Readit News logoReadit News
CaptainOfCoit commented on Microsoft 365 Copilot – Arbitrary Data Exfiltration via Mermaid Diagrams   adamlogue.com/microsoft-3... · Posted by u/gnabgib
driverdan · 3 months ago
This is MS telling anyone who finds an M365 Copilot exploit to sell it instead of reporting it. Incredibly short sighted and foolish.
CaptainOfCoit · 3 months ago
The very same company that for at least two decades and two CEOs have been saying "Security is now our top security".
CaptainOfCoit commented on YouTube Just Ate TV. It's Only Getting Started   hollywoodreporter.com/bus... · Posted by u/wallflower
justinclift · 3 months ago
> let people watch the entire show

Isn't that only for people in the US?

CaptainOfCoit · 3 months ago
I lived in three different countries in my life, and neither of them have been the US, but all of them have apparently had free South Park episodes available to them :)

I don't know if that website works/shows full episodes in the US, currently I'm in a EU country and everything except the last two seasons seems available.

CaptainOfCoit commented on We saved $500k per year by rolling our own "S3"   engineering.nanit.com/how... · Posted by u/mpweiher
none2585 · 3 months ago
I'm curious how many engineers per year this costs to maintain
CaptainOfCoit · 3 months ago
> I'm curious how many engineers per year this costs to maintain

The end of the article has this:

> Consider custom infrastructure when you have both: sufficient scale for meaningful cost savings, and specific constraints that enable a simple solution. The engineering effort to build and maintain your system must be less than the infrastructure costs it eliminates. In our case, specific requirements (ephemeral storage, loss tolerance, S3 fallback) let us build something simple enough that maintenance costs stay low. Without both factors, stick with managed services.

Seems they were well aware of the tradeoffs.

CaptainOfCoit commented on Nvidia DGX Spark: When benchmark numbers meet production reality   publish.obsidian.md/aixpl... · Posted by u/RyeCatcher
eitally · 4 months ago
One of my colleagues wrote a first impressions blog post last week. It's from our company's perspective, but is a solid overview of the product and intended capabilities, from the POV of an AI developer or data scientist.

https://www.anaconda.com/blog/python-nvidia-dgx-spark-first-...

CaptainOfCoit · 3 months ago
> There you’ll see the 10 Cortex-X925 (“performance”) cores listed with a peak clock rate of 4 GHz, along with the 10 Cortex-A725 (“efficiency”) cores listed with a peak clock rate of 2.8 GHz

> If you start Python and ask it how many CPU cores you have, it will count both kinds of cores and report 20

> Note that because of the speed difference between the cores, you will want to ensure there is some form of dynamic scheduling in your application that can load balance between the different core types.

Sounds like a new type of hell where I now not only need to manage the threads themselves, but also take into account what type of core they run on, and Python straight up report them as the same.

CaptainOfCoit commented on Microsoft 365 Copilot – Arbitrary Data Exfiltration via Mermaid Diagrams   adamlogue.com/microsoft-3... · Posted by u/gnabgib
binarymax · 3 months ago
> MSRC bounty team determined that M365 Copilot was out-of-scope for bounty and therefore not eligible for a reward.

What a shame. There’s probably LOTS of vulns in copilot. This just discourages researchers and responsible disclosure, likely leaving copilot very insecure in the long run.

CaptainOfCoit · 3 months ago
> There’s probably LOTS of vulns in copilot

Probably exactly why they "determined" it to be out of scope :)

CaptainOfCoit commented on Nvidia DGX Spark: When benchmark numbers meet production reality   publish.obsidian.md/aixpl... · Posted by u/RyeCatcher
veber-alex · 4 months ago
The llama.cpp issues are strange.

There are official benchmarks of the Spark running multiple models just fine on llama.cpp

https://github.com/ggml-org/llama.cpp/discussions/16578

CaptainOfCoit · 4 months ago
There wasn't any instructions how the author got ollama/llama.cpp, could possibly be something nvidia shipped with the DGX Spark and is an old version?
CaptainOfCoit commented on A bug that taught me more about PyTorch than years of using it   elanapearl.github.io/blog... · Posted by u/bblcla
hinkley · 4 months ago
Reminds me of the largest AJAX app I worked on, back when jquery was still hot and IE6 still existed as a problem.

The landing page in our app used jqueryUI’s drag and drop support, back around the time they declared bankruptcy on the confusing buggy code and wouldn’t even accept bug fixes because they were replacing it component by component (which was taking almost 3x as long as predicted). We had columns you could drag items between but they had a max height and scroll bars and it turned out jqueryUI would let you drag items into different rows if the overflow area for adjacent drag targets overlapped your row.

The person who found it couldn’t fix it. The other fixer couldn’t fix it. I diagnosed it but the spaghetti code was a recursive mess and I could not find a spot where I could fix it. Especially given I couldn’t send in a patch to them.

So I spent half of my free time the last day of every (2 week) sprint for almost six months before I finally found a small function I could monkey patch to wrap it in a short circuit check for clipping region. I spent maybe 20,30 hours on this, a lot of it just getting back to the same situation to debug. But it felt like it took forever to fix it.

The short circuit also made drag and drop faster, which was just getting in the edge of distracting. Particularly on a crowded page.

CaptainOfCoit · 4 months ago
I remember many similar cycles of having different browsers open side-by-side, and trying to pinpoint (without the developer tools we know and love today) the exact reason why one border was one pixel in one browser, and two pixels in the other, throwing the whole layout off.

Also remembering when Firebug for Firefox appeared, and made so many things so much easier. Suddenly things that took hours took days, and it was so much easier when you had some introspection tools.

CaptainOfCoit commented on A definition of AGI   arxiv.org/abs/2510.18212... · Posted by u/pegasus
CaptainOfCoit · 4 months ago
> defining AGI as matching the cognitive versatility and proficiency of a well-educated adult

Seems most of the people one would encounter out in the world might not posses AGI, how are we supposed to be able to train our electrified rocks to have AGI if this is the case?

If no one has created a online quiz called "Are you smarter than AGI?" yet based on the proposed "ten core cognitive domains", I'd be disappointed.

CaptainOfCoit commented on YouTube Just Ate TV. It's Only Getting Started   hollywoodreporter.com/bus... · Posted by u/wallflower
ssl-3 · 4 months ago
Why so much?

Plex is a pretty light-weight system as long as transcoding is avoided or it has hardware transcoding available to use.

And wrangling Usenet is a fairly simple affair on vaguely modern PC hardware, too.

So all of that stuff runs in the background on the same desktop Linux box that I also use for everything else.

Am I doing it wrong?

CaptainOfCoit · 4 months ago
People use separate computers for wide range of reasons. My desktop isn't always running Linux for example, or even from the same partition always, and to run something 24/7 I need to host it not on my for-work desktop. I also run some less trusted software on separate server and network than say Home Assistant and Frigate.
CaptainOfCoit commented on YouTube Just Ate TV. It's Only Getting Started   hollywoodreporter.com/bus... · Posted by u/wallflower
benbristow · 4 months ago
... so we end up in the same predicament we are now. Maybe the model doesn't work? And no, I'm not a communist.
CaptainOfCoit · 4 months ago
I think it's broken, yeah. I think the whole "art for money" thing doesn't make sense in general and something else has to be figured out. Artists should be able to survive without depending on things like "perfectly competitive goods" or whatever.

u/CaptainOfCoit

KarmaCake day2067December 19, 2023
About
Modder at night, plain hacker during the day.
View Original