Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.
I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.
Scoring internet points that can be converted into CV line items and promotion package paragraphs is vastly better than squandering it all for a quick dunk.
And this is not something that you can leave up to the private sector. It’s not something where you can do your own research. It’s a very complicated world out there. And the informational burden of trying to figure out whether the people responsible for your package of hamburger are actually following safe procedures, that’s beyond everybody.
Been using Astra for the last few weeks and it’s so good and proactive. There’s a bunch of PRs on vitest, tsx or SwiftPM where Astra debugged OC and ended up finding and patching issues in upstream dependencies.
there is evidence that the reversal effect has weakened over time, leaving investors who bet on mean reversion and a return to fundamentals in the lurch
maybe performance could be part of a package where you try to take on one of those players. like, hey, look at how much more responsive our thing is than theirs. Might be a nice plus, but that's not going to be sufficient.
I would agree to that type of package for every company I've ever worked with, and most CEOs wouldn't take it. Uh, it basically says you don't make money unless the stock goes way up. And if you stock goes way up, you make an obscene amount of money. And I would do that deal over and over and over and over again.
We need to flip it. We need to absolutely flip it, and we have to say, and this is what I always wanted to do with Nest, which is I want to remove displays, and we need to have voice as the number one primary feature, and you build around voice.
one of the things that I noticed about computers and I think today with mobile phones, uh is that in many ways they isolate us from one another, right? They actually take us out of our social interactions.
I don't think that human preference is just an equation that people can just like package nicely and like, "Hey, ask people like which which of these two answers people would prefer?" It's very very personal, very culturally dependent, geographically dependent, age dependent.
You cannot just reverse that, right? It's just not working. So, I do think that we need to build out the whole guardrails for the reversibility of actions because that actually where things get really really scary.
America needs an educational and cultural transformation to compete with China and reverse the decline in living standards that Americans have suffered over decades.
I think if you have especially a B2B feature where you may have some lock in reverse trials can be super powerful. You just want to get people in there. You don't need to ask for their credit card because they're using your CRM or they're investing quite a lot of time in like building out, you know, material and content. And so by the time that window drops, you actually like feel, oh man, I probably should keep this and and start paying. I think for a lot of consumer products, it's a little bit harder for that to work. And so I've typically seen more just normal free trials be be the norm.
I'm now fairly pessimistic about ambitious interpretability (i.e. complete reverse-engineering), and I'm excited about model biology (studying qualitative high-level properties of models) and applied interpretability (rigorously doing useful things with interp).
And the impact of solar array on desert is arguably positive because it shades the ground and improves like soil moisture retention. Um there like if you wanted to reverse desertification, you would basically just deploy solar panels on it and that would pay for the process.
It seems we're driven much more quickly by moods rather than thought-through ideas. Right now, it seems the ideas they follow the political mood and try to put together the underpinning of it where it really was the opposite for much of the 20th century.
Growth team can optimize. Growth can maybe lift it by 10, 15% maybe that's enough for you even that like is on the upper end of what growth team would be able to do if there is a slow down trajectory
If you have the overall business slowing down, your head of growth is destined to fail because the reason business is slowing down is much deeper than not having a growth team.
And my contrarian opinion is that full-time jobs are not the best way to monetize the skill that you have. It's one of the packages that everybody should evaluate and take advantage of, but too many people blindly default to that package
I think you have some guys that have their finger on the pulse there. We need to start thinking about how we’re going to survive this, not that we’re going to make it go away.
I’m also still not sure how much I like nix – it’s very confusing! But it’s helped me compile some software that I was struggling to compile otherwise, and in general it seems to install things faster than homebrew.
Their words now
I’ve mostly switched back to Homebrew, nix was interesting but overall I think it’s not worth the complexity for me
I started with a rather non-consensus hypothesis: companies want to pay for their critical open source dependencies, but most projects are not selling them a legible way to do so.
People tend to get excited about investments when stocks are going up and they get depressed when they're going down. And I think that's just inherently human. You have to reverse that. You have to get excited when things get cheaper and you got to get concerned when things get more expensive.
I think that the enshittification framework goes a long way to explaining it, moving us out of the mysterious realm of the 'great forces of history,' and into the material world of specific decisions made by named people – decisions we can reverse and people whose addresses and pitchfork sizes we can learn.
If you make the wrong decision, if it's a two-way door decision, you pick a door, you walk out and you spend a little time there. It turns out to be the wrong decision, you can come back in and pick another door. Some decisions are so consequential and so important and so hard to reverse that they really are one-way door decisions. You go in that door, you're not coming back. And those decisions have to be made very deliberately, very carefully.
But once the demographics reverse, the challenge will be to find a person for every job. In the coming years, the impact of demographic changes is going to lead to chronic labor shortages.
In many cases, the person specifying a new system won’t capture the upside from actually using it - they’ll be under a sort of reverse moral hazard, where the benefits accrue to the rest of the project team, but the risks will accrue only to them.
Instead of having people do the parts of a task that machines are bad at, let’s reverse the process and have machines do the parts that people are bad at. Instead of requiring people to work on technology’s terms, require the machines to work on human terms.
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com.
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.