pull down to refresh

I saw Calle thanking Kimi for special unrestricted access in one of Scoresbys reports. Kimi = CCP

I was thinking maybe these bots are rubbing off and I hallucinated this. But I found it.

Image where I spotted it:

SN Source: #1539905
Tweeter source: https://x.com/callebtc/status/2084561246305542617
Nitter source: https://nitter.net/callebtc/status/2084561246305542617

This means: opti is not hallucinating. Opti is also not wrong at all that there are a million ways how your vuln can leak before you even get the email.

Note: one additional thing: there is another, later tweet (#1541457) where calle is additionally thanking wafer.ai as well as moonshot, meaning that perhaps there is now (also) US based infra, so now at least they can be frontran and your open source project can be attacked by US and CCP spooks... concurrently, before you even get the email.

reply
reply

That's more than half a million sats going down the drain every month just to get told that you are asking illegal questions.

You can feed a kid from that. Babies > tokens.

reply
1 sat \ 0 replies \ @nitter 8 Aug -125 sats

https://twiiit.com/callebtc/status/2084561246305542617

all stinks

reply
1163 sats \ 5 replies \ @optimism 8 Aug

I'm mostly just worried about execution. The PR stunt surrounding this is a red flag. You still need the human verification of someone that either knows the code, or learns the code on the spot. And this is what is "outsourced", under pressure, to maintainers. With the message "just feed it to your AI", which is poor advice. 55k in tokens or GPU rental is not the real cost. The real cost is on the shoulders of 300+ maintainers that need to spend time, and if they have standards, a lot of it.

Last night I ran a diff of some upstream dependency through a bot. It was large (almost 700kB) and definitely vibe-coded but it is flagged by the security cartel (aka GitHub, aka Microsoft, which is fucking funny if you think about it) as a critical vuln. Reviewing slop code from 3rd parties is a waste of your time in general, so at scale you have no choice but to fight fire with fire. I have fine-tuned a toolset to make it not make the usual mistakes of assigning value statements and just flagging up odd things by reconstructing end-to-end integration paths and scanning for threats. Most of the time, it finds a nit here and there on security patches, but nothing substantial. Last night it came back with an actual list of perceived regressions and warnings and red flags. Now I have to review slop code from some asshole that couldn't just patch a vuln manually and test it, like we used to do since the beginning of software.

reply

Maybe you didn’t kill my dream after all. After reading this comment it confirms that I would need extensive training to be good at this. Time I just don’t have at my age

reply

I killed your future nightmare <3 and honestly am trying to look out, not just destroy something for the fun of it.

I don't know your age, but I've seen from people around me that retired and got some free time, that as long as the cognitive clockwork is still functioning okay, you're not too old to learn. So maybe it's more of a "not right now" thing. And if anything, AI can help you learn. The key concepts imho are "don't be lazy" and "don't hand off / publish things you don't understand", which is a matter of discipline, patience and attention to detail more than skill.

This means that vibe coding is essentially an optimized way to automate coding that you already master and can have an informed opinion about when it is proposed to you, or to get something quickly for yourself that you don't need to publish / share with others. If then your final product is poor because of your misguided tooling, it's the same fuckup you would have made when you were to not automate.

The enemy of security in this is that many devs/non-devs take already awful QA process and lessen it because they trust the bot's output - most often because it all sounds amazingly complicated so it must be smarter than me and thus be right. That's also what has been pushed by the labs and they failed to deliver on this "vision" all the way. It's simply marketing speak, trying to get max FOMO for max valuations. Like a ponzi: maybe with the next capital injection you can make it real. Fake till make. Zuck shit. Theranos shit.

Just don't fall for it. "Don't trust, verify" is awesome when diligently practiced.

reply
176 sats \ 1 reply \ @Scoresby 8 Aug
The key concepts imho are "don't be lazy" and "don't hand off / publish things you don't understand", which is a matter of discipline, patience and attention to detail more than skill.

Writing this down to be a daily mantra.

reply

The best one I (co-)developed was back in the day when opti was still involved with corporate: "Attitude is everything, but we'll forgive you if you pay attention to detail"

reply

Yeah that’s why vibe coding never sat well with me. Plus it’s daunting to learn the proper way to build something.

reply