Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.
I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.
Scoring internet points that can be converted into CV line items and promotion package paragraphs is vastly better than squandering it all for a quick dunk.
And this is not something that you can leave up to the private sector. It’s not something where you can do your own research. It’s a very complicated world out there. And the informational burden of trying to figure out whether the people responsible for your package of hamburger are actually following safe procedures, that’s beyond everybody.
If you look at those things, they're kind of just bad programming practices. I I don't really know how else to say them. They don't mesh well when you put them together.
maybe performance could be part of a package where you try to take on one of those players. like, hey, look at how much more responsive our thing is than theirs. Might be a nice plus, but that's not going to be sufficient.
But passing an automatic filter is not a substitute for community acceptance; I do not believe that human referees can be removed from the publication process.
I wish everybody read this book. The surprising thing is that many aspects and recommendations apply to virtually any language, not specifically English.
I truly believe these these models are already just incredibly powerful. Like they should they should be so powerful to fuel, you know, um many many points of expansion of GDP growth and I think it's like up to smart people with vision and ambition to make all that happen.
part of the goal of programs is to communicate intent to other human beings and now to models as well which which is a much more open-ended problem. We understand a lot more about how to communicate to other human beings whether we apply that understanding or not. We don't understand at all how to communicate effectively to models
I would agree to that type of package for every company I've ever worked with, and most CEOs wouldn't take it. Uh, it basically says you don't make money unless the stock goes way up. And if you stock goes way up, you make an obscene amount of money. And I would do that deal over and over and over and over again.
the point is that where we always get bottlenecked is where the the previous processes and and and heuristics don't apply. Right? Like that's almost sort of definitionally what causes the bottlenecks.
I don't think that human preference is just an equation that people can just like package nicely and like, "Hey, ask people like which which of these two answers people would prefer?" It's very very personal, very culturally dependent, geographically dependent, age dependent.
a lot of companies haven't started until now thinking about how we could apply AI to the very human, very business process part of it. And so, that will keep slowing us down until we find a way to to address it, right?
Uh but whenever we do a systematic study, um any given problem, an AI tool has a success rate of maybe 1 or 2%. Uh it's just that it's just that they can apply at scale and and you just pick the winners, it looks great.
Basically what that gives you is like you can apply a lot of theoretical sort of um a lot of theoretical toolkit used in physics to model parts of this question in ways that are actually useful. And it is just not true that you can use like equations from physics to think usefully about almost any other problem in biology.
So this is a filter. Like if I'm talking to you, it takes effort to put it down on the page. I don't record anything that I've filtered it. It's interesting enough to me that it belongs on the page.
it's, I think, critical that ideas don't die on the vine because you've got, um, a visual expression that doesn't match what everyone else expects. Sometimes people will just filter them out because they don't look right.
The bitter lesson. Oh, who cares about that? That's that's an empirical observation about a particular period in history. 70 years in history no longer doesn't necessarily have to apply the next 70 years.
While the same does not directly apply in other fields, working with others to produce the best results for everyone will be much better in the long-term than focusing solely on what Amazon needs right now.
My model is that research requires a mix of skills. The day-to-day coding and execution is crucial. But there's also a set of harder-to-learn conceptual skills, collectively called research taste. These skills take a long time to gain because they have poor feedback loops, but they take very little time to use.
You already bought that phone, why should Apple be adding a 30% junk fee to all commerce you do, and why do they selectively apply it to some things and not others? I've always viewed this as deeply abusive and that it shuts down the competitive engine that once fueled the app and software economy.
The journey is better than the destination. Everyone's heard this. Just take one second to apply what that means. That means forever starting from now, you are only going towards a place that's worse.
So, Japan has a law which you're allowed to train on any training data and copyrights don't apply if you want to train a model, A. B, Japan has 9 gigawatts of curtailed nuclear power. C, Japan is allowed under the AI diffusion rule to import as many GPUs as they'd like.
And my contrarian opinion is that full-time jobs are not the best way to monetize the skill that you have. It's one of the packages that everybody should evaluate and take advantage of, but too many people blindly default to that package
This "memorize, fetch, apply" paradigm can achieve arbitrary levels of skills at arbitrary tasks given appropriate training data, but it cannot adapt to novelty or pick up new skills on the fly (which is to say that there is no fluid intelligence at play here.)
Their words now
OpenAI's new o3 model represents a significant leap forward in AI's ability to adapt to novel tasks. This is not merely incremental improvement, but a genuine breakthrough, marking a qualitative shift in AI capabilities compared to the prior limitations of LLMs.
An eye-opening view on considerations going into building a widely used public API or reusable library. While the book focuses on the .NET framework, many of the conventions apply to maintainable and reusable components, in general. This book had an outsized impact on me as I read it when I was a mid-level .NET developer.
I’m also still not sure how much I like nix – it’s very confusing! But it’s helped me compile some software that I was struggling to compile otherwise, and in general it seems to install things faster than homebrew.
Their words now
I’ve mostly switched back to Homebrew, nix was interesting but overall I think it’s not worth the complexity for me
I think if we can achieve that amount of inference compute, where it leads to a dramatically better answer as you apply more inference compute, I think that will be the beginning of real reasoning breakthroughs.
That is, labs should make sure that the safety measures they apply to their powerful models prevent unacceptably bad outcomes, even if the AIs are misaligned and intentionally try to subvert those safety measures.
That is absolutely possible. I’m actually putting less credence on that one just because you need to happen every single time. If even one, I mean, this goes back to John von Neumann pointed out that you don’t need to send the aliens around the galaxy. You can build self-reproducing probes and send them around the galaxy.
a new relationship is like fresh powder. It is new and shiny and exciting but it will not be a new relationship for long. And then you're still stuck with an old relationship and the question is will your old relationship a year from now be better than your old relationship that you currently have is? And if the answer is yes then yes sunk costs completely apply. But if the answer is no then what you're really doing is shopping for novelty not ignoring sunk costs.
So abstract. Maybe the most abstract book you’ll ever read. Compares “finite” games with rules and winners, versus “infinite” games without winners where we can play with the game itself. Is it about a job versus a calling? Religion versus spirituality? A story versus story-telling? Who knows. Thought-provoking if you can apply the metaphor to whatever concerns you.
my central thesis about the world is there’s things that centralize power, and they’re bad. There’s things that decentralize power, and they’re good. Everything I can do to help decentralize power, I’d like to do.
people get up to a certain level of performance, and then they start to stagnate. And they start to plateau. And people who who break through and move to the next level um are the ones who have to who engage in unlearning. Who realize there are certain uh conventions they've bought into or beliefs they hold that are either wrong or are limited and and don't apply as broadly as as they imagine.
If you want one book to teach you everything you need to know about giving great presentations, this is the book. A film director, a psychologist, and an actor share their combined experiences to help improve your content, the design, your movements, and just about every other detail of being a great speaker. It was a slow start, but by the end, I had dog-eared dozens of pages and marked up many more which I was able to directly apply to a major talk I was working on.
This is a great book for understanding how the creative process works. It left me with a lot of ideas I could apply to my day to day to be more creative. After living in the world of startups and business in real life and most of the books I read, it was great to hear how the different world of dance performance can be learned from.
If you're curious how Google built it's culture and the processes thanks to their extremely data & engineering driven nature, this is a great book. What held it back was being ~100 pages too long and Bock didn't always understand where what they did only fit at a $100Bn+, mega-profitable company. Still, the insights on the studies on their 50,000+ employees is well worth the read since so few of us can get similar statistical significance to apply to our teams.
It goes much further and deeper into how to approach actually doing Lean in your business than Eric Ries's The Lean Startup book. It also has some awesome case studies showing how lean can apply to any industry. See my full review here.
Simple, practical, useful. This book is a quick read that covers modern positioning and how to do it. Unlike all the theoretical books out there, this is a VC who lived a life as a marketer (all the way up to CMO/VP) doing this and then worked with more entrepreneurs. This hands on experience leads to a system that is easy to understand and apply. I'm now trying to apply it so this score will rise or fall based on the results we have.
This is what I wish I learned from in my freshman year of college. The part of it about linear algebra is one of the best linear algebra resources out there, and remainder shows you how those tools apply to non-linear mathematics.
Work that’s too fine, too early commits everyone to the wrong details. Designers and programmers need room to apply their own judgement and expertise when they roll up their sleeves and discover all the real trade-offs that emerge.
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com.
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.