strategy and the Fat Smoker". It's written by a consultant but points out an obvious point: the quality of the strategy itself is not nearly as impactful as the ability to execute. The author compares this to being a fat smoker who won't change their habits - knowing the right strategy is insufficient.

Archival Storage 1 year ago

Good thinking - there are many projects around this. Ceramic, DNA, 3d glass, etc. They all run into the same IO problems tape has though.