pull down to refresh
What's funny is that in reading the LLM analysis slop, most often you'll find real root causes and failing mitigations with hydrocarbon intelligence rather than the silicon kind. Volume and speed aren't worth much if you don't understand the issue, how to fix it, what other things are affected, and so on.
You can also ask an LLM all these questions, even in a fully automated framework, but due to error rate compounding, even if it is "only" 5% (it's higher on everything I tried thus far, also the models that are labeled as near-perfect right now) diligence still requires humans because experience reduces the compounding rate, even if our error rate is higher.
Opensats spent $55k on this apparently.
They spent 55k on what? You can't buy a Blackwell rack for 55k. Did they spend it on CCP hosted GPU time?
Thats what I saw on nostr! They wear it like a badge of honor it appears.
The token spend with open AI and Claude for their frontier models.
Prompting ain’t cheap no mo
I saw Calle thanking Kimi for special unrestricted access in one of Scoresbys reports. Kimi = CCP
I was thinking maybe these bots are rubbing off and I hallucinated this. But I found it.
Image where I spotted it:
SN Source: #1539905
Tweeter source: https://x.com/callebtc/status/2084561246305542617
Nitter source: https://nitter.net/callebtc/status/2084561246305542617
This means: opti is not hallucinating. Opti is also not wrong at all that there are a million ways how your vuln can leak before you even get the email.
Note: one additional thing: there is another, later tweet (#1541457) where calle is additionally thanking wafer.ai as well as moonshot, meaning that perhaps there is now (also) US based infra, so now at least they can be frontran and your open source project can be attacked by US and CCP spooks... concurrently, before you even get the email.
so now at least they can be frontran and your open source project can be attacked by US and CCP spooks
all stinks
I'm mostly just worried about execution. The PR stunt surrounding this is a red flag. You still need the human verification of someone that either knows the code, or learns the code on the spot. And this is what is "outsourced", under pressure, to maintainers. With the message "just feed it to your AI", which is poor advice. 55k in tokens or GPU rental is not the real cost. The real cost is on the shoulders of 300+ maintainers that need to spend time, and if they have standards, a lot of it.
Last night I ran a diff of some upstream dependency through a bot. It was large (almost 700kB) and definitely vibe-coded but it is flagged by the security cartel (aka GitHub, aka Microsoft, which is fucking funny if you think about it) as a critical vuln. Reviewing slop code from 3rd parties is a waste of your time in general, so at scale you have no choice but to fight fire with fire. I have fine-tuned a toolset to make it not make the usual mistakes of assigning value statements and just flagging up odd things by reconstructing end-to-end integration paths and scanning for threats. Most of the time, it finds a nit here and there on security patches, but nothing substantial. Last night it came back with an actual list of perceived regressions and warnings and red flags. Now I have to review slop code from some asshole that couldn't just patch a vuln manually and test it, like we used to do since the beginning of software.
Maybe you didn’t kill my dream after all. After reading this comment it confirms that I would need extensive training to be good at this. Time I just don’t have at my age
"We are going to find vulnerabilities in Bitcoin FOSS apps and fix them with AI..."
Smile... tomorrow will be worse