Perhaps. That was yesterday, today there's 650+, with hundreds being tagged as bugs.
HN user
xtagon
Yeah, I see what you're saying.
This is great! Interesting to see how many navigation lights there are besides the obvious ones.
You're talking about if a box is compromised, but to clarify, this is hard coded into the source in the repo, not an end-user's credentials (and it's a `client_id` and `client_secret`, not a token): https://github.com/clawdbot/clawdbot/blob/7187c3d06765c9d3a7...
Wild. There are 300 open Github issues. One of them is this (also AI generated) security report: https://github.com/clawdbot/clawdbot/issues/1796 claiming findings of hundreds of high-risk issues, including examples of hard coded, unencrypted OAuth credentials.
I am...disinclined to install this software.
I don't feel like they owe me a refund in principle, at the end of the day I paid for subscription-free software and they delivered it, and I'm happy to do that exchange. I just don't like the changes and the future direction and that I won't be receiving updates to the one I'm currently using.
Not happy. I recently purchased the whole suite and now not only is it now free (didn't need to purchase it), but it's no longer even what I want. And it doesn't work on iPad until they finish whatever rewrite, when cross-platform + apple pencil niceness was a huge draw.
Sure, it's free -- but it's no longer the same product with the same priorities.
Non-destructive editing sounds great!
Not all rewriting and not all summarization is the same, and the surprising part is that it often makes it seem more legitimate. There's no reason, for example, that it couldn't rephrase it in a way that conveys it as suspicious.
This is like telling someone to learn programming by starting with assembly.
Believe it or not, this is some people's preferred learning style. See also: Nand2Tetris, Linux From Scratch
I highly, highly doubt we've reached the level of AI safety required to make it a good idea to replace (or even just supplement) caregivers for children. Nobody has truly solved the safety problems with AI yet, just doing the best they can--seems like a terrible idea to put that in direct intimate access of emotionally vulnerable children. We've already passed the threshold of AI suggesting to testers to commit suicide[0], and the bar has been raised to actual users being told that[1] and someone reportedly following through.[2]
[0] https://www.artificialintelligence-news.com/news/medical-cha...
[1] https://ainiro.io/blog/googles-ai-encouraging-people-to-comm...
[2] https://www.euronews.com/next/2023/03/31/man-ends-his-life-a...
Seems like a variation of https://en.wikipedia.org/wiki/The_Million_Dollar_Homepage but yearly instead of one-time payments. The Million Dollar Homepage had a sort of early-internet novelty vibe to it, but beyond that I don't get the practicality of this kind of thing. Okay so it's a billboard...who drives traffic to it? Who looks at the billboard other than once or twice to see if they want to rent their own space?
Not all ML is built on neural nets. Genetic programming and symbolic regression is fun because the resulting model is just code, and software devs know how to read code.
The types are no less protectable by authorization policies than the data, although authorization is hard to get right anyways, all else the same this architecture doesn't worsen it much--perhaps just less reverse engineering required to exploit vulnerabilities you already had.
Interestingly, you could accomplish a similar thing with GraphQL if the frontend uses the type introspection GraphQL provides and the backend graphql schema implements HATEOAS-like principles to let the frontend become a UI that's agnostic to different backends. That might not be how most GraphQL implementations are used, but it's kind of a cool pattern.
See also the phenomenon of it always taking 3 tries to plug in USB the correct way
Paywalled so if the article already mentions this I wouldn't know, but just going off "scroll" the title, I wonder if this would pair well with Dasher as an input method to replace typing with a keyboard.
If the user has to initiate all shuffles, it won't play continuously. If you handle it another way, that demonstrates that it doesn't "just" work with a pure shuffle without using those tricks.
Given a set of songs or albums {a, b, c}
Suppose shuffling results in ordered set [b, a, c]
Suppose user plays through the entire set. Now it's shuffled again before repating.
Suppose the new shuffle results in ordered set [c, a, b]
The user now hears c play after c
I'm pretty sure both Office 365 and Google Calendar have a way to generate an iCal URL. So you could just implement that, I would think.
Are the Whos within Whoville human?
Yes but how do I use WebAssembly as a markup language?
Those who say it can't be done should not interrupt the people doing it, I suppose!
See: https://keepass.info/integrity.html (you may want to manually type it into the address bar...) and download their PGP keys. That way you can verify KeePass downloads using their signatures, which you can save and sign with your own key to really verify the paranoid way. If you ever land on a bad download site, you'll know something's up after you verify and it doesn't match.
A mid-level human engineer can iteratively fix the mistakes they start making, instead of that just being the final result. Can GPT-4 do that?
I think where the semantics become relevant is that people say "project" to mean "product". When it's a product, it might never be 100% done, and it might be a poor idea to try to frame it as if it could be. But some projects aren't products, and don't have perpetual stakeholders, and for some of those it can be possible to set realistic 100% done targets and reach them.
I want news as an RSS/atom feed with properly consistent tags to filter by. That way I can opt in to just what I want to know, get it when it happens, and ignore everything else by default. But there isn't business value in news outlets providing this.
For the case/battery compartment part, hit up someone with a 3D printer (or a makerspace or library that has one)
The downside to things that "just work" is that they become magical black boxes where learning how they work isn't a requirement until things really go wrong.
The first two paragraphs of the home page say what it is:
MiniZinc is a free and open-source constraint modeling language.
You can use MiniZinc to model constraint satisfaction and optimization problems in a high-level, solver-independent way, taking advantage of a large library of pre-defined constraints. Your model is then compiled into FlatZinc, a solver input language that is understood by a wide range of solvers.