Naturally, the next move was pivoting from defense to offense. I wanted to see if the attackers left any vulnerable services exposed on their IP.
Why not attack them through the C2 interface? That's where I'd expect them to slip up.
HN user
I blog about software and entrepreneurship at https://mtlynch.io
I'm writing a book to help developers improve their writing at https://refactoringenglish.com
Naturally, the next move was pivoting from defense to offense. I wanted to see if the attackers left any vulnerable services exposed on their IP.
Why not attack them through the C2 interface? That's where I'd expect them to slip up.
I think we disagree on the connotation of the word "lead."
To me, if someone describes me as a "lead," it implies that they are focused on making the sale rather than on anything else about the business relationship. I would also find it unsettling if a doctor told me that I was a "good lead" because I had a disease they treat.
OP here. I wrote the post myself with no AI (modulo grammar checks).
What makes you think it's AI-generated?
OP here. Thanks for reading!
I'm having trouble understanding where we disagree. It seems like you're arguing that she's correct because it was helpful for the mutual acquaintance to refer me to this vendor, which I agree it is.
My point is that the term "lead" implies that she's thinking about making the sale rather than serving me as her client. Do we disagree about the connotation of the word "lead?"
As a more extreme example, if you went to a doctor for an illness and they said, "Wow, I'm going to make so much money treating you," I imagine you'd find it off-putting even if the doctor would only earn the money because they're doing a useful thing by treating your illness.
I appreciate the critique!
Sometimes when I'm thinking about a blog post, I fall in love with a joke I want to use, but then it constrains how I think about the topic. I still like the David example, but I'm too close to the post to have a balanced perspective, just having finished it today.
OP here. Thanks for reading!
I'm not trying to argue that art is sacred and we have to hold it up over everything else, but I am joking that there is still an implicit boundary where we don't use "content" to refer to things that we respect highly.
I think a lot of people that talk about "art" vs. "content" are talking about art vs. business, but I'm more arguing about big vs. small and aggregation vs. individuality.
It makes sense for YouTube and Twitter and Facebook to refer to everything on the Internet as "content" because there's so much variety and those platforms are trying to capture all of it. But I just realized it's silly for me, an individual author to refer to my work as "content" when I could just as easily say "book" or "blog posts."
OP here. Thanks for reading!
I feel that all the terms mentioned are useful in specific contexts. Web traffic brings visitors to your resource. If they read your blog, they become readers. If they use your products, they become users. When someone buys something from you, they become a customer.
I'll respectfully disagree. I think those terms make sense if you're talking in general terms, but if you're an individual person talking about your work, they're generic catchall terms with better alternatives.
Like, in concrete terms, let's say I publish funny cartoons on my website and sell prints of those cartoons. It doesn't make sense for me to say "web traffic brings visitors to my resource." What traffic? What resource? It would be more meaningful to say, "Visitors find my website through Google search."
OP here. Thanks for reading!
I don't really have anything against the existence of the catchall term "content." Like, I don't expect the CEO of YouTube to say, "music, short film, art, comedy, journalism, ..., creators" every time he talks about YouTube users. It makes sense from their perspective to bucket everything into "content."
The thing I found interesting was just that the language had crossed over to people where it doesn't make sense to bucket everything. If I'm a blogger, I can just say "blogger" and it's more meaningful than "content creator" but I think the people running small businesses or doing creative work have needlessly adopted the big bucket terminology of "content."
Are you talking about this line?
What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.
I think it's clear that I presented it as a hypothetical dialog, not something you literally said. But I agree that the fairer way to present it would be to say, "Kelley can't say 'It appears to be an outright fabrication'," to match the original language in your blog post.
I think you are earnestly trying to untangle the facts from two parties for whom you have no bias one way or the other, which is commendable.
Honestly, my bias is to support Zig. I personally like the Zig project and you as a person (this blog post notwithstanding) enough that I've contributed a small monthly financial amount for the last 2.5 years. You've never sucked up all my code and then tried to sell it back to me.
So, despite the fact that I have many reasons to favor you and Zig over Sumner and Anthropic, when I read both blog posts, the impression I walk away with is that your blog post is needlessly critical of Sumner as a person and that you made unsubstantiated accusations against him.
To do this, they need to make this rewrite appear successful, so they need to retcon this idea that they were doing good engineering practices in their zig codebase the whole time, including fuzzing, even though that is not the case.
I don't get that from their blog post.
Both you and Loris seem to be saying that Sumner's "We've been fuzzing Bun" claim implies to everyone that they've been fuzzing it for a long time as much as they possibly can, but I think it just means what it says. They've been fuzzing it some, and some bugs fell out of it, not that they fuzzed it perfectly or followed every software engineering practice perfectly.
Right, that part is not in dispute.
If Sumner says today, "We do X," then Kelley can say, "Nine months ago, Sumner did not do X," and both can be correct. What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.
One of the things I find so disappointing about Kelley's behavior here is that he falsely accused Jarred Sumner of lying about fuzzing Bun, and then when Sumner showed evidence[0] that they've been fuzzing Bun for months, Kelley just silently edited his post[1] to walk back the accusation and never apologized or admitted he was wrong.
I commented on Mastodon[2] to point out to Kelley that it's dishonest to silently remove the accusation, as so many people were already talking about it, and it confuses the conversation if Kelley retroactively edits it, and he replied[3]:
the false claim is in the bun blog post not mine. I only changed the text because it's easy to lazily argue against it. Please read more carefully. They are the ones being deceitful not me.
Loris Cro, Zig's VP of Community, gave a slightly clearer response[4]:
Jarred's post has a section about what they "were already doing" to maintain their Zig codebase, which includes "24/7 fuzzing", which will make the average reader assume that the codebase has been fuzzed thoroughly, while in reality it has been for, what, 2 months before the rewrite?
Even then, I find it so bizarre that Loris thinks that if someone says, "We've been fuzzing Bun," and shows evidence of months of fuzzing, then that person is lying because "We've been fuzzing Bun" somehow implies something longer than two months.
The duration is irrelevant. If you say you've been fuzzing it and you've fixed bugs that your fuzzer found, then clearly you're fuzzing. The Zig team doesn't get to arbitrarily move the goalposts of what "fuzzing" means.
[0] https://news.ycombinator.com/item?id=48845652
[1] https://news.ycombinator.com/item?id=48854921
[2] https://m.mtlynch.io/@michael/116896188093796421
I'm having trouble understanding what you mean.
If I say, "I run 5 miles every day" and my old neighbor says, "I lived next door to him until 9 months ago, and he definitely doesn't run 5 miles a day," and then I show my GPS logs proving I've been running 5 miles a day for the last 9 months, I am correct and my ex-neighbor is incorrect.
If Sumner had said, "We've been fuzzing our code for years," then Kelley could justifiably say that's incorrect. But Sumner is saying that currently Bun fuzzes their code, which is true, so Kelley appears to be incorrect to claim it is a "fabrication."
Andrew was wrong. He stealth edited his post to hide it. https://news.ycombinator.com/item?id=48854921
For me, using Fuzzilli for testing a Zig code is not fuzzing, it's integration testing. If you're running code externally (e.g. wrapping binary) you cannot guarantee that side effect isn't caused by IO. I consider fuzzing a low level activity with many external variables removed.
I've never heard anyone restrict the definition of "fuzzing" in this way. If I repeatedly generate inputs to a program and then run the program with those inputs, that's fuzzing. It doesn't matter if there's IO or not.
Depending on where you are and how you communicate semantics matter more or less. It's very similar to compiler/transpiler. E.g. TypeScript "Compiler" is called compiler but in fact it's transpiler (it emits other high-level language as a result).
It's still a compiler. It translates code from one language to another. You can argue whether we need the term "transpiler," but a source-to-source compiler is a compiler.
Yes, "their" refers to Bun's code, not the Zig compiler's code. Fuzzili is a fuzzing engine for JavaScript, so integrating it into Bun means that Fuzzili is fuzzing Bun.[0]
From the Bun post[1]
We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore
From Andrew Kelley's post today[2]:
The post claims they were fuzzing their Zig code, while during our calls the whole Bun team told us that they were not fuzzing anything. This appears to be an outright fabrication.
Sumner says that the Bun team has been fuzzing Bun's Zig code. Kelley says that this is a fabrication. Sumner showed proof that the Bun team has been fuzzing Bun's Zig code.
It looks like Kelley is incorrect and made an unfounded claim. The generous interpretation is that at the time Kelley and Sumner had a more collaborative relationship, Sumner was not fuzzing Bun's Zig code, but I'd expect Kelley to check if anything had changed since then before publicly accusing Sumner of lying in this week's Bun blog post.
[0] https://github.com/googleprojectzero/fuzzilli
[1] https://bun.com/blog/bun-in-rust
[2] https://andrewkelley.me/post/my-thoughts-bun-rust-rewrite.ht...
This is what Jason Cohen did when he was getting WPEngine off the ground. He messaged 40 WordPress consultants on LinkedIn and offered to pay them higher than their hourly rate since it was a one-off task.[0]
Out of 40 messages, 38 replied and agreed to a phone call, and none of them actually asked for the money.
[0] https://mtlynch.io/notes/designing-the-ideal-bootstrapped-bu...
OP here. Happy to take any feedback or questions about this post.
Author here.
Happy to answer any questions or take feedback about this post.
The problems for services such as GitHub with scaling are reducing cost per customer. That's even more pertinent when discussing inference at scale.
I don't think that's true. When I look at GitHub's incident history,[0] it doesn't read to me like a company that's struggling to cut costs. It looks like a company that's trying to do a million things to serve a million use cases, and the growing interconnections between all those distinct services and workflows cause unexpected failures.
Not GP, but just being smaller makes it easier to achieve reliability. Like if you're a git forge with 100 similar customers, you can likely achieve an order of magnitude better reliability than GitHub, who is trying to serve millions of customers with wildly different needs.
The target audience of the app is me and my wife. This is a "home-cooked meal" app.[0] If it's useful to other people, I'm glad, but I'm primarily building it for myself for the pleasure of building and the satisfaction of a tool that works exactly how I want it to work.
You could approximate it with email, but I want things that you can't do with email like letting recipients control the frequency of emails, making high-res images available without bloating everyone's inboxes.
Thanks for reading!
But I spent five years on a solo app and never wrote anything close to this. Not on principle event, just the design just kept moving.
Yeah, I agree that for solo projects, it makes sense to greatly scale down the design phase. In a lot of cases, you'd scale design down to zero if you need user feedback to figure out what to build.
But even for solo projects, if I keep at it for months or years, I eventually get to the point where some problem is hard enough that I need to do some upfront design, even if it's not as formal as a whole design doc.
It's for private photo sharing with family or close friends. It's more like an open-source, self-hostable TinyBeans or PhotoCircle. I explain the motivation more in the design doc:
https://refactoringenglish.com/excerpts/write-an-effective-d...
Was it this it this one by Eaton Works?
The gokrazy team being Michael Stapelberg : )
These are all different submitters. HN is supposed to detect duplicate links.
Most are not serious, and we’ve quietly fixed them, thanked the researcher, and went our merry way... These come from a wide variety of locations and people, and sometimes, but not always, are looking for bug bounties.
I take it that Metabase is both not paying bug bounties and not using these tools internally?
If that's the case, Metabase is not going to get meaningful investment from researchers who want to fix issues, but they'll get increased attention from malicious attackers who have no qualms exploiting the vulnerabilities for profit.
LLMs have made it a lot easier for people to find vulnerabilities in software. Open-source makes it easier, but we already have non-AI tooling (IDA Pro, Ghidra) that's good at binary reverse engineering, and LLMs can use that output to find vulnerabilities as well.
This year, as I select products to use for sensitive data, I've been paying a lot more attention to whether they offer bug bounties and for how much. For example, I like Kagi for search and thought about trying Orion, their web browser. Then, I saw that Kagi's been paying $100 for UXSS vulnerabilities.[0] For comparison, Firefox pays $8-10k,[1] and Chrome pays up to $10k for the same class of bug.[2]
[0] https://help.kagi.com/kagi/privacy/bug-bounty-program.html
[1] https://www.mozilla.org/en-US/security/client-bug-bounty/
[2] https://bughunters.google.com/about/rules/chrome-friends/chr...
Parent wrote a great blog post about this for anyone interested in the details:
https://blog.noforeignland.com/off-grid-boat-communications-...
That would be even worse than our already bad system.
The system is already pretty bad because vendors underinvest in security, and then to fix it, researchers have to volunteer their time to investigate with no guarantee of payment. If the vendor could force researchers to hand over findings for free, nobody would want to do security research except hobbyists having fun. They're basically signing up for hours of tedious forced labor to explain vulnerabilities to the vendor.
I wish there was legislation that allowed the government to fine vendors for security vulnerabilities like this where the amount scales based on how much user data they leaked. And it could function like other whistleblower systems where a researcher who spots a leak can report it to the government and collect 50%. That way, if the vendor says, "We're not paying you," the researcher can turn around and collect the money from fines.
Oh, I'm glad!
Yeah, I don't think you'll find it a red-pill kind of book at all. I know what you mean about books like The 48 Laws of Power feeling like the world is 100% zero sum, so everything is about dominating or outplaying people.
How to Win Friends and Influence People is very much focused on win-win. There is an agenda to make friends and influence people, as you'd guess from the title, but the strategies are about taking a genuine interest in people and making them feel good.
It's almost 100 years old, so the style is kind of hokey, and only about half the advice resonated with me, but there are 3-4 lessons that had a major impact on me.