Readit News logoReadit News
bfelbo commented on RCE Vulnerability in React and Next.js   github.com/vercel/next.js... · Posted by u/rayhaanj
vanwal_j · 2 months ago
Does this include any provider that does not fall under USA CLOUD Act? This vulnerability disclosure timeline is a nightmare for us Europeans, it was fully disclosed yesterday late afternoon for us and I can trace back attack logs that happend during the night. I expect some downfalls from this.

I genuinely believe Next.JS is a great framework, but as an European developer working on software that should not touch anything related to CLOUD Act you're just telling me that Next.JS and React, despite being OSS, is not made for me anymore.

bfelbo · 2 months ago
It’s infuriating how US-centric some OSS maintainers can be. Really sad if the OOS ecosystem also have to fragment into pieces like much of the internet is starting to.
bfelbo commented on Olmo 3: Charting a path through the model flow to lead open-source AI   allenai.org/blog/olmo3... · Posted by u/mseri
bfelbo · 3 months ago
Great with a truly open model! How much would it cost to train the different versions?
bfelbo commented on A Postmark backdoor that’s downloading emails   koi.security/blog/postmar... · Posted by u/ghuntley
AznHisoka · 5 months ago
Good thing i dont even wanna use any 3rd party libraries when using stuff like Postmark. Just old fashioned curl and POST requests to send emails with Postmark.

And i consider myself a lazy person. Using 3rd party libraries are just more of a headache and time sink sometimes

bfelbo · 5 months ago
Yeah, this was the case before MCPs as well. Especially with some of the really bloated SDKs (looking at you Firebase and Twilio).
bfelbo commented on Slack has raised our charges by $195k per year   mahadk.com/posts/slack... · Posted by u/JustSkyfall
v3ss0n · 5 months ago
Zulip is much better alternative due it it's threaded nature and it have nice slack import tool. Please give a try.
bfelbo · 5 months ago
Would love to use Zulip, but the bad mobile app reviews are scaring me off.
bfelbo commented on Grok 4 Launch [video]   twitter.com/xai/status/19... · Posted by u/meetpateltech
stormfather · 7 months ago
I find for auto turn detection, models work better if you put in the system prompt "if it seems the user hasnt completed their thought yet, output silence". This hack works around their compulsive need to output something.
bfelbo · 7 months ago
Great hack, thanks for sharing! Any other hacks like this you’ve found useful to improve voice AI?
bfelbo commented on Apple needs a Snow Sequoia   reviews.ofb.biz/safari/ar... · Posted by u/trbutler
joaomoreno · 10 months ago
With the hopes that Apple engineers are scanning this discussion:

- Using the iPhone to scan documents from Finder has recently stopped working on the second scan. I need to restart my phone to get it to work again.

- iPhone mirroring is terrible: laggy, UI glitches, drops click events, scrolling is a nightmare. This is when it actually even manages to connect.

- Often, with Airpods on, lowering the volume, shutting down the iPhone display and putting it in my pocket quickly enough will entirely turn off volume. If you happen to increase the volume instead, you'll get blasted with maximum volume in your ears.

- Use vertical tabs on Safari for one day. You'll see it actually crash a few times. Not to mention the UI glitches. - Open the App Store on macOS. It first opens empty, then the UI controls show up, then it flickers the entire UI. I am convinced it's a Web app.

- In System Settings, most of the sections you click have a delay in rendering. Nothing feels snappy in that app. I can actually click 3 sections quick enough for the second to never even be rendered.

- Sometimes dragging an application from the Dock popup menu into the Trash does nothing, even though it appears to have worked. I often find that it wasn't deleted at all, that I have to open Applications folder in Finder and hit Cmd-Backspace to delete it.

bfelbo · 10 months ago
Good idea. I’ll add some that have annoyed me for years just in case:

- On iOS, the alarms app breaks down once you get to ~250 alarms. You can try to add/delete alarms and it’ll appear like they changed, but the change wont be saved. I can’t use the alarms app now and can’t fix it as I can’t delete alarms. By the way, would be nice to reuse alarms when creating at the same time as an existing alarm so you don’t end up with 250+ alarms in the first place.

- On iOS, the notes app breaks down in long documents (~10 pages of text with bullet points). When writing beyond that, some text will sometimes disappear only to reappear when you type some more. Other times, the cursor disappears. This only happens in long documents. All English text, mainly bullet points, often with some text pasted in.

It’s shocking to me that my iPhone 11 Pro can play gorgeous 3D video games, but can’t handle 250 alarms or 10 pages of text..

bfelbo commented on Cursor uploads local credential files   forum.cursor.com/t/block-... · Posted by u/bfelbo
bfelbo · a year ago
Cursor uploads files like credentials.json, .env, and .git-credentials to their servers for their Cursor Tab model. They do this despite those files being clearly credential secrets and even if these files are listed in .gitignore. See the link for a forum post with repro and details by a Cursor user.

You can use a .cursorignore file to prevent the upload, but you need to have that file present before you open the project in Cursor. You also need to update your .cursorignore file before saving any new credential files into your directory to prevent Cursor from uploading them.

Cursor users might feel safe when they have privacy mode enabled, but IMO that feels like false safety. The Cursor team have responded to the forum post describing the security issue saying that privacy mode only means that the sent files aren't stored in plaintext. They don't say anything about not training on uploaded files.

I have no affiliation with Cursor or any other AI IDE company. Sharing as I use Cursor myself and was shocked to see it autocomplete my own secrets and that it uploads such sensitive files.

u/bfelbo

KarmaCake day178March 14, 2018View Original