Forgot your password?
typodupeerror

Comment Re: Nothing of value was added (Score 0) 145

This is only really a useful observation if you can tell me ahead of time which developers are competent and which ones are incompetent.

If you are hiring a developer your chances of finding one who is not incompetent is vanishingly small. The correct approach is to train them to be competent, and set standards. This should begin with requiring the bug tracker to be emptied out (or decreasing bug count, if the total number is currently overwhelmingly large), and there are plenty of online and in-person resources for training developers to learn how to write secure code.

and use tools like memory-safe languages to mitigate that risk.

Security vulnerabilities happen in every language. Anyone who thinks the language will make them safe is an idiot. What I mean is, you are an idiot, cmseagle 1195671.

Comment Re: Nothing of value was added (Score 4, Insightful) 145

The problem as I see it is coming up with good standards. We do have standards in some places, for example, SOX requires changing passwords every three months as best practices. But that is probably not actually best practice, so the wrong thing was codified.

How do we get the right things codified is the question.

Comment Re: We are going so fast we need to slow down! (Score 1) 118

** - It seems dubious that Truman really understood what he was signing onto.

My take was that he could have stopped it if he wanted to, but the bureaucratic machine was already in motion, and he would have had to put some effort into stopping it. I'm glad we didn't bomb Kyoto but maybe Xi will.

Comment Re: Nothing of value was added (Score 4, Insightful) 145

Yes of course when there is a skill and no standards of training, some people are bad at it

This. Most companies don't follow best practices when it comes to good code (for example, they have a bug tracker that is always growing, never empty). They don't try to write secure code, they don't have trainings in secure code, they don't penalize insecure code (although they should in a lot of cases). That is why most corporate programmers can't write secure code.

Comment Re: Nothing of value was added (Score 2, Insightful) 145

History shows that developers cannot write safe code

History shows that incompetent developers cannot write safe code. There are examples of programmers writing safe code.

People who make excuses for unsafe code are usually crappy developers, and that is what I think of you. You're a crappy developer if you can code at all.

Comment Re: Nothing of value was added (Score 3, Insightful) 145

I think Ubuntu (and other's desire) to remove coreutils is precisely because coreutils is old, brittle and written in an unsafe language.

They aren't brittle. I've looked at them. The code is fine, but it uses an older style that is annoying to newbies.

If I were going to rewrite something in Rust, I would look at Firefox, not Coreutils which I would consider a waste of time.

Comment Re:You're shitting me! (Score 4, Informative) 164

Nazi are still the bad guys. They're only "evergreen" because we failed to get rid of all of them. Damn things are like roaches.

Well, they were. They don't scatter when you shine a light on them anymore. On the plus side, that should make them easier to eradicate next time we get the chance.

Comment Re:Makes me wonder (Score 1) 123

Obviously, I agree.

My other question, is how long will they be able to get away with this sort of thing, before customers decide the risk of disclosing your data to these external AI firms, is greater than the cost of building the capacity to run your own models in-house.

I don't use LLM, generally. But I was messing around and got some older models running on my laptop last night. Nothing special, no idea what I would use them for (couldn't generate a paragraph of text before clearing losing all coherence, because these were small old models running on 5 year old hardware). Supposedly Mac Studios and Mac minis are selling like hotcakes because hobbyists want to run local models. How long before the Venn Diagram for "can be run locally" and "capable enough model" overlaps for most use cases, making the risk of data exfiltration by these firms not worth the risk?

Lot of words to say this kind of thing may accelerate the bubble bursting.

Slashdot Top Deals

"Look! There! Evil!.. pure and simple, total evil from the Eighth Dimension!" -- Buckaroo Banzai

Working...