That was a nice diversion. I got 76,750.
HN user
popey
Developer Relations at Tessl.io
It took a bit of clicking, but no login needed to see the "feed". https://cringeout.com/feed
My worry with the confidence scoring is that it conflates "an agent used this and didn't obviously break" with "this is correct". An agent can follow bad advice for several steps before anything fails. So a KU gaining confirmation weight doesn't tell you much about whether it's actually true, just that it propagated. You're crowd-sourcing correctness from sources that can't reliably detect their own mistakes.
It's why at Tessl we treat evals as a first-class part of the development process rather than an afterthought. Without some mechanism to verify quality beyond adoption, you end up with a very efficient way to spread confident nonsense at scale.
The agents are smart enough to write the evals too.
It's agents all the way down!
Submit a GitHub repo containing skills to Tessl, and it will generate the evals, run them, and present the results. https://tessl.io/registry/skills/submit
The evals and results are all shown, no login necessary, so you can assess them yourself. e.g. https://tessl.io/registry/skills/github/coreyhaines31/market... (click details to see the eval texts).
The vulnerability database search didn't find CVE-2024-9990 - a valid CVE according to NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-9990
I submitted a package-lock.json file to the playground and got a vulnerability report after processing. The sort order next to the pie chart is weird. Medium / High / Critical / Low. I'd expect Critical / High / Medium / Low?
The vuln report ended up in my email spam folder.
I had to hit 'resend' multiple times to receive the verification email. Once I did, I had to either create a new account or login. I don't yet have a password. When I tried to create an account, it said my email was already taken. This onboarding flow seems quite janky.
Is Vulert Open Source software? I couldn't find any links or repos. What does "Join the Open-Source Security Movement" mean in this context?
Probably because the Car Thing was never made available outside the US.
I submitted two open-source tools. The submission form has a field for 'License' in which the only two options are 'Free' and 'Commercial'. Those aren't licenses. Maybe adjust that field to either say 'cost' or 'terms', or actually have a license field which lets you paste an SPDX entry (or entries) or pick a license from a list.
There certainly used to be a strong push to have internal people use the product a lot more during the development cycle. There was also a real desire to make the devel version actually usable. That fell by the wayside, sadly.
Having your developer workstation break while you have a backlog full of stuff to do, would absolutely make you less motivated to run the developer release. Especially if you're not on the desktop team.
First comment on the video - from the maker of the video - is " FIX (worked for me): write Ubuntu ISO to USB flash with dd"
So, yeah. Okay.
(Speaking as ex-Canonical, and still Ubuntu user. I upgraded my ThinkPad 2 days before release, and it was a catastrophe I had to manually un-fudge with the help of the apt maintainer. It was a packaging problem).
My feeling on this particular release is that it was rushed out, and should probably have been kept back for a month or two. The xz and t64 (2038) issues occupied some unexpected time this cycle.
Also, there used to be a dedicated QA lab which did a whole slew of automated tests. I don't believe that still exists.
Also, also. The Ubuntu community has shrunk, which means fewer people doing QA.
Also, also, also. The guy running the desktop team left the day after the release. Read into that what you will.
RHEL even shipped upstart before systemd was a thing.
Love that book. It enabled me to have one of my favourite flights of all time. Sat next to Chris Turner, chatting about his time at Acorn for about 9 hours.
I blogged about something related and included this anecdote part way through. https://popey.com/blog/2023/09/a-virus-for-the-bbc-micro/ - under "A short aside"
Looks like the repo was just removed from GH.
Been using and contributing to (and working for) Ubuntu on everything since 2005 or so.
I still use it for everything. I don't have time or inclination to switch. However I have been somewhat convinced to take a look at Nix (packaging) for some of the tools I use. But all my existing systems are fine. So likely when I next get a work machine (next week) I'll probably (if allowed) use Nix to install anything developer related over and above the stock image and supplied packages.
Possibly this one https://twitter.com/CertiKAlert/status/1777632812700713254
No, the Ubuntu community is pushing Flutter, not upstream GNOME.
Like the desktop app store, the Ubuntu installer is now written in Flutter.
Seems fixed now, I just submitted a podcast feed.
Abstract: Generative AI (GAI) offers unprecedented possibilities but its commercialization has raised concerns about transparency, reproducibility, bias, and safety. Many "open-source" GAI models lack the necessary components for full understanding and reproduction, and some use restrictive licenses, a practice known as "openwashing." We propose the Model Openness Framework (MOF), a ranked classification system that rates machine learning models based on their completeness and openness, following principles of open science, open source, open data, and open access. The MOF requires specific components of the model development lifecycle to be included and released under appropriate open licenses. This framework aims to prevent misrepresentation of models claiming to be open, guide researchers and developers in providing all model components under permissive licenses, and help companies, academia, and hobbyists identify models that can be safely adopted without restrictions. Wide adoption of the MOF will foster a more open AI ecosystem, accelerating research, innovation, and adoption.
This is coming up on 20 years old soon. Maybe add [2006] to the title :D
https://web.archive.org/web/20060315081659/http://www.ex-par...
I enjoyed this nostalgic talk from DefCon 31 by David Leadbeater, and you might, too.
I further thought about your feedback and the comments from the owner of exchangerate-API and have removed that section from the blog and mentioned it in a follow-up post.
I appreciate your comments, as they made me think more about that topic.
Hi Alex!
Yes, I understood your point.
Back in the day, we had long internal conversations about doing verification 'properly' with government-issued IDs, third-party verification agencies and the like. But that never amounted to anything, sadly.
They might consider it further if the store got to a decent scale (like the contemporaries like iOS, Play and Microsoft). But with "only" 6K applications published, and the money canon being pointed in other directions, I can't see it happening any time soon.
Indeed, the victim, in this case, did mention on the linked 4chan thread that they realised their mistake. While we only see a small part of their world through text communication on forums, I suspect they're kicking themselves in the real world.
Or perhaps not, and they have a ton of other wallets full to the brim with crypto-nonsense.
Sure, there was a bit of guesswork on my part. I could analyse the traffic in more detail, but when I wrote this all up, it was Sunday evening, and I wanted to do the minimum analysis to get a response to the unlucky rube.
I still have the snap, and could test further, but I suspect the endpoint linode boxes will disappear and popup somewhere else sometime.
Maybe I could have worded that sentence better. Thanks for the feedback. It wasn't intended the way you took it. But I appreciate you mentioning it anyway.
When I signed up and put in my credit card details, they immediately cancelled my order and completely deleted my account. I had to resort to moaning at them on twitter to get them to unblock me, which they did. Bit of a rubbish start to the journey though.
I usually get this kind of data from https://layoffs.fyi/
When this topic comes up I usually check https://layoffs.fyi/ which typically has roughly up to date data, but isn't 100% accurate of course, because it relies on submissions.
Heh, Rabbit (another one) was a location-specific mobile phone company in the UK back in the early 1990's. You had to be near an antenna to make or receive a call. It's the first thing that came to mind when this post came up.