Damus

Recent Notes

equinox · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 that's another submission on the review pile 😂
Buridan's procrastinator ⁂ · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 what's "gullible" in latin? 🤔 Homo gullibilis?
Stefan Eissing profile picture
If a libcurl application does the following several steps in the API and connects to 2(!) RTSP servers that use digest authentication and the second server is run by a malicious agent and the same easy handle is used and...

Sure, dude...
Stefan Eissing profile picture
Interested in a Mythos scan?

„Kindly note that Anthropic states that individuals chosen to participate are a) ideally US-based, and b) subject to passing a security check.“

Maybe not.
Dr. TheDbof :verified: · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 well I just wrote a rant about this. How can I react to mistakes made with or using AI...
Stefan Eissing profile picture
@nprofile1q... It depends on the situation. If your boss drop LLM output into your inbox and think that is the way to go, you are probably very limited.

If a random person drop such a thing into your project, you can refuse to process it without further work by the submitter.

I experience LLM output as part of being a maintainer. And a FOSS project should not feel obligated to accommodate such behavior, IMO.

I do not care what tools someone uses. I care how we communicate and collaborate.
Dj PorCus - Will · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 so in other words ' please send me the prompt ' ? would that be acceptable ?
Stefan Eissing profile picture
@nprofile1q... No. The prompt could be "Find a security vulnerability in #curl".

I'd want to know *what exactly* the submitted LLM output found and why it is a vulnerability (and not some bug).

In the reporters words. To make sure they read it. If they did not read/understand it, it is not a communication.
Stefan Eissing profile picture
When I get a report which is obviously LLM output, I do not read it.

Instead, I ask the sender to summarize the novella in their own words, because I do not have the time, unless they explain to me why it‘s worthwhile.

My advice: do the same. Deflect, politely, LLM dumps. Let‘s make this a conversational norm.
2
Dj PorCus - Will · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 so in other words ' please send me the prompt ' ? would that be acceptable ?
Dr. TheDbof :verified: · 3w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpq7qes6mstpcsn6rg3w9fwnsau68sw9h9nga9zjy3htmegg27na6wsjd3n63 well I just wrote a rant about this. How can I react to mistakes made with or using AI? Can we always blame the person, or should we blame the AI companies for that? What can I reasonab...