thesmokingman

joined 3 years ago
[–] thesmokingman@programming.dev 2 points 2 months ago (1 children)

I wouldn’t do any of that in a CI-only system. If I did, I’d use tools that exist for those jobs that already allow scripting languages.

  1. Why wouldn’t you use IaC tools for this? All the majors have Python already.
  2. What build or deploy task needs to both create and reference a bug ticket?
  3. What build or deploy task needs to do database lookups? Or possibly what task needs those across multiple, independent stages?
[–] thesmokingman@programming.dev 5 points 2 months ago (2 children)

I dislike scam money as much as the next person. I do not, however, dislike cryptography. There’s a really good common in the thread about elliptic curve cryptography not having a place on Codeberg anymore and I think that’s valid. I don’t even know if OpenSSL could have a place on Codeberg with this decision. Their nonprofit, their rules. Just not very libre-minded and definitely sets a bad precedent. And before someone tells me Microsoft actively censors GitHub, this isn’t a whataboutism thread. It just reduces my trust in a supposedly open collective.

[–] thesmokingman@programming.dev 1 points 2 months ago (3 children)

This is a boilerplate example. I asked for something more than boilerplate. Give me some reasons why I need an incredibly stateful CI engine.

[–] thesmokingman@programming.dev -1 points 2 months ago

AFAIK there have been no cases setting precedence for this copyright attack globally. I am also not aware of any hosting platform under government attack for hosting AI works. Similarly, the WTFPL has no precedence and its legal status is unclear (contrast against GPL and Apache precedence). However, Codeberg recommends WTFPL. I also find it incredibly hard to believe that all 650k+ projects on Codeberg have better security than AI slop.

Either be consistent or stay off the fucking bandwagon. If you’re going to make copyright a big deal, you can only advocate for licenses that have precedence. If you’re going to say shitty security slop matters, you need a real security review process and active testing+moderation. Moderation like this opens up different classifications of scrutiny and isn’t a good look for a libre platform.

Note that I think the idea is solid and agree with the reasoning. I just don’t think this is the execution that makes people think differently about AI.

[–] thesmokingman@programming.dev 1 points 2 months ago (5 children)

Looking at the examples, you’ve just made a brand new GitHub Actions framework. There’s YAML to wrap everything together and a bunch of Python that’s so declarative it might as well be HCL. Do you have an example that’s a bit more than “do what YAML does only in bash?”

[–] thesmokingman@programming.dev 12 points 2 months ago

While they can’t buy a pardon, they can buy “asylum.” Until they’re out of the US there’s no guarantee Trump won’t break yet another legal system to do whatever the fuck he wants. Interpol is, after all, not his idea so he has little reason to respect it.

[–] thesmokingman@programming.dev -1 points 2 months ago

You took this from Reddit’s r/interestingasfuck and posted it to c/mildlyinteresting? Clearly neither is a good fit because this isn’t interesting at all.

[–] thesmokingman@programming.dev 4 points 2 months ago

The Litter Robots I’m aware of rotate with the door at the pole, meaning the cat can always jump out. If the cat jumps in when the globe is dumping into the waste drawer, the globe does not rotate with enough force to seriously injure the cat. If you’re genuinely worried, stick your arm in and try to force it so you can get a sense of the absolute worst case scenario.

I think there are plenty of things to not be thrilled with Litter Robot about. I don’t feel this is one of them.

[–] thesmokingman@programming.dev 3 points 3 months ago* (last edited 3 months ago)

Your second check is exactly why someone would check if it’s AI-generated.

I check whether it is safe to install. Are there security or privacy concerns?

Let’s review some basic security: the CIA triad stands for Confidentiality, Integrity, and Availability. Confidentiality is never a guarantee with AI-generated systems because the developers are usually spending even less time thinking about the code than normal since AI does the thinking. Plus AI systems are getting owned left and right (litellm anyone?). Integrity is never a guarantee because the developers don’t understand the system the AI slopped together and AI is only good at unit tests in some cases, not integration or end-to-end. That requires a system perspective. Finally, availability is usually worse with AI slop because AI is trained on really bad software that is rarely optimized. That requires vertical scaling out of the box.

Looking at this codebase, the integration cover hits three services and not totally at that. There are no security tests. There are no published security findings. There are no security standards in the contribution guidelines. While there is a disclosure process, there are no automated baseline tests available.

So why exactly did you move beyond your second check? This project has no security. Remember, that’s your guideline even before constructive criticism.

Edit: I just realized you’re the maintainer and you’re yelling at someone for asking about AI stuff when you can’t be bothered to do basic security. Worse yet, you’ve attempted to hide your slop instead of making users aware of the extra security issues. You have to understand I wouldn’t have commented on this if you hadn’t included a basic check you went out of your way to screw up. Glass houses and all that.

[–] thesmokingman@programming.dev 1 points 3 months ago

I don’t think you’re using straw man correctly.

You’re naively referring to how consensus should work while completely ignoring both the well-defined attacks I referenced and the reality of large actors in a consensus network. You don’t know what you’re talking about or you don’t understand how the theory works or you’re possibly just being obtuse. No matter what, this is pointless. Good luck.

[–] thesmokingman@programming.dev 1 points 3 months ago

If login tokens are stored on a public ledger replay attacks write themselves. Public or private, keeping every login token ever is a horrible audit mechanism and doesn’t scale well. At scale, speed to generate becomes a concern. Not at scale, something lighter is faster.

A normal database scales better than a license blockchain and doesn’t require extra computation to write. Audit logs and hashes prevent extra edits. License files signed by a central authority don’t require a database and the central authority is functionally equivalent albeit less expensive than a blockchain.

I am still interested in a good use for the tech. I have yet to see one that is genuine.

[–] thesmokingman@programming.dev 0 points 3 months ago (2 children)

If any of it is rewritable, none of it is immutable. You can’t have it both ways.

27
Universes Beyond is now MTG (magic.wizards.com)
submitted 2 years ago* (last edited 2 years ago) by thesmokingman@programming.dev to c/mtg@mtgzone.com
 
view more: next ›