• 2 Posts
  • 149 Comments
Joined 3 years ago
cake
Cake day: August 4th, 2023

help-circle









  • Now, some tech job candidates have begun asking about what AI compute budget they will have access to if they decide to join. “I am increasingly asked during candidate interviews how much dedicated inference compute they will have to build with Codex,” Thibault Sottiaux, engineering lead at OpenAI’s Codex, the startup’s AI coding service, wrote on X recently.

    Big fucking bullshit. No one ever ask for “AI compute budget”, people wants money. Not your coffee, not your foosball game, money.

    Guess what you can buy with money? Yeah, that compute time, if desired.

    What a fucking load of bullshit.











  • PushButton@lemmy.worldtoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    4 months ago

    There are two reasons. One is the name spacing that is inherent in Maven and bolted on to npm, and the enforcement or lack of enforcement in the repository. You can read more about that here https://blog.sonatype.com/why-namespacing-matters-in-public-open-source-repositories Then there’s the fact that npm runs “install” scripts when you download the component. This means if you can trick someone into grabbing your component by namespace confusion, typosquatting a name etc, you can get code run as soon as someone makes a mistake. Maven on the other hand only downloads the jars, it does not execute them. Taken together, you have an easier path to tricking people to grabbing your component with npm and that trick leads directly to code execution.

    —Brian Fox, Apache Maven PM & Sonatype cofounder & CTO

    I am on my phone, which is a bit too long to explain, but there are multiple facets to how NPM is worse than most packaging systems out there. There are enough on the web for you to browse and learn, if you are really interested to know more.

    But, here, I quoted a little something from Brian from Sonatype.