Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:
-
@inex @soatok "Look, I only gave the user a foot-gun. Most users know how to not use the foot-gun. I mean yes, it is a gun; and yes, it is pointed automatically at their foot; and yes, it is loaded and has a hair trigger; but users should know better. I mean they are programmers, for heaven's sake, they should know about trigger discipline."
-
Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:
Personally I would actively avoid the check,
Hmm. What a weird thing to say.
Loup-Vaillant wrote a cryptography library called Monocypher, which famously had an EdDSA vulnerability mostly caused by their insistence on rolling their own custom EdDSA variant to avoid SHA512.
"I wonder how Monocypher holds up in 2026?"
Who said that? Well, anyway:
-
@rusty__shackleford @soatok Trying to determine if this is bad snark on their part or the output of an AI agent
-
@rusty__shackleford @soatok Trying to determine if this is bad snark on their part or the output of an AI agent
@cwebber @rusty__shackleford The "spell out the acronyms used in the filenames" part does gesture suggestively towards "AI"
The heel-turn on me allegedly not contacting them without an "You're absolutely right!" tells me that, even if it is AI, they at least edited the sycophancy out of it.
-
Loup-Vaillant wrote this on Lobste.rs in a dumb rant about my Matrix disclosure:
Personally I would actively avoid the check,
Hmm. What a weird thing to say.
Loup-Vaillant wrote a cryptography library called Monocypher, which famously had an EdDSA vulnerability mostly caused by their insistence on rolling their own custom EdDSA variant to avoid SHA512.
"I wonder how Monocypher holds up in 2026?"
Who said that? Well, anyway:
@soatok Wait, so the entire input validation scheme is "don't call it wrong?"
That's... well, that's a choice you can make, I guess.
-
@cwebber @rusty__shackleford The "spell out the acronyms used in the filenames" part does gesture suggestively towards "AI"
The heel-turn on me allegedly not contacting them without an "You're absolutely right!" tells me that, even if it is AI, they at least edited the sycophancy out of it.
@soatok @rusty__shackleford you're absolutely right
-
@soatok Wait, so the entire input validation scheme is "don't call it wrong?"
That's... well, that's a choice you can make, I guess.
@wordshaper Our Threat Model is "You must only accept secure inputs if you want secure outputs".
-
@wordshaper Our Threat Model is "You must only accept secure inputs if you want secure outputs".
@soatok good thing this code doesn’t have to operate in an adversarial environment. Something unfortunate could happen.
-
-
undefined oblomov@sociale.network shared this topic
-
@rusty__shackleford @soatok Trying to determine if this is bad snark on their part or the output of an AI agent
@cwebber @rusty__shackleford @soatok I think the "the output length limit is a precondition" definitely stinks of AI, confusing pre and post like that. Either that or somebody is incredibly incompetent.
Resulting, now, in a situation where either someone has to admit how dumb they are or admit they let AI write this, which will result in a double down of angry denial, most likely.
-
@cwebber @rusty__shackleford @soatok I think the "the output length limit is a precondition" definitely stinks of AI, confusing pre and post like that. Either that or somebody is incredibly incompetent.
Resulting, now, in a situation where either someone has to admit how dumb they are or admit they let AI write this, which will result in a double down of angry denial, most likely.
@tekhedd @rusty__shackleford @soatok I did end up thinking about this Nancy comic after I sent this this morning