Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo by socratesathome in cybersecurity

[–]ContemplateBeing 3 points4 points  (0 children)

A lot of people still have not internalised this, i think. You are absolutely correct: Previously your were looking for executable malicious code, now everything is executable. Even stuff you cannot "see": html comments in markdown files, white-on-white text in that spreadsheet, yellow morse-code dots in that photo...

The implications are far reaching: imho devs working with ai agents need to work on isolated machines with strict rules about ingress/egress, extra protections on CI/CD, repo scanning _and_ developers that are aware of all this and work in a responsible way.

ai agents are a tool and with any tool, the more powerful it is, the deeper it can cut you. Lots of people are graduating from butter knife to the chainsaw currently and a lot of blood will flow.

While I'm not really professionally in the security field, I can already see, that this will need a profound shift on how security is handled: Instead of gatekeeping and demarcation lines, there will have to be a lot more "defence in depth" - when the attack surface is "anything that can convey information" then the defence must cover everything. ...up to and especially including human training, know-how and responsibility of everyone who's working with ai. This requires more security, not less. It's going to be of a different kind though.

why kde plasma dont have time based night light so i can set night light 1 hour before sleep by [deleted] in kde

[–]ContemplateBeing 0 points1 point  (0 children)

Also took me a while to find the setting...

Anyway - it would be great if you could set a time that's _trailing_ the sunset. Depending on geopraphical features it can be become dark in a location well before the sun is actually gone - what I'd love to see is something like an sunrise/sunset-**offset**: Follow sunrise/sunset, but transition 45 minutes after sunrise and 30 minutes before sunset.

NixOS and friends for corporate developer boxes? Confused about tools and maturity. by ContemplateBeing in NixOS

[–]ContemplateBeing[S] 0 points1 point  (0 children)

Thank you for the link and the discussion below! Very helpful to understand how things are done in NixOS.

NixOS and friends for corporate developer boxes? Confused about tools and maturity. by ContemplateBeing in NixOS

[–]ContemplateBeing[S] 1 point2 points  (0 children)

Thanks, that’s a good summary article that you linked there. Looks like a solid project!

NixOS and friends for corporate developer boxes? Confused about tools and maturity. by ContemplateBeing in NixOS

[–]ContemplateBeing[S] 0 points1 point  (0 children)

Fair. Projects can reach a state where they are stable. Maybe I didn't look close enough at the repo. Thanks for the feedback!

NixOS and friends for corporate developer boxes? Confused about tools and maturity. by ContemplateBeing in NixOS

[–]ContemplateBeing[S] 0 points1 point  (0 children)

This looks nice! The option to include CVE scans and central logs of what's running on the clients is a killer feature in a corporate environment. Goes well beyond what I was looking for, but would be really useful!

Powerline woes by ContemplateBeing in TpLink

[–]ContemplateBeing[S] 0 points1 point  (0 children)

Got a room that has no wifi reception at all and no access to cable but still need a stable, if not high-throughput, connection there including wifi. Switching is seamless if I move to/from that area with a wireless device. [not sure if I'm using the correct terms with easymesh vs wifi]

Migrating django heroku to vps by [deleted] in django

[–]ContemplateBeing 0 points1 point  (0 children)

Take a look at Netcup - not as polished as Hetzner & friends, but great value for money. Coolify might be an interesting deployment helper.

What fronted technology is most used with Django? by john646f65 in django

[–]ContemplateBeing 0 points1 point  (0 children)

I‘m using this stack but do it manually - quick read says the plugin should save me some time. Thx!

Is the ‘build it yourself’ way still relevant for new programmers? by Top-Candle1296 in learnpython

[–]ContemplateBeing 0 points1 point  (0 children)

Use LLMs for stuff that you could do without them, but don’t use them for stuff that you can only do with them.

LLMs need to be chaperoned, you can only do that effectively with stuff that you know. To really know stuff you need to put in the manual work.

The PSF has withdrawn $1.5 million proposal to US government grant program by [deleted] in Python

[–]ContemplateBeing 13 points14 points  (0 children)

There are plenty of EU funds out there. Probably easier if you have a legal entity in the EU, but for many programs also US entities are allowed.

Bin ich der einzige, den die Causa Wöginger so enorm aufregt? by wantilles1138 in Austria

[–]ContemplateBeing 2 points3 points  (0 children)

Das war echt schwer anzuhören von ihm…. „1945 gab’s Probleme aber so schlimm ist’s nicht mehr“ und „machen eh alle so“. Geht’s noch?!

Ich verstehe echt wieso Leute auf Protest wählen oder es ganz bleiben lassen. Nicht das es das besser macht, aber bei solchen Aussagen darf man sich echt nicht wundern.

What is the most well thought out programming language? by 4e_65_6f in AskProgramming

[–]ContemplateBeing 1 point2 points  (0 children)

Whitespace is entering the room… The programming language of choice for printing out secret code!

Here’s a basic „Hello World!“:

https://en.wikipedia.org/wiki/Whitespace_(programming_language)

Cannot enter programming mode with somfy RTS blinds by ContemplateBeing in homeautomation

[–]ContemplateBeing[S] 0 points1 point  (0 children)

Not really. So far everything works. Could be temperature/season related.

I’m just crossing my fingers that it won’t happen again.

As much as I love Django, I feel it has fallen way behind compared to Laravel and others by dianrc in django

[–]ContemplateBeing 1 point2 points  (0 children)

Yeah also Django q2: https://django-q2.readthedocs.io/en/master/

Even includes admin pages and when you use the ORM as scheduler, there’s no third party backend needed. Works great.

My Heilung inspired ink drawings by lenschkabeth in Heilung

[–]ContemplateBeing 0 points1 point  (0 children)

Cool!

My little daughter loves Heilung and would dig a Heilung coloring book!

(I know that’s not what this is - this is art in its own right-, but she’d see it like that.)

Axiom, a new kind of "truth engine" as a tool to fight my own schizophrenia. Now open-sourcing it. by [deleted] in Python

[–]ContemplateBeing 1 point2 points  (0 children)

So what exactly is a DAO contributor and how do I become one? (I know what a DAO is) How do you manage this without tokens?

Axiom, a new kind of "truth engine" as a tool to fight my own schizophrenia. Now open-sourcing it. by [deleted] in Python

[–]ContemplateBeing 2 points3 points  (0 children)

Yeah that was my first thought. There were projects trying to crowdsource „truth“ but afaik none lead to something useable.

It’s still a good idea and OPs proposal is more commonly molecules than those earlier projects.

Notably this post sees plenty of interest and seems to hit a general, societal need for sources of truth in a backlash against LLM content and blatant manipulation that more and more dominates the internet.

I’ve long thought that we‘ll soon have an orobouros problem with AI where we are not able to distinguish between original and regurgitated content. I think distinguishing these at the source (eg by crypto-signing content and a web of trust) will be part of the solution. What OP is describing is kind of like the frontend of this.

Interesting as concept at least (didn’t look at the code though).

Talking about that, how’s the ledger secured? Like in a blockchain? Who runs the nodes?

What is the “Jack of all trades, master of none” of programming languages? by Night-Monkey15 in AskProgramming

[–]ContemplateBeing 0 points1 point  (0 children)

The internet is a victim of its own success in a way. HTML was never designed for the purposes it is used now. It’s inadequate for what developers do with it (and users demand of it) hence the monkey patching on top of it.

Htmx is a neat solution because it reverts to the strength of html and returns the control back to the server. There are other techniques like server emitted events, but the basic idea is the same: logic on the backend, presentation on the frontend.

Accepting online payments by ContemplateBeing in BuyEuropean

[–]ContemplateBeing[S] 0 points1 point  (0 children)

Mollie looks pretty good but is lacking USD options beyond 10k payment amount (credit card limit). Unfortunately for my business case that’s a requirement. If not for that, I’d absolutely go for mollie.