InsanityBit @insanitybit.bsky.social · 01/04/2026Just updated rust deps. Ran `cargo-vet`, got lots of unaudited updates. Spawn an agent for each one with a prompt to review for unsafe or actively malicious dependencies. This took 11 minutes. Perfect? No. But imo a huge win. 100
InsanityBit @insanitybit.bsky.social · 01/04/2026Greg is so fucking dumb github.com/cisagov/vuln...github.comRequest: Exclude kernel.org CVEs from CVSS/CWE enrichment · Issue #262 · cisagov/vulnrichmentWe intentionally don't include CVSS scores or CWE identifiers in kernel.org CVEs, and we'd appreciate it if CISA's ADP stopped adding them. The kernel is used in everything from phones to supercomp... 000
InsanityBit @insanitybit.bsky.social · 01/04/2026I vibe coded a cargo replacement that sandboxes build scripts with wasm, adds a Manifest.toml with cap policies + lockfile so you have to ack changes to dependency sandbox policies, and forces you to ack proc macros (since they can't be sandboxed without rustc help). It pretty much "just works". 130
InsanityBit @insanitybit.bsky.social · 28/03/2026A lot of these supply chain issues could have been solved by package managers using any number of well known, well understood techniques that have been suggested a million times. Instead we're going to get "dependency cooldowns" lol 130
InsanityBit @insanitybit.bsky.social · 25/03/2026I hate that "FROM" comes after "SELECT" in sql. :[ 021
InsanityBit @insanitybit.bsky.social · 24/03/2026sccache thinking it can get away with 10GB lol, off by about 10x there 000
InsanityBit @insanitybit.bsky.social · 18/03/2026Does anyone know how DLSS5 works? I don't. Is it just a generic "filter" like from Snapchat or whatever? Or is it more like a tunable feature where devs can target it/ configure it? 000
InsanityBit @insanitybit.bsky.social · 17/03/2026Line Goes Up? Large Language Models are Poor General Reasoners jamesfodor.com/2025/06/22/l...jamesfodor.comLine Goes Up? Large Language Models are Poor General ReasonersIntroduction The recent development of large language models (LLMs) based on the transformer architecture has led to extensive discussion as to how to best measure their capabilities. The most comm… 000
InsanityBit @insanitybit.bsky.social · 15/03/2026cdn2.qualys.com/advisory/202... It is very nice to read something like this and stumble upon work we did at Grapl. Valentina's exploits were genuinely stellar, it's always nice to see that work get referenced.cdn2.qualys.com 000
InsanityBit @insanitybit.bsky.social · 14/03/2026cdn2.qualys.com/advisory/202... > Last-minute note: unfortunately, no CVEs have been assigned to these vulnerabilities yet, because "CVEs are assigned after-the-fact" Linux security remains a joke.cdn2.qualys.com 000
InsanityBit @insanitybit.bsky.social · 11/03/2026Having a very good time with Apache DataFusion. datafusion.apache.org I was skeptical that it could incorporate some optimizations I've been working on, but nope, I've managed to fit them all in and now I get SQL "for free".datafusion.apache.orgApache DataFusion — Apache DataFusion documentation 000
InsanityBit @insanitybit.bsky.social · 26/02/2026I'd never have the patience for this normally, but I've had claude move basically all of my dynamic content into sandboxed iframes with strict CSPs that have to RPC back to the main page to do anything other than render content. Null origins, no networking, etc. 100
InsanityBit @insanitybit.bsky.social · 24/02/2026Someone needs to be brave and just start producing JSON parsers that produce/consume JSON with trailing commas. I don't care if everything breaks, enough is enough. 000
InsanityBit @insanitybit.bsky.social · 22/02/2026A very silly but insanely significant advantage to maintaining a Rust codebase is how significantly less likely you are to get "hey please patch this completely stupid CVE" requests every day for CVEs that aren't even valid. 120
InsanityBit @insanitybit.bsky.social · 21/02/2026Switching hash algorithms in Rust is such an easy win. 40% performance improvement on one of my project's benchmarks. 010
InsanityBit @insanitybit.bsky.social · 19/02/2026Decades later and Linux security is still a fucking joke; www.kroah.com/log/blog/202...kroah.comLinux CVE assignment processAs described previously, the Linux kernel security team does not identify or mark or announce any sort of security fixes that are made to the Linux kernel tree. So how, if the Linux kernel were to be... 100
InsanityBit @insanitybit.bsky.social · 16/02/2026Absolutely insane what kind of performance opportunities there are when you replace strings with integers. Especially 32bit integers. 100
InsanityBit @insanitybit.bsky.social · 15/02/2026LLMs are definitely going to kill HN. I don't see how it'll survive with the bots signing up. 000
InsanityBit @insanitybit.bsky.social · 14/02/2026Very frustrated again that the best algorithm that's available with FIPS is AES-256-GCM. I really dislike this. 010
Reposted by InsanityBitdavid barsky @davidbarsky.com · 14/02/2026do i know anyone who works at azure that can get me access to horizondb? i can elaborate more in dms if needed. 001
InsanityBit @insanitybit.bsky.social · 14/02/2026lwn.net/SubscriberLi... "When Git was released, SHA-1 was considered to be a secure hash function" ahahaha. Wow. Revisionist history is really something else. Thankfully it's trivial to verify that this is nonsense. Linus chose the unsafe option out of hubris and ignorance.lwn.netEvolving Git for the next decadeGit is ubiquitous; in the last two decades, the version-control system has truly achieved world [...] 100
Reposted by InsanityBitScott Piper @scottpiper.bsky.social · 13/02/2026It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️): 131
InsanityBit @insanitybit.bsky.social · 13/02/2026Someone add Linus's face to the to and idk Claude or whatever to the bottom 100
InsanityBit @insanitybit.bsky.social · 09/02/2026Wish there were a way to know if a crate author is using non-phishable 2FA :C 000
InsanityBit @insanitybit.bsky.social · 06/02/2026I really wish Rust crates had binary distributions. Compile times are still an order of magnitude too slow. 000
InsanityBit @insanitybit.bsky.social · 28/01/2026I don't get why I would bother with this lol gist.github.com/MostAwesomeD... Maybe someone who's in a more "influencer" space might. But "I am tired of hearing the fallacious claim that [...] those same chatbots are able to develop any software whatsoever." is obviously true to me so who cares?gist.github.comLobsters Vibecoding Challenge (Winter 2025-2026)Lobsters Vibecoding Challenge (Winter 2025-2026). GitHub Gist: instantly share code, notes, and snippets. 100
InsanityBit @insanitybit.bsky.social · 02/01/2026I stopped paying attention to the rust subreddit for years. Looking at it lately, it's absolute dogshit. Is this just fallout from so many rust devs moving to other forums/ leaving the community? It's a bad look to have it suck so hard. 000
Reposted by InsanityBitLuis Villa @lu.is · 21/12/2025Quick quiz: how many people in S.F. were killed by Waymos this week? How many people in S.F. were killed by human drivers this week? (The answers are zero and two, but no one would know that from the reactions today.) 6389
InsanityBit @insanitybit.bsky.social · 18/12/2025Github Actions was bad on release and hasn't really improved since then. Moving to depot is 30 seconds of work and will give you 10x performance, radically better UX, and 50% of the cost. I have no idea what bonehead thought that GHA should fuck with pricing right now. 000
InsanityBit @insanitybit.bsky.social · 30/11/2025Inability to trivially mock in Rust is a real problem. Similarly, inability to assert things like "a method was called N times" etc. This would be invaluable for formally verifying some aspects of my algorithms (ie: optimizations that ensure O(N) etc) via properties of tests. 100
InsanityBit @insanitybit.bsky.social · 24/11/2025I think the dependency "cooldown" approach is fundamentally flawed and a total distraction from the work that would actually solve supply chain issues - sandboxing and attestation. insanitybit.github.io/2025/11/22/o...insanitybit.github.io On Dependency Cooldowns - InsanityBit 0204
InsanityBit @insanitybit.bsky.social · 10/11/2025Doing a thing with wasm again. I always end up disappointed, let's see how it goes this time! 000
InsanityBit @insanitybit.bsky.social · 12/10/2025news.ycombinator.com/item?id=4556... Interesting how broken your epistemology has to be to say something like this. "We call it X therefor it is X".news.ycombinator.com> we are on the cusp of intelligent machines. Nah, we aren't. There's a reason t... | Hacker News 010
InsanityBit @insanitybit.bsky.social · 12/10/2025Trying to modularize crates so that the entire API surface and implementation of each can fit into a small context window. 000
Reposted by InsanityBitemily s. @emily.news · 11/10/2025I totally get why people think this (due to how rapidly the SOTA has changed), but it's not really accurate. Transformer models operate in high-dimensional embedding spaces where semantic relationships differ from surface form. It's not just about the text. It's the meanings, the relationships. 3386
InsanityBit @insanitybit.bsky.social · 09/10/2025Lobste.rs AI discussions are so cringe. I mostly don't visit the site at this point because it's basically just 1 or 2 commenters providing value, but when I do and I see AI convos they're just hard to read. lobste.rs/s/xbxhvq/vib... Simon does good work, idk why he tries to talk to these people.lobste.rsLobsters 000
InsanityBit @insanitybit.bsky.social · 25/09/2025An interesting thing about "a malicious package grabbed keys from the system" is that this problem has 0 technical or UX considerations and has been solved by browsers for over 20 years. Sandboxing is the solution. That is it. UX for sandboxing is solved, look at manifests and how changes surface. 100
InsanityBit @insanitybit.bsky.social · 01/09/2025Two things I feel comfortable "vibe coding" (ie: with loose guidance, allowing a model to drive). 1. After my own tests are written, asking for additional "Given/ When/ Then" tests to be written based on expected properties of the code. 2. Reduction of code to reduce LOC. "That could be a fn" 110
InsanityBit @insanitybit.bsky.social · 25/08/2025Feels nuts that Github Actions doesn't provide basic features like restricting outbound networking. This feels like it would be so dead simple for them to implement? 000
InsanityBit @insanitybit.bsky.social · 03/08/2025Claude is far too nice and not nearly as skeptical as I want it to be. I suppose second guessing and checking assumptions is very expensive but it's frustrating, and I've found that I need to have a second model in a sort of "skeptical mode" to compensate. 000
Reposted by InsanityBitSteve Klabnik @steveklabnik.com · 24/07/2025Safer drivers, stronger devices (with #rustlang) techcommunity.microsoft.com/blog/surface...techcommunity.microsoft.comSafer Drivers, Stronger Devices | Microsoft Community HubSurface is advancing Windows driver development by adopting Rust, a memory-safe programming language, to improve device security and reliability. Through... 2427
InsanityBit @insanitybit.bsky.social · 13/07/2025Very glad that "function coloring is good" has stopped being such a hot take. 010
InsanityBit @insanitybit.bsky.social · 11/07/2025I wonder how much ChatGPT usage spikes on Prime Day 000
InsanityBit @insanitybit.bsky.social · 24/06/2025Running into a particularly challenging issue. I want anonymous structs in my language. Doing this in a way that's zero cost + compiling to Rust is *hard*. In particular, the first pass I have is to gen `HasX` traits for each prop, but then rust borrows the entire `self`, making moves impossible. 110
InsanityBit @insanitybit.bsky.social · 23/06/2025My language is now faster than rust... sometimes. Faster default hasher + the effects system opens up novel optimization opportunities. 110
InsanityBit @insanitybit.bsky.social · 20/06/2025Spent time writing some basic optimizations for codegen. I've doubled the performance of some operations. Still much slower than Rust, but I'm about to write a CFG to do a lot more optimization. And there's still low hanging fruit. 100
InsanityBit @insanitybit.bsky.social · 19/06/2025My language now supports inference of union types in a way that's really neat and compiles to a rust enum under the hood. Full Hindley-Milner with unification, lots of type tracking info that I may use later like *where* a type comes from (for flow typing and refining later!). 010