Live data from Hacker News

Viewing profile — joshka

joshka

HN member
Joined
Mon, Jun 06, 2011, 11:51 AM UTC
HN karma
2,190
Public activity
1,277 items

About joshka

[ my public key: https://keybase.io/joshka; my proof: https://keybase.io/joshka/sigs/ElI6j13SI-_2rTrkLnoKyV-uDepH4JvAQAzp2OWV_W0 ]

Recent public activity

  1. comment
    Comment #49195461

    The current thing that comes up regularly is choosing an LLM setup.

  2. comment
    Comment #49195428

    lol same :D

  3. story
  4. comment
  5. comment
    Comment #49151571

    This, but I'd say that there is an engineering perspective that you can apply. What the developer world is trying to discover here is how to encode taste concretely - often this is…

  6. comment
    Comment #49151556

    I've done VHS (terminal recording) rewrite in rust built on libghostty called Betamax [1], and then threw it at creating a TUI for jujutsu. This worked pretty well, but is admitted…

  7. comment
    Comment #49141013

    Take a look also at https://tropes.fyi/ I've put in some effort to try to help agentic tools avoid these problems: https://www.joshka.net/practice/rules/documentation/docs-avo... .…

  8. comment
    Comment #49128497

    Some agents have specific tools that the models have been trained to use. E.g. diff formats for editing that aren't the same as the standard unified diff format. Access to specific…

  9. comment
    Comment #49094677

    Yeah, what bothers me is that the prompt already said using a different vulnerability didn’t count, and the model did it anyway. We’re starting to assume clear instructions act as …

  10. comment
    Comment #49094507

    The exploit gym setup explicitly allowed access to package registries and v8 sources. Putting a cache on that doesn't seem like a bad idea generally, except when there's a 0-day in…

  11. story
  12. comment
    Comment #49091576

    Thanks for the reply here. I guess I have some perspectives on a bunch of this. I'm for open sharing of academic work for all (but I'm not an academic, so my perspective is a consu…

  13. comment
    Comment #49090926

    This is freaking good.

  14. comment
    Comment #49090806

    How do you square away the idea that you do science for the increase in knowledge of human kind, but then say that a particular use of that knowledge is verboten? I get the copyrig…

  15. comment
    Comment #49090637

    Consider optimizing your demo for laptop user screen sizes and checking contrast of all elements. A lot of things on the demo are difficult to read fast due to low contrast, which …

  16. comment
    Comment #49090461

    discussion / article: https://news.ycombinator.com/item?id=49087091

  17. comment
    Comment #49090426

    https://huggingface.co/blog/agent-intrusion-technical-timeli... has that side of the write up a bit more discussion: https://news.ycombinator.com/item?id=49089500

  18. comment
    Comment #49071782

    Makes you wonder whether that reality has a left wing bias quote might have some legs after all (though it's probable more likely selection bias for the corpora)

  19. story
  20. comment
    Comment #49019143

    The other suspicion I had was jfrog artifactory (you mentioned OpenAI use it in a blog post in Jan). I accidentally conflated that with Nexus 14 july CVE. I think that's probably m…

  21. comment
    Comment #49018696

    I wonder if it was this bug fixed july 14 in sonatype: https://support.sonatype.com/hc/en-us/articles/5316501964136... pure speculation here - no non public info

  22. comment
    Comment #49018666

    There's no reason to think that a tool that can find an 0-day in a repo cache can't work out how to make that host send a post request rather than a get request once it has its key…

  23. comment
  24. comment
    Comment #49004235

    https://news.ycombinator.com/item?id=49003386

  25. comment
    Comment #49002281

    yes, and... ?