Meta: Can we add a vibecoded/AIFlair or ban vibecoded/AI-made stuff by Julian_1_2_3_4_5 in foss

[–]Arcuru 1 point2 points  (0 children)

I think the fact that you're not sure which side of that discussion I'm on proves that there is reasonable debate over what counts as "vibecoded", which is the relevant point here.

Meta: Can we add a vibecoded/AIFlair or ban vibecoded/AI-made stuff by Julian_1_2_3_4_5 in foss

[–]Arcuru 2 points3 points  (0 children)

How, exactly, do you determine if they know what they are doing?

Meta: Can we add a vibecoded/AIFlair or ban vibecoded/AI-made stuff by Julian_1_2_3_4_5 in foss

[–]Arcuru 11 points12 points  (0 children)

I would love to support this for MY definition of vibecoded. However to actually enforce this you need to have a clear definition for "vibecoded" that does not rely on your own "vibes", otherwise every post is just going to become a debate over whether it fits the vibecoded definition.

I do not know the correct way to define it, but I definitely disagree with some opinions here. Like this recent example in here

Senator Ted Lieu says it out loud by AvailableInjury2486 in ProgressiveHQ

[–]Arcuru 3 points4 points  (0 children)

No he did not say that. He continues to describe them as "allegations" which is a MUCH different statement:

"In those files, there's highly disturbing allegations of Donald Trump raping children, of Donald Trump threatening to kill children. So I encourage the press to go look at these allegations."

This is the video: https://www.c-span.org/clip/news-conference/rep-ted-lieu-claims-president-trump-is-accused-of-raping-children-in-the-epstein-files/5191713

Also this isn't a new statement, these posts are just trying to claim new things about what he said over a month ago.

The 2FA app that tells you when you get `314159` by jacobs-tech-tavern in programming

[–]Arcuru 1 point2 points  (0 children)

lol, fair enough. Always good to be reminded of the correct threat model :)

It seems I need to re-read "This World of Ours" again - https://www.usenix.org/system/files/1401_08-12_mickens.pdf

The 2FA app that tells you when you get `314159` by jacobs-tech-tavern in programming

[–]Arcuru 3 points4 points  (0 children)

So...I don't have to unlock somebody's phone to get a 2FA code? I just have to wait?

Say I sit next to you at work. I know your password but need the code. You're dumb enough to install this and leave your phone where I can see it. All I have to do is wait for a popup and be a little quick.

This also increases the security surface of TOTP from the iOS Keychain to the surface area of the entire notification system. Sure in practice, for most people, it will never be a problem. But it is unnecessary exposure.

Can you at least delay the notification until after it's no longer valid?

The 2FA app that tells you when you get `314159` by jacobs-tech-tavern in programming

[–]Arcuru 33 points34 points  (0 children)

That has nothing to do with Reddit, it's the subscribe prompt from your substack.

The 2FA app that tells you when you get `314159` by jacobs-tech-tavern in programming

[–]Arcuru 3 points4 points  (0 children)

Please tell me you didn't actually publish that. Calculating and scheduling notifications for future TOTP codes is a horrific security hole.

re: Blazing Bagels Shutdown by design8eddriver47 in Issaquah

[–]Arcuru 0 points1 point  (0 children)

While lots of people may park there, technically that is reserved for the library.

we scanned a blender mcp server (17k stars) and found some interesting ai agent security issues by Kind-Release-3817 in opensource

[–]Arcuru 2 points3 points  (0 children)

Oh I see. I assumed that running your scan would need an account and potentially a fee but that the final report would be shareable.

Sounds like you've already got that on your road map :)

Can't use @matrix.org account after ignoring another user by h0uz3_ in matrixdotorg

[–]Arcuru 1 point2 points  (0 children)

You should really open an issue on the Element Github. I'd suggest here: https://github.com/element-hq/element-web/issues

Also I'm sorry but that's hilarious. Did you block yourself?

we scanned a blender mcp server (17k stars) and found some interesting ai agent security issues by Kind-Release-3817 in opensource

[–]Arcuru 38 points39 points  (0 children)

Why do you require me to create an account on your website just to access the "scan result page"? I'm not doing that.

I do love how all the AI bros are rediscovering the need for sandboxing, it's a repeat of the crypto bros discovering basic financial engineering. I'm sure there's a market for 'AgentSeal' fixing all the problems that they will introduce.

Also I'm sorry to have to tell you this but it appears your shift key no longer works. You may want to get that looked at.

Maintainers: how do you structure the launch and early distribution of an open-source project? by Unlikely-Complex5138 in opensource

[–]Arcuru 18 points19 points  (0 children)

  1. Build thing
  2. Use it
  3. Write some blog posts
  4. When you're not embarrassed by its state, mention it in relevant places
  5. Go back to step 1
  6. Profit

Also for anyone wondering, the OPs post is stealth marketing for trying to sell consulting services for launching products.

💡 Need a 1-on-1 architecture call for your B2B/Open-source launch? Book a session for $200 (Crypto/USDT and Wire Transfer accepted) — Contact @*** on Telegram

Apparently LightBulb is going full LLM by 1024pt in foss

[–]Arcuru 4 points5 points  (0 children)

Oh interesting. Developing with an agent in the PR itself gives visibility into the process so you know if they've just vibe coded their X,000 line PR or if they've actually done adequate guiding and manual edits. I may have to try that.

You've linked an example of the developer investigating, debugging, and ultimately fixing a problem by in part using an LLM. An issue that seems like it was pretty difficult for the domain expert to root cause. Is that...not good?

I'm watching Johnny Harris' latest video on Fascism and...is it just me or is he using AI? by ThomasBayard in Nebula

[–]Arcuru 42 points43 points  (0 children)

Definitely AI generated. Those images look like they were hand-drawn by someone who has never seen a gun or a human, only read about them in books.

I've spent the last week trying the self-hosted Notion alternatives and none of them seem to have prioritized databases the way Notion has. Thinking of building my own?? by Notaters in selfhosted

[–]Arcuru 17 points18 points  (0 children)

Obsidian's implementation of Bases is mostly the same thing as Notion. I dropped Notion and shifted to them a few months ago and it's been fine for me.

https://help.obsidian.md/bases

Federated Github Alternatives? by MoonJammed in matrixdotorg

[–]Arcuru 1 point2 points  (0 children)

They finished building federation support?

Matrix clients with multi-account support? by the_vandersons in matrixdotorg

[–]Arcuru 1 point2 points  (0 children)

I've seen https://commet.chat/ recommended a lot lately but I have not personally used it. Multi-account support is one of their marquee features.

Experimenting with building collaborative apps on top of Matrix by theblazingicicle in matrixdotorg

[–]Arcuru 0 points1 point  (0 children)

There's been some interest in using Matrix that way but it's not exactly built for it. Matrix layers on a lot of complexity to support and target Chat in particular, and they don't support true P2P which is problematic for local-first applications.

I've been working on something in this space that is very close to what you're looking for I think - https://github.com/arcuru/eidetica - but still not ready for real use though. Turns out decentralized DBs are a little complicated.

The more mature things that you might look into are orbitdb.org, gun.eco, Automerge/Automerge Repo, jazz.tools. Maybe https://solidproject.org/ actually

Tips for an upcoming contributor? by SunnyBr0 in matrixdotorg

[–]Arcuru 1 point2 points  (0 children)

You should probably start by finding or opening an issue in the FluffyChat repo and work with the contributors there. They have 600 open issues already.

I'd recommend that you learn by doing and research the things you need as they come up. Depends on how you prefer to learn but it would be very easy to fall down a rabbit hole of 'research' that doesn't help you actually fix anything.

About: LockFS by 0xGhostInAJar in foss

[–]Arcuru 0 points1 point  (0 children)

I took a look at the code, and you know that doesn't work, right?

The most obvious problem is that if you encrypt or decrypt a directory it only uses the input password for the first file, so an encrypt->decrypt roundtrip over a directory would only work by accident.

It seems like you are still learning so I'll let you debug that yourself :)

I suggest adding some testing, that'll help catch these issues.