The JSpace research probably had a lot to do here:
HN user
pkoiralap
Huge kudos to the security researchers for 1, finding an exploit, and 2, unlike copyfail, excluding a zero-day ready-to-use LPE script that anyone could have used.
I tried using this for LPE on a Rocky9 for a couple of hours and thankfully couldn't get it to work. So that means unless you have quite some free time on your hand, or are extremely good at doing what you do, you can't actually use this to get LPE on enterprise distros.
This is fascinating research. I feel this is a significant leap in interpretability research. Since we know J-Space exists and is bi-directional, we can train models on the same and come up with meta cognition abilities.
I also fear that the big corporations might use the same to run targeted ads, capitalistic shenanigans. Which they might already be doing through system prompts.
Justice to Karen
We would like to thank:
Karen Oyelaran, who found the issue on Day 1 and is currently appealing her GitHub rate limit via a web form that is also AI-triaged
It's one thing to report a vulnerability, another entirely to make a crazy exploit available for any tom, dick, and harry to take and use. It was irresponsible of whoever came up with it to release it in the world without first giving major distros a head's up.
I was coming up with the same intuition. However, it's like a whack-a-mole. What about cronjobs and slurmjobs and other services? Is there a way to do this directly on systemd so that all other processes inherit it rather than doing it on each one?
Does anyone have a workaround for it? Edit: I don't understand why the comment would be downvoted.
This was bound to happen either organically or inorganically. Make sure it performs well on the benchmarks. And it doesn't really matter if it doesn't generalize outside of it right? :D
Also similar: Graduate student descent. https://sciencedryad.wordpress.com/2014/01/25/grad-student-d...
While it is true that guides and business owners are always looking for opportunities to earn extra cash, the reporting is a tiny bit off here.
Start of AMS like symptoms can easily be mistaken for walking fatigue and dehydration. It is easier to identify if you are at rest, but during the trek that is seldom the case. So when you actually start realizing something is wrong, you already are at an elevated risk. The only thing that works in these cases is to descend and as fast as possible at that.
Considering the fact that AMS will absolutely and a 100% kill you if you play around with it, guides presenting trekkers with an option of helicopter rescue is not that bad, at least if you look at the worst that can happen.
That would indeed be the case if one has never learned the stuff. And I am all in for not using AI/LLM for homework/assignments. I don't know about others, but when I was in school, they didn't let us use calculators in exams.
Today, I know very well how to multiply 98123948 and 109823593 by hand. That doesn't mean I will do it by hand if I have a calculator handy.
Also, ancient scholars, most notably Socrates via Plato, opposed writing because they believed it would weaken human memory, create false wisdom, and stifle interactive dialogue. But hey, turns out you learn better if you write and practice.
I think the 'better than googling' part is less about the final code and more about the friction.
For example, consider this game: The game creates a target that's randomly generated on the screen and have a player at the middle of the screen that needs to hit the target. When a key is pressed, the player swings a rope attached to a metal ball in circles above it's head, at a certain rotational velocity. Upon key release, the player has to let go of the rope and the ball travels tangentially from the point of release. Each time you hit the target you score.
Now, I’m trying to calculate the tangential velocity of a projectile from a circular path, I could find the trig formulas on Stack Overflow. But with an LLM, I can describe the 'vibe' of the game mechanic and get the math scaffolded in seconds.
It's that shift from searching for syntax to architecting the logic that feels like the real win.
In the 1930s, when electronic calculators were first introduced, there was a widespread belief that accounting as a career was finished. Instead, the opposite became true. Accounting as a profession grew, becoming far more analytical/strategic than it had been previously.
You are correct that these models primarily address problems that have already been solved. However, that has always been the case for the majority of technical challenges. Before LLMs, we would often spend days searching Stack Overflow to find and adapt the right solution.
Another way to look at this is through the lens of problem decomposition as well. If a complex problem is a collection of sub-problems, receiving immediate solutions for those components accelerates the path to the final result.
For example, I was recently struggling with a UI feature where I wanted cards to follow a fan-like arc. I couldn't quite get the implementation right until I gave it to Gemini. It didn't solve the entire problem for me, but it suggested an approach involving polar coordinates and sine/cosine values. I was able to take that foundational logic turn it into a feature I wanted.
Was it a 100x productivity gain? No. But it was easily a 2x gain, because it replaced hours of searching and waiting for a mental breakthrough with immediate direction.
There was also a relevant thread on Hacker News recently regarding "vibe coding":
https://news.ycombinator.com/item?id=45205232
The developer created a unique game using scroll behavior as the primary input. While the technical aspects of scroll events are certainly "solved" problems, the creative application was novel.
So if we can somehow preserve the signal and make it go round and round, can we get long term storage out of nothing?
Versity is really promising. I got a chance to meet with Ben recently at the Super Computing conference in St. Louis and he was super chill about stuff. Big shout out to him.
He also mentioned that the minio-to-versity migration is a straight forward process. Apparently, you just read the data from mino's shadow filesystem and set it as an extended attribute in your file.
sketch.metademolab provides something similar https://sketch.metademolab.com/
You make a good point and I agree mostly to the point being made i.e. it is more fluid than categorical. However, I think it is not being made in good faith. I found the article highly insightful because it provides a solid starting point to those that have not started or don't know much about negotiations and how they happen. It should be safe to assume that there are plenty that have not started yet. It is also true that the more frameworks one reads and learns about, the more they realize that there are gaps in each one of them, and it is indeed fluid, not categorical, and hence reaching the same conclusion.
I think two reasons. If reactors can't function above 20%, a country having access to >20% enriched payload is a certain violation. Vs "60% enrichment is still for clean energy, my reactor works with it". 2. If you are only buying the payload and not enriching it yourself, you can't do anything with >20% . More like mixing methyl alcohol in lab available ethyl alcohol, to deter lab techs from mixing water and having a rager.
This is scary. so the extra effort to move from, say, 20% to 85% is relatively small compared with the effort to get up to 20% in the first place. Might as well build a feature into the reactor so that it only works with <=20%
Asking because I don't know. How is enrichment governed? Say for instance if a country is only using it for energy vs defense/offense. And are there elements that can be specifically used for energy vs otherwise? Last I remember, having access to enriched uranium was grounds for a country to bomb another one.
I was thinking about what all is new in this version, or in fact in any other versions after iPhone 10/X (I don't know)? They all look same to me.
I personally think that Apple and other smartphone companies need to do a minor and major version release like you do with software. Every 3-5 year, do a major release. This way you create significant hardware/software features every major version, a hype that is well backed up, and at the same time keeps you working and improving and still making money out of it through minor versions. Plus, you also don't have to rely on planned obsolescence as people are gravitated towards the major version release naturally.
My take on fed's unaccountable power is you can't and shouldn't do anything about it and keep it that way. Because if the fed does do a good job, the economy keeps floating just fine. On the contrary, if it doesn't, its just chaos and catastrophe, that benefits no one, including the fed. So in essence, the job is to prevent disaster. Personally, I think it is a super shitty job.
Normal (voting) person is oblivious to both what the fed does and what will happen if the fed doesn't do it. All that a normal (voting) people care about, are numbers on price tags, and the fact that those numbers aren't as low as they used to be.
I have been using python http server to get this working. Go to a place where you have your index.html, start a python server, python3 -m http.server, and voila, everything is now importable and locally accessible.
Not true, if XSS is used to compromise an admin user, the damage can be far more than what a seemingly harmless SQL injection that just reads extra columns from a table does.
This particular comment feels more like an over-concentration on trivialities rather than refutation or critique of opinion.
I reached the same conclusion but in a roundabout way. I think the ultimate goal is to know about one's own self at the most deepest of levels. One way obviously is engaging with the self at a deeper level which is not always possible. Unfortunately, it is extremely hard to master.
However watching others and just collecting more datapoints help in the process of learning. You are learning to read and be more observant regardless of judgements.
I found the article really good.
Okay! first thing first, this is super cool. Kudos to the whole team. I did some fiddling around and found it usable and I think I can get used to it. However, there are a couple of things that it can improve on. And I have listed a few here.
1. Allow zoom ins and zoom outs in the canvas. It is super hard to navigate through the files otherwise. One way I can see this working is I would make a file graph view which can be obtained by zooming out of it enough, or just a toggle somewhere. That way I can easily navigate through the files.
2. I was not able to create edges or connection between the panes. I had opened a python/django project. So if there is a feature for manually creating edges between the panes, that would be awesome.
3. There are sometimes files that are more important than others. For such cases if I could visually mark those, say perhaps by color or labels, the panes would make more sense. An example for this scenario in django would be, different colored panes for views, forms, urls, models and setting files.
Apart from the features mentioned above, I did not miss anything at all. Once again great work.
DAG does seem natural here. Having a LLM add metadata to the nodes can make this even cooler. For instance, person A presents statement Sa. Person B comments on person A's statement, Sba and person C comments on person A's statement, Sca. The viewers now, especially new parties that are joining the conversation, would be able to see that Sba agrees to most of Sa said, but refutes a fact said by Sa. Sca doesn't agree with anything Sa is saying. Another example would be, nodes getting more weight as more people agree with it and smaller as more people disagree. Obviously, the implementation and implications are boundless.
They have started putting some models in huggingface: https://huggingface.co/collections/microsoft/phi-3-6626e15e9...
I was trying to explain my point through a more personal and practical point of view. It got to you so I think it did a good job.
Let's look at a really dumb comparison.
You are the owner of a house and you have a tenant person X, that's living in that house. You let person X to live in your house. They in turn, paid you the rent regularly, took care of your house, and never gave you any reason to complain. Personally, person X built a garden in the backyard, got a dog, got married while living in that house and now live with their partner and 3 other kids that go to school, have friends and consider your house to be their house.
You were fair though. You were very clear to person X at the very beginning that at the end of every year, you will put them in a lottery system where the winning odds are 1 in six, and the other 5 people you are pitting them against can potentially replace them from your house. And if they don't win for three consecutive years, you will throw them out and get a new person, person Y that won the lottery to live in your house for 6 years. But you don't know anything about person Y, i.e. if they will pay you the rent, if they will take care of your house. But you are completely fine with it.
You were clear to them so it's not your fault. They should have been more careful about getting that dog or getting married because they knew there is a rather high chance that they would be kicked out. But they are dumb and they did it either ways. So its them not you.
However, if you put yourself in person X's perspective, you were doing everything right. You were a great tenant, you were paying rent, taking care of the house, and even got attached to the house, knowing fully that there was a high chance of you being kicked out.
I guess people are just dumb that way.
Something that I personally feel unfair about the H1B lottery is that it doesn't consider where you live and what you are currently doing. Students that graduate through a STEM degree get to work for 3 years in their OPT (Optional Practical Training). This extends then to them having 3 chances (one per year) at getting the H1B. Now what's unfair is that an employer in the US can apply H1B for employees living oversees. That application then goes to the same pool where H1B application of the employees that are already living in the US go. The very same people that already hold a college or graduate degree, are already living in the US, and are contributing to the US economy. Unfortunately, the lottery is fair. So those that don't get picked up even after their third attempt are kicked out. They leave their life that they were trying to build in the US, potentially their girlfriends and partners, their friends, and their possessions. While that happens, someone who has never stepped foot in the US soil gets to go to the US. So in a sense it's fair for them. And while there is no real metric to measure this, when compared, between the fairness people oversees get and the unfairness people already living in the US experience, I personally think that the later tips the scale by a huge margin.