Any piece of software that depends on open source (which is almost every piece of software) has a network of human beings who are potential attack vectors - everyone with publishing rights to any of the packages in the dependency network for that software.
I guess our best defense right now is dependency cooldowns - giving new package releases a few days before upgrading to them, in the hope that supply chain attacks like this will be spotted by someone else.
Scoring internet points that can be converted into CV line items and promotion package paragraphs is vastly better than squandering it all for a quick dunk.
And this is not something that you can leave up to the private sector. It’s not something where you can do your own research. It’s a very complicated world out there. And the informational burden of trying to figure out whether the people responsible for your package of hamburger are actually following safe procedures, that’s beyond everybody.
maybe performance could be part of a package where you try to take on one of those players. like, hey, look at how much more responsive our thing is than theirs. Might be a nice plus, but that's not going to be sufficient.
One of the reasons that you don't see hotspot optimization as a thing that really matters that much anymore and one of the reasons I advise that architecture and and not making bad decisions is much more important is because a lot of libraries already have been optimized for you that you might use.
there are people who are really big on road maps and there are people who are really big on iteration. I I think the honest answer is you've got to do both. You can't over-index on either.
And so it's like I mean getting into Eli Goldrat and the goal is like optimizing for utilization and efficiency of one node in your factory rather than the end to end goal of like how do we ship value and things that people like that are stable and like will last a long time. But that's my idea of token harder
I would agree to that type of package for every company I've ever worked with, and most CEOs wouldn't take it. Uh, it basically says you don't make money unless the stock goes way up. And if you stock goes way up, you make an obscene amount of money. And I would do that deal over and over and over and over again.
as soon as you have an organization that's very large and very structured like that, uh people become very focused on getting a promotion, right? Getting, you know, into the next step of the hierarchy. And that means that all of a sudden, uh they become a lot more risk-averse.
And so our expertise um helps our our our um uh our AI labs partners get another 2x out of their stack easily. Often times it's not unusual that we you know by the time that we're done optimizing their stack or optimizing a particular kernel their model sped up by 3x 2x 50%.
I don't think that human preference is just an equation that people can just like package nicely and like, "Hey, ask people like which which of these two answers people would prefer?" It's very very personal, very culturally dependent, geographically dependent, age dependent.
Um And yeah, so I believe a lot in serendipity. Um And maybe there's a danger actually that you know, in the mo- modern society, it's not just AI, but we've become really good at optimizing everything.
this is a very deep truth about habits, which is a habit must be established before it can be improved. You know, it has to become the standard in your life before you can scale it up and optimize and turning it into something more. You need to standardize before you optimize.
the shareholder value movement is totally incoherent because over what time frame which shareholder is what are you optimizing for? It's a completely incoherent nonsense which is very very friendly to stock market analysts who want a ready supply of quarterly data
When you allow tech bros too much power over decision-making along with their running dog lackey in kind of management consultancy, you're optimizing for something which may be very very distant from what your real world customers really care about.
And my contrarian opinion is that full-time jobs are not the best way to monetize the skill that you have. It's one of the packages that everybody should evaluate and take advantage of, but too many people blindly default to that package
I’m also still not sure how much I like nix – it’s very confusing! But it’s helped me compile some software that I was struggling to compile otherwise, and in general it seems to install things faster than homebrew.
Their words now
I’ve mostly switched back to Homebrew, nix was interesting but overall I think it’s not worth the complexity for me
Profilers can only show you "what is there"; skillful performance engineering requires understanding the information that shapes and informs the profile but is "not there" in the profile itself.
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com.
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.