Even after the owner has realized the attack and revoked the token, there’s next steps (alerting the community, pulling from NPM) that causing havoc delays even by just a bit.
HN user
dominicm
dominicm.dev
While not directly mentioned in this article, guix pack[1] allows you to distribute your software in multiple formats, including Docker images.
The general philosophy of Guix is to have a single definition for how to build your software and use it for the entire dev to production pipeline.
[1] https://guix.gnu.org/manual/1.5.0/en/html_node/Invoking-guix...
I mean, it's certainly not as seamless as an open x86 machine, but if you have an Air already you can always try Linux on it? The Fedora Asahi spin [1] supports pretty much everything on M1/M2 devices.
I'm...rather confused why the results here are surprising. The title and first paragraph are suggestive of unusual data like analytics or sending all your codebase, but it's just sending the prompt + context.
This is how every LLM API has worked for years; the API is a stateless token machine, and the prompts + turns are managed by the client application. If anything it's interesting how standard it is; no inside baseball, they just use the normal public API.
Youch. I knew the rates of people criticizing-by-headline could be bad, but this one is rough.
Y'all, please actually read the homepage before dunking on someone's project...
Dang, everything about this feels really well considered. Semi-throwaway, nearly bare-metal machines that I can put on the internet with basically 0 config? I'll take
Silverbullet is a PWA that downloads all your notes and then operates on them locally, so that slow initial load happens fairly infrequently.
Wow, this is embarrassing. Hard to read.
But since it is a electron app, it will always contact Google everytime you open the app
Do you have a source for this? I couldn't find anything about this, and I find it strange that Electron (which uses the open-source chromium engine but not Chrome) would automatically send tracking information to Google.
Huh, TIL. Thanks.
I think that shows what the target audience is. I think most people wouldn’t know what to do with that prompt, other than immediately discard it.
That's a fair complaint, and I'm definitely biased since I'm technically oriented. That said, discarding it is totally fine as long as people who want it at least get the option; and if even showing it is too confusing to users, it's a lot better to have a "developer" toggle in settings that enables all this stuff, rather than not having it at all.
Haiku's certainly not crazy accessible right now, but it has some ideas that I think other OSs should take note of.
I think after Windows 7 the processes are grouped per application in Task Manager. We’re all grumpy about the redesigns of things we are familiar with, but little UX improvements happen all the time.
You're right; I was mostly thinking about problems with Linux since thats my daily driver. It would have been better to say that Haiku gives developers the same UX affordances for interacting with their system as non-technical users.
When using Linux I'm frustrated by an overall lack of UX, but when using Windows/Mac it's developer specific UX that's ignored.
I worked on Haiku this summer as part of Google summer of code, and it just made me wish their attitude towards user experience was more prevalent in mainstream OSs.
It's little things like errors automatically prompting you to open a graphical debugger or processes being grouped by application. There's sensible UX that doesn't expect me to be a wizard to understand what's going on or how to dig deeper.
Obviously it has rough edges (as, well, honestly all operating systems do), but the things that do work work really well.