Skip Navigation

Posts
5
Comments
306
Joined
3 yr. ago

  • I second this. I only started slowly switching to nvim few months ago, and I already can feel slightly annoyed when I have to take off my hands of the keyboard to reach for a mouse, or when I'm editting a text in i.e a browser, want to make an edit few words back, and I have to spam keys like a madman instead of just jumping where I need to be.

    It's addicting and extremely comfortable, having a good keyboard navigation controls.

    I really need to look into tiled window managers and a browser.

  • I do also like all the alt and ctrl combinations with arrow keys to move lines, blocks and jump over words.

    That's what I love the most about VIM, that it has dozen little tricks like these. Need to jump over a word? Jump to next occurance of letter L? Jump five words? Jump to second parameter of a function definition? Jump to matching bracket? There's a motion for all of that, and more. Including "go to definition" or "go to references", if you set up your vim correctly.

    I don’t even know where to start to make vim or neovim do all that.

    What I did was simply install IdeaVIM into my Rider, so I can start learning the motions while also keep the features of the IDE I'm used to, but also more importantly installed LazyVim, which is a pre-made config for nvim that can do most of that by default, or has a simple addon menu (LazyExtras) that automatically download and install plugins relevant for a language you are working on. I.e I need to work in Zig, I just open LazyExtras menu, find zig-lang, and it install LSP, debugger, linter, etc that's specific for that language.

  • From a very quick glanceit looks similar to https://logseq.com/, which I've been using for some time now and absolutely enjoy.

    The querying stuf and "referenced by" box on pages is awesome, and I like the journalling format.

    Once I solved sync troubles (with a git repo), it was great.

  • Definitely, but the issue is that even the security companies that actually do the assesments also seem to be heavily transitioning towards AI.

    To be fair, in some cases, ML is actually really good (i.e in EDRs. Bypassing a ML-trained EDR is really annoying, since you can't easily see what was it that triggered the detection, and that's good), and that will carry most of the prevention and compensate for the vulnerable and buggy software. A good EDR and WAF can stop a lot. That is, assuming you can afford such an EDR, AV won't do shit - but unless we get another Wannacry, no-one cares that a few dozen of people got hacked through random game/app, "it's probably their fault for installing random crap anyway".

    I've also already seen a lot of people either writing reports with, or building whole tools that run "agentic penetration tests". So, instead of a Nessus scan, or an actual Red Teamer building a scenario themselves, you get a LLM to write and decide a random course of action, and they just trust the results.

    Most of the cybersecurity SaaS corporates didn't care about the quality of the work before, just like the companies that are actually getting the services didn't care (but had to check a checkbox). There's not really an incentive for them to do so, worst case you get into a finger-pointing scenario ("We did have it pentested" -> "But our contract says that we can't 100% find everything, and this wasn't found because XYZ... Here's a report with our methodology that we did everything right"), or the modern equivalent of "It was the AI's fault", maybe get a slap on the wrist, but I think that it will not get more important, but way, way more depressing than it already was three years ago.

    I'd estimate it will take around a decade of unusable software and dozens of extremely major security breaches before any of the large corporations (on any side) concedes that AI was really, really stupid idea. And at that time they'll probably also realize that they can just get away with buggy vulnerable software and not care, since breaches will be pretty common place, and probably won't affect larger companies with good (and expensive) frontline mitigation tools.

  • I have worked as a pentester and eventually a Red Team lead before leaving foe gamedev, and oh god this is so horrifiying to read.

    The state of the industry was alredy extremely depressing, which is why I left. Even without all of this AI craze, the fact that I was able to get from a junior to Red Team Lead, in a corporation with hundreds of employees, in a span of 4 years is already fucked up, solely because Red Teaming was starting to be a buzz word, and I had passion for the field and for Shadowrun while also being good at presentations that customers liked.

    When I got into the team, the "inhouse custom malware" was a web server with a script that pools it for commands to run with cmd.exe. It had a pretty involved custom obfuscation, but it took me lile two engagements and the guy responsible for it to leave before I even (during my own research) found out that WinAPI is a thing, and that you actually should run stuff from memory and why. And I was just a junior at the time, and this "revelation" got me eventually a unofficial RT Lead position, with 2 MDs per month for learning and internal development, rest had to be on engagements.

    And even then, we were able to do kind of OK in engagements, because the customers didn't know and also didn't care. I was always able to come up with "lessons learned", and we always found out some glaring sec policy issues, even with limited tools, but the thing is - they still did not care. We reported something, and two years ago they still had the same bruteforcable kerberos tickets. It already felt like the industry is just a scam done for appearances, and if it's now just AIs talking to the AIs then, well, I don't think much would change.

    But it sucks. I love offensive security, it was really interresting few years of my carreer, but ot was so sad to do, if you wanted to do it well :(

  • I might be mistaken, but I think that if you use the free version, it's also opt out, because IIRC it's also an individual non-commerecial licence.

    For individuals on non-commercial licenses: Data sharing is enabled by default, but you can turn it off anytime in the settings.

    At least on the prouct page, the free tier is literaly called "Rider Non-commercial", under Individuals tab.

  • For me, the issue isn't as much that they are forcing the data collection (on some/free people, to be clear).

    I have issues with the way they are spending their development money, that I give them for the product. I don't care about the AI hype slop, that apparently can't even get good results (which they outright admit in the blogpost), instead of actually making the core features of the editor better. Everyone knows at this point it's a hype bubble that will never be usable, and they are grasping at straws.

    I don't want to pay 200$ a year only for them to add a dumb chatbot and data collection into my IDE, or make the code completion dumber and random instead of actually being deterministic. So I don't, canceled my subscription and I'm sticking to the perpetual license while slowly switching to nvim. But I can still make fun of them about it. I have been recommending JetBrains products for most of my life, and they have disappointed me with the direction they are going, so I'll make sure to un-recommend it.

  • The context is that they made a blogpost that's written in, at least in my opinion, extremely pleading tone. They are basically crying that they can't make a good AI with public data, and if you please could turn on their new AI data collection that would steal all your code. I've seen a few "we will use your data for AI" posts, and this was just unsettling, with the tone in which it was written.

    I can't really say why, but I find this style of communication pretty unsettling. It does have exactly the same wibe as the picture in the post.

    So, if you pay for their IDEs, nothing changes, but you can opt-in into them using your data for AI training, and they are pleading you do. If you use the free version, it's opt out and turned on by default.

  • I don't think it's misleading, or at leas the point was not to imply that they are forcing the data collection (which they are, for free users, but it is opt-out). The point is that they are actually downright emotionally manipulating in the blogpost. The blogpost in which they announce it, at least in my opinion, is written in exactly the same tone as the picture. They are basically crying that they can't make a good AI without stealing your private data, pleading you to turn it on.

    I've seen a few similar posts of products announcing AI data collection, and this one was the most unsettling, hence the meme.

  • This was one of my biggest issues, but I did manage to succesfully switch to nvim few months ago, by installing ideavim into Rider, vscode-vim into vscode (so I can't easily escape it when I get lazy), but most importantly - setting LazyVim as my default editor, which has been a lifesaver.

    It has a pretty good LazyExtras interface for easily installing a ton of plugins, almost for every language. You just open the LazyVim menu, select a language you want, and it installs LSPs, debuggers and whatnot you may need for it. It's probably using the nvim-lspconfig mentioned in other comments, but it has been pretty seamless.

    But any other pre-made nvim config will work, this one is just more approachable than someone's random plugin list.

  • That's exactly what I did, switching from Rider. LazyVim helped with getting a usable setup (especially LSPs are pain to setup without it), https://www.vim-hero.com/ taught me the absolute basics of navigation, and then I simply installed IdeaVIM into Rider to force myself to use it, and switched my default editor to LazyVim.

    It has already been a few months, and I'm pretty used to it. I still fumble here and there, I still have to stop and think then doing more involved operations, but for the basic editing I wouldn't go back.

    The most important observation I have is that it does not make me more efficient at editting text, the fumbles and mistakes usually offset any gains I have from the many navigation/jump/repeat keys, and reaching for the mouse would be quicker, but -

    It's super fun. Learning new motions is satisfying, you can see progress, and by slowly adding a new motion, then trying to get it to your muscle memory is simply fun. And there's always something to learn, a new motion to add or make more efficient. It's basically gamified text editting, and if you like mastering things in the muscle memory sense, it's awesome. I'd absolutely recommend everyone to make the switch, but not for "being a faster/more efficent at text editting" reason, because if you want that, learning every single IDE keybind will make you faster faster.

    Also, it's surprisingly comfortable not having to reach for a mouse. It has only been a few months, and I'm getting slightly annoyed whenever a program doesn't have a hotkey for proper navigation and I have to touch my mouse, hah.

  • If I got a Copilot license, I'd definitely make sure to expend my quota every single day and use it as much as possible. Especially if I was "highly encouraged" to use it.

    Just run a markov chain and let it talk to the thing. It's expensive to make the queries, for MS.

  • I have canceled my subscription the moment they started spending development time on AI hype instead of their core product.

    I can still use the fallback licence (you keep the version you've paid a year for, i.e 2023, forever), and I will do so until it stops working, while transitioning to other editor wherever possible (nvim in my case, which I've already gotten used to pretty well thanks to ideaVim)

    Until they stop with the overhyped AI bullshit, I won't get a new version. And, seeing how they beg for user data in the most uncanny blogpost possible, that'll probably be never.

    It's a shame, I liked jetbrains.

  • I discovered powertoys only recently, and it's a pretty cool set of tools. From color picker, tiling window manager to regex file renames or copy/paste tools, it has a lot of QoL features.

    If you have to be on windows, i.e due ro work, I recommend not sleeping on it.

  • Once they started pushing the AI shit, I immediately unsubscribed and am sticking to my perpetual/fallback (or whatever is it called) license. I don't see any reason to continue paying for new versions and features, when most of those new features are AI related, and I slowly started transitioning into nvim.

    Also, I really hate the tone in which this blogpost is written. As if crying in a blog post changes anything about how extremely anti-consumer this move is. Fuck off, JetBrains.

  • I've been using Kagi for several years, before eventually switching to Ecosia once I got a second update newsletter from Kagi that focused solely on AI.

    Can I turn it off? Probably, but I refuse to give my money to a company that spends it on AI in any way, shape or form.

    Ecosia is at least a non-profit with a pretty good mesage, and while they have a gimmick "AI chat" tab (btw, "come chat with out [openai] chatbot and ask about how the be more energy netural and support ecology" is the most insanely cursed and out of touch sentence ever, what the fuck), I don't think there's an AI summary at least.

  • I was toying around with an idea for a VCS that uses LLM as a compression method, where during pushes it just asks an LLM to describe what your diff contains (what changes it makes to what files), you push that summary to the origin, and when you pull it just plops that into another llm to reconstruct the files or make the file changes.

    If it wasn't such a waste of energy, I'd find that a pretty funny random side project. Would love to see the results.

  • This, the internet is already filled with AI slop articles that by now make majority of what's posted here, and adding "OMG LOOK AT WHAT AI SAID" posts makes it even worse, and it's pretty difficult to make a blocking filter for.

  • Is it working for you now? I didn't have any issues for the past few months, but they changed their anticheat to denuvo in a yesterday's patch (or rather, do a technical test for later rollout), and I'm getting security violations now.

  • Tbh I have no idea, I just like the evolution stone analogy :D