Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)D
Posts
2
Comments
165
Joined
1 yr. ago

  • SSH tunneling is the term for what you need here. You can set it up on either end, and it’ll transparently pipe data from a port on the VPS to your TLS box. Configure the web server to reverse-proxy that port, and you’re up and running.

  • The short answer is that vibe-coding works best when you have a well-structured, clean codebase with guide rails to assist the LLM. If you leave an LLM to its own devices though, the structure collapses and turns to slop over time.

    Human-in-loop coding with LLMs is a truly exceptional force multiplier. Vibe-coding with minimal review falls apart fast.

    Incremental improvements on the current models aren’t enough to overcome this dynamic; we’ll need another transformational step-function improvement to get to a place where an agent can consistently keep the codebase as coherent as a human can.

  • This part applies to all customers:

    v. Use of Your Content. As part of providing the AI services, Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring for and preventing abusive or harmful uses or outputs of the service.

    And while Microsoft has many variations of licensing terms for different jurisdictions and market segments, what they generally promise to opted-out enterprise customers is that they won’t use their inputs to train “public foundation models”. They’re still retaining those inputs, and they reserve the right to use them for training proprietary or specialized models, like safety-filters or summarizers meant to act as part of their broader AI platform, which could leak down the line.

    That’s also assuming Microsoft are competent, good-faith actors — which they definitely aren’t.

  • This is some pathetic chuddery you’re spewing…

    You wouldn’t assume that QA can read every email you send through their mail servers ”just because”

    I absolutely would, and Microsoft explicitly maintains the right to do that in their standard T&C, both for emails and for any data passed through their AI products.

    https://www.microsoft.com/en-us/servicesagreement#14s_AIServices

    v. Use of Your Content. As part of providing the AI services, Microsoft will process and store your inputs to the service as well as output from the service, for purposes of monitoring for and preventing abusive or harmful uses or outputs of the service.

    We don’t own Your Content, but we may use Your Content to operate Copilot and improve it. By using Copilot, you grant us permission to use Your Content, which means we can copy, distribute, transmit, publicly display, publicly perform, edit, translate, and reformat it, and we can give those same rights to others who work on our behalf.

    We get to decide whether to use Your Content, and we don’t have to pay you, ask your permission, or tell you when we do.

  • Your general understanding is entirely correct, but:

    Microsoft is almost certainly recording these summarization requests for QA and future training runs; that’s where the leakage would happen.

  • It’s a bit wandering, but this piece has great insight on the whole and explains the motivations behind a lot of abstract modern tooling.

    As a grugbrained/anti-complexity type of designer, I was pleased that the author did such a good job aligning their arguments so that they were equally relevant to single-node hegemonic deployments just as much as Web-Scale (TM) microservice soup.

  • I can absolutely see that making sense for a targeted attack.

    Are there bootkits in the wild that can reliably bootstrap to a rootkit on most non-Windows hosts these days? The hard part of that approach would be having a bootkit payload sophisticated enough to escalate to a meaningful form of exfiltration, I imagine.

  • Genuine curiosity: What kind of hardware bug would you go for if you wanted to spy on a relatively easy target like a Thinkpad from ten years ago, and had 1-2 hours to install it?

    My naive guess would be intercepting the monitor cable to pull occasional screencaps, but then you’d need a wireless modem to transmit out and you’d have pretty serious limitations on power draw (assuming you’re running off a cell battery and not splicing in somewhere).

  • might catch hardware backdoor on the border

    Say whatever you will about the CCP: there’s nobody on earth burning the level of resources needed to do that undetectably and reliably on some tourist pleb’s arbitrary hardware.

    More power to you if that’s what you wanna spend energy on, though.

  • Completely depends on what your threat model is, but personally:

    I'd make an encrypted image of my drives, upload that to remote storage, zero out the drives for border crossing, then restore over the wire on the other side.

  • The other common trap you might be hitting is trying to turn them too early.

    Once most foods (but potatoes especially) sear properly, they’ll release their hold on the pan and you won’t lose the skins/outer layer quite as easily.

  • I run Debian stable for all the reasons you describe.

    My experience is that you occasionally have to peek at the wiki to get things set up right initially, but after that, you’re set for many years.

    My daily driver is a bookworm install from 2021, and I’ll be running it until EOL. Zero issues with gaming; shit just works.

  • It’s just a meme site that was posted to HN and took off.

    No investors or purpose beyond putting a pool of chatbots together and watching the slop proliferate.

  • unless you consider it hard coded because its coded into the codebase

    That’s precisely the common definition and understanding of the term.

    E: Sorry, I see what you mean in context now. I thought we were talking about a different piefed feature with a similar anti-4chan label that used a set of hardcoded strings to blacklist comments. Yeah, the tesseract image filter isn’t quite what I’d call hardcoded in and of itself.

  • Make attainders great again

  • Best cat-rearing advice I ever received: Cats are gonna cat.

    You can try to fight their instinctive behavior all you want, but you’ll lose every time. What you’re describing is common dominance behavior between cats and not at all pathological. Just stop doling out attention when they beef, and throw them a treat if they’re hanging out amicably for a while.

    You can channel a river, but you can’t dam it entirely and expect to win forever.

  • Speaking as a born and raised Texan, I wouldn’t describe corn as a TexMex staple at all, outside of vegetarian dishes or corn tortillas.

    Maybe you have a few kernels in the rice depending on the restaurant, but it’s far from universal and more typical of cuisine from countries south of Mexico (e.g. Salvadorean).

    You can generally assume that anywhere serving proper elote is going to be a more true-Mexican street taco type of establishment.

  • Anything to deflect from the Epstein files.

  • As a rule of thumb, the more ethical companies are going to be smaller shops as opposed to household names, because they’re siphoning less of the economic value they produce into bloat and “hyperscaling”. Yet there are plenty such shops in every field doing quality work for clients at fair prices; they’re just not the ones making waves and catching press.

    If you’re seriously looking for something though, tell me your niche or PM your CV, and I’ll see if I can’t find something reasonable.