Readit News logoReadit News
rs999gti commented on Ireland is making basic income for artists program permanent   artnews.com/art-news/news... · Posted by u/rbanffy
rs999gti · 2 months ago
Does the public have claim on all of these artists' art?

They all are now involuntary patreons.

rs999gti commented on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised   socket.dev/blog/ongoing-s... · Posted by u/jamesberthoty
reactordev · 3 months ago
Until you go get malware

Supply chain attacks happen at every layer where there is package management or a vector onto the machine or into the code.

What NPM should do if they really give a shit is start requiring 2FA to publish. Require a scan prior to publish. Sign the package with hard keys and signature. Verify all packages installed match signatures. Semver matching isn’t enough. CRC checks aren’t enough. This has to be baked into packages and package management.

rs999gti · 3 months ago
> What NPM should do if they really give a shit is start requiring 2FA to publish.

How does 2FA prevent malware? Anyone can get a phone number to receive a text or add an authenticator to their phone.

I would argue a subscrption model for 1 EUR/month would be better. The money received could pay for certification of packages and the credit card on file can leverage the security of the payments system.

rs999gti commented on Generative AI as Seniority-Biased Technological Change   papers.ssrn.com/sol3/pape... · Posted by u/zeuch
FrustratedMonky · 3 months ago
In 10 years where do the senior dev's come from? Real question. Seems like with lower entry level jobs now, in 10 years there won't be seniors to hire.
rs999gti · 3 months ago
> In 10 years where do the senior dev's come from?

From company interns. Internships won't go away, there will just be less of them. For example, some companies will turn down interns because they do not have the time to train them due to project load.

With AI, now employed developers can be picky on whether or not to take on interns.

rs999gti commented on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised   socket.dev/blog/ongoing-s... · Posted by u/jamesberthoty
codemonkey-zeta · 3 months ago
I'm coming to the unfortunate realizattion that supply chain attacks like this are simply baked into the modern JavaScript ecosystem. Vendoring can mitigate your immediate exposure, but does not solve this problem.

These attacks may just be the final push I needed to take server rendering (without js) more seriously. The HTMX folks convinced me that I can get REALLY far without any JavaScript, and my apps will probably be faster and less janky anyway.

rs999gti · 3 months ago
> supply chain attacks

You all really need to stop using this term when it comes to OSS. Supply chain implies a relationship, none of these companies or developers have a relationship with the creators other than including their packages.

Call it something like "free code attacks" or "hobbyist code attacks."

rs999gti commented on I'm an award winning mathematician. Trump just cut my funding   newsletter.ofthebrave.org... · Posted by u/dargscisyhp
rs999gti · 4 months ago
UCLA, where Tao works, has a 10B USD endowment. He will do just fine.
rs999gti commented on Staying cool without refrigerants: Next-generation Peltier cooling   news.samsung.com/global/i... · Posted by u/simonebrunozzi
zevv · 5 months ago
Could you summarize the contents of this video so we don't have to watch it?
rs999gti · 5 months ago
> Could you summarize the contents of this video so we don't have to watch it?

Thermoelectric cooling is not very good and takes a lot of energy to do.

rs999gti commented on Corporation for Public Broadcasting Statement Regarding Executive Order   cpb.org/pressroom/Corpora... · Posted by u/coloneltcb
agloe_dreams · 7 months ago
Heh...it is so much worse than that.

Trump has no idea what he is doing, it has been very clear in interviews.

In the first admin, it was the adults in the room, the thing is, it's not yes men this time...it's the villians in the room. Trump is being handed EOs that he doesn't have a clue about.

For all the talk about P2025 and denial of any relation to it, they have done roughly 50% of the actions in the project already with more on the way. ~2/3rds of all his EOs have been in the plan. Virtually everyone related to the project is now in the admin - the head of the FCC literally wrote the 'FCC' section and boy is it an attack on everything the EFF holds dear.

I think what is notable is that it seems to have gotten more bold - the plan called for reducing USAID, not killing it for example.

And Yes, page 246, killing funding for PBS.

rs999gti · 7 months ago
> Trump is being handed EOs that he doesn't have a clue about.

Probably like every president before him.

No president like CEOs can know everything about the organization they head. They are mostly the face and mouthpiece, and depend on chiefs and VPs to tell them what needs to be done according to the agenda that CEO or president has put forth.

rs999gti commented on Corporation for Public Broadcasting Statement Regarding Executive Order   cpb.org/pressroom/Corpora... · Posted by u/coloneltcb
bhouston · 7 months ago
The US is so weird right now.

You have a President who is ordering the defunding of tons of groups (universities, media, aid, institutes) while not clearly having that authority and often doing so for what he views as ideological crimes.

Also arresting and trying to deport people for things that are not clearly crimes (newspaper op-eds, etc) and without due process.

Very strange times.

Right now I have some faith the courts in the US will stand up to this and get the US back on track but I worry that dam may not hold forever.

Saving grace is that his is not widely popular, although that is more for his tariff moves than for the others.

rs999gti · 7 months ago
> You have a President who is ordering the defunding of tons of groups (universities, media, aid, institutes) while not clearly having that authority

You have to read into this line from the article:

> Congress directly authorized and funded CPB

He may not have the authority, but his influence over certain congress people and CPB board members can get the process moving.

Also, I have always wondered why CPB cannot just cut federal ties and become a sponsored non-profit?

During all shows you always hear or see that they are sponsored or have grants from major Fortune 500s, private families, and other institutions.

Also, whenever this defund topic comes up, CPB always says, "we receive very little from the fed, so our funding is not much and can be ignored." Well now is the time to put up and split from the US federal government officially.

https://www.propublica.org/article/big-bird-debate-how-much-...

rs999gti commented on Redis is open source again   antirez.com/news/151... · Posted by u/antirez
giancarlostoro · 7 months ago
Microsoft made one called Garnet, I wouldn't say its a fork though, its basically compatible with Redis and implemented mostly in C#. It supports the RESP wire protocol from Redis for ease of compatibility.

https://github.com/microsoft/garnet

rs999gti · 7 months ago
Wow. First time hearing about Garnet. MS should package and deploy it as a service in the Azure SAAS offerings.
rs999gti commented on All four major web browsers are about to lose 80% of their funding   danfabulich.medium.com/al... · Posted by u/dfabulich
rolandog · 7 months ago
I think we're at an awkward place where governments worldwide have been slow to understand the importance of the global infrastructure that has sprouted, largely due to open source software...

Given that browsers are essential to access information, I think they shouldn't be developed behind a business model, but rather as part of a global digital infrastructure fund.

There should be some independence guarantees in order to make that organization not have to bow to pressure from governments to sacrifice privacy due to funding threats.

rs999gti · 7 months ago
> but rather as part of a global digital infrastructure fund

Sounds like a backdoor way to add a kill switch or censor filter to browsers from a central, unelected authority that does not respect the sovereignty and speech and media laws of the individual users' home countries.

No thanks, I'll take an open source, corporate controlled browser 10/10 times.

u/rs999gti

KarmaCake day635April 15, 2015View Original