Sign in

InsanityBit

@insanitybit.bsky.social
25 followers 12 following 127 posts
PostsRepliesMedia
InsanityBit @insanitybit.bsky.social · 01/04/2026
Just updated rust deps. Ran `cargo-vet`, got lots of unaudited updates. Spawn an agent for each one with a prompt to review for unsafe or actively malicious dependencies. This took 11 minutes. Perfect? No. But imo a huge win.
100
InsanityBit @insanitybit.bsky.social · 01/04/2026
Greg is so fucking dumb github.com/cisagov/vuln...
github.com
Request: Exclude kernel.org CVEs from CVSS/CWE enrichment · Issue #262 · cisagov/vulnrichment
We intentionally don't include CVSS scores or CWE identifiers in kernel.org CVEs, and we'd appreciate it if CISA's ADP stopped adding them. The kernel is used in everything from phones to supercomp...
000
InsanityBit @insanitybit.bsky.social · 01/04/2026
I vibe coded a cargo replacement that sandboxes build scripts with wasm, adds a Manifest.toml with cap policies + lockfile so you have to ack changes to dependency sandbox policies, and forces you to ack proc macros (since they can't be sandboxed without rustc help). It pretty much "just works".
130
InsanityBit @insanitybit.bsky.social · 28/03/2026
A lot of these supply chain issues could have been solved by package managers using any number of well known, well understood techniques that have been suggested a million times. Instead we're going to get "dependency cooldowns" lol
130
InsanityBit @insanitybit.bsky.social · 25/03/2026
I hate that "FROM" comes after "SELECT" in sql. :[
021
InsanityBit @insanitybit.bsky.social · 24/03/2026
sccache thinking it can get away with 10GB lol, off by about 10x there
000
InsanityBit @insanitybit.bsky.social · 18/03/2026
Does anyone know how DLSS5 works? I don't. Is it just a generic "filter" like from Snapchat or whatever? Or is it more like a tunable feature where devs can target it/ configure it?
000
InsanityBit @insanitybit.bsky.social · 17/03/2026
Line Goes Up? Large Language Models are Poor General Reasoners jamesfodor.com/2025/06/22/l...
jamesfodor.com
Line Goes Up? Large Language Models are Poor General Reasoners
Introduction The recent development of large language models (LLMs) based on the transformer architecture has led to extensive discussion as to how to best measure their capabilities. The most comm…
000
InsanityBit @insanitybit.bsky.social · 15/03/2026
cdn2.qualys.com/advisory/202... It is very nice to read something like this and stumble upon work we did at Grapl. Valentina's exploits were genuinely stellar, it's always nice to see that work get referenced.
cdn2.qualys.com
000
InsanityBit @insanitybit.bsky.social · 14/03/2026
cdn2.qualys.com/advisory/202... > Last-minute note: unfortunately, no CVEs have been assigned to these vulnerabilities yet, because "CVEs are assigned after-the-fact" Linux security remains a joke.
cdn2.qualys.com
000
InsanityBit @insanitybit.bsky.social · 11/03/2026
Having a very good time with Apache DataFusion. datafusion.apache.org I was skeptical that it could incorporate some optimizations I've been working on, but nope, I've managed to fit them all in and now I get SQL "for free".
datafusion.apache.org
Apache DataFusion — Apache DataFusion documentation
000
InsanityBit @insanitybit.bsky.social · 26/02/2026
I'd never have the patience for this normally, but I've had claude move basically all of my dynamic content into sandboxed iframes with strict CSPs that have to RPC back to the main page to do anything other than render content. Null origins, no networking, etc.
100
InsanityBit @insanitybit.bsky.social · 24/02/2026
Someone needs to be brave and just start producing JSON parsers that produce/consume JSON with trailing commas. I don't care if everything breaks, enough is enough.
000
InsanityBit @insanitybit.bsky.social · 22/02/2026
A very silly but insanely significant advantage to maintaining a Rust codebase is how significantly less likely you are to get "hey please patch this completely stupid CVE" requests every day for CVEs that aren't even valid.
120
InsanityBit @insanitybit.bsky.social · 21/02/2026
Switching hash algorithms in Rust is such an easy win. 40% performance improvement on one of my project's benchmarks.
010
InsanityBit @insanitybit.bsky.social · 19/02/2026
Decades later and Linux security is still a fucking joke; www.kroah.com/log/blog/202...
kroah.com
Linux CVE assignment process
As described previously, the Linux kernel security team does not identify or mark or announce any sort of security fixes that are made to the Linux kernel tree. So how, if the Linux kernel were to be...
100
InsanityBit @insanitybit.bsky.social · 16/02/2026
Absolutely insane what kind of performance opportunities there are when you replace strings with integers. Especially 32bit integers.
100
InsanityBit @insanitybit.bsky.social · 15/02/2026
LLMs are definitely going to kill HN. I don't see how it'll survive with the bots signing up.
000
InsanityBit @insanitybit.bsky.social · 14/02/2026
Very frustrated again that the best algorithm that's available with FIPS is AES-256-GCM. I really dislike this.
010
Reposted by InsanityBit
david barsky @davidbarsky.com · 14/02/2026
do i know anyone who works at azure that can get me access to horizondb? i can elaborate more in dms if needed.
001
InsanityBit @insanitybit.bsky.social · 14/02/2026
lwn.net/SubscriberLi... "When Git was released, SHA-1 was considered to be a secure hash function" ahahaha. Wow. Revisionist history is really something else. Thankfully it's trivial to verify that this is nonsense. Linus chose the unsafe option out of hubris and ignorance.
lwn.net
Evolving Git for the next decade
Git is ubiquitous; in the last two decades, the version-control system has truly achieved world [...]
100
Reposted by InsanityBit
Scott Piper @scottpiper.bsky.social · 13/02/2026
It pains me when I hear people say "I thought about submitting a talk to the fwd:cloudsec, but didn't because..." and the reasons are often things I actually want to see presentations on! Some talk ideas I personally want to watch (the other reviewers and I will fight ⚔️):
131
InsanityBit @insanitybit.bsky.social · 13/02/2026
Someone add Linus's face to the to and idk Claude or whatever to the bottom
100
InsanityBit @insanitybit.bsky.social · 09/02/2026
Wish there were a way to know if a crate author is using non-phishable 2FA :C
000
InsanityBit @insanitybit.bsky.social · 06/02/2026
I really wish Rust crates had binary distributions. Compile times are still an order of magnitude too slow.
000
InsanityBit @insanitybit.bsky.social · 28/01/2026
I don't get why I would bother with this lol gist.github.com/MostAwesomeD... Maybe someone who's in a more "influencer" space might. But "I am tired of hearing the fallacious claim that [...] those same chatbots are able to develop any software whatsoever." is obviously true to me so who cares?
gist.github.com
Lobsters Vibecoding Challenge (Winter 2025-2026)
Lobsters Vibecoding Challenge (Winter 2025-2026). GitHub Gist: instantly share code, notes, and snippets.
100
InsanityBit @insanitybit.bsky.social · 02/01/2026
I stopped paying attention to the rust subreddit for years. Looking at it lately, it's absolute dogshit. Is this just fallout from so many rust devs moving to other forums/ leaving the community? It's a bad look to have it suck so hard.
000
Reposted by InsanityBit
Luis Villa @lu.is · 21/12/2025
Quick quiz: how many people in S.F. were killed by Waymos this week? How many people in S.F. were killed by human drivers this week? (The answers are zero and two, but no one would know that from the reactions today.)
6389
InsanityBit @insanitybit.bsky.social · 18/12/2025
Github Actions was bad on release and hasn't really improved since then. Moving to depot is 30 seconds of work and will give you 10x performance, radically better UX, and 50% of the cost. I have no idea what bonehead thought that GHA should fuck with pricing right now.
000
InsanityBit @insanitybit.bsky.social · 30/11/2025
Inability to trivially mock in Rust is a real problem. Similarly, inability to assert things like "a method was called N times" etc. This would be invaluable for formally verifying some aspects of my algorithms (ie: optimizations that ensure O(N) etc) via properties of tests.
100
InsanityBit @insanitybit.bsky.social · 24/11/2025
I think the dependency "cooldown" approach is fundamentally flawed and a total distraction from the work that would actually solve supply chain issues - sandboxing and attestation. insanitybit.github.io/2025/11/22/o...
insanitybit.github.io
On Dependency Cooldowns - InsanityBit
0204
InsanityBit @insanitybit.bsky.social · 10/11/2025
Doing a thing with wasm again. I always end up disappointed, let's see how it goes this time!
000
InsanityBit @insanitybit.bsky.social · 12/10/2025
news.ycombinator.com/item?id=4556... Interesting how broken your epistemology has to be to say something like this. "We call it X therefor it is X".
news.ycombinator.com
> we are on the cusp of intelligent machines. Nah, we aren't. There's a reason t... | Hacker News
010
InsanityBit @insanitybit.bsky.social · 12/10/2025
Trying to modularize crates so that the entire API surface and implementation of each can fit into a small context window.
000
Reposted by InsanityBit
emily s. @emily.news · 11/10/2025
I totally get why people think this (due to how rapidly the SOTA has changed), but it's not really accurate. Transformer models operate in high-dimensional embedding spaces where semantic relationships differ from surface form. It's not just about the text. It's the meanings, the relationships.
3386
InsanityBit @insanitybit.bsky.social · 09/10/2025
Lobste.rs AI discussions are so cringe. I mostly don't visit the site at this point because it's basically just 1 or 2 commenters providing value, but when I do and I see AI convos they're just hard to read. lobste.rs/s/xbxhvq/vib... Simon does good work, idk why he tries to talk to these people.
lobste.rs
Lobsters
000
InsanityBit @insanitybit.bsky.social · 25/09/2025
An interesting thing about "a malicious package grabbed keys from the system" is that this problem has 0 technical or UX considerations and has been solved by browsers for over 20 years. Sandboxing is the solution. That is it. UX for sandboxing is solved, look at manifests and how changes surface.
100
InsanityBit @insanitybit.bsky.social · 01/09/2025
Two things I feel comfortable "vibe coding" (ie: with loose guidance, allowing a model to drive). 1. After my own tests are written, asking for additional "Given/ When/ Then" tests to be written based on expected properties of the code. 2. Reduction of code to reduce LOC. "That could be a fn"
110
InsanityBit @insanitybit.bsky.social · 25/08/2025
Feels nuts that Github Actions doesn't provide basic features like restricting outbound networking. This feels like it would be so dead simple for them to implement?
000
InsanityBit @insanitybit.bsky.social · 03/08/2025
Claude is far too nice and not nearly as skeptical as I want it to be. I suppose second guessing and checking assumptions is very expensive but it's frustrating, and I've found that I need to have a second model in a sort of "skeptical mode" to compensate.
000
Reposted by InsanityBit
Steve Klabnik @steveklabnik.com · 24/07/2025
Safer drivers, stronger devices (with #rustlang) techcommunity.microsoft.com/blog/surface...
techcommunity.microsoft.com
Safer Drivers, Stronger Devices | Microsoft Community Hub
Surface is advancing Windows driver development by adopting Rust, a memory-safe programming language, to improve device security and reliability. Through...
2427
InsanityBit @insanitybit.bsky.social · 20/07/2025
OpenAI's Codex needs a lot more work.
000
InsanityBit @insanitybit.bsky.social · 13/07/2025
Very glad that "function coloring is good" has stopped being such a hot take.
010
InsanityBit @insanitybit.bsky.social · 11/07/2025
I wonder how much ChatGPT usage spikes on Prime Day
000
InsanityBit @insanitybit.bsky.social · 25/06/2025
Support for atoms is now implemented.
000
InsanityBit @insanitybit.bsky.social · 24/06/2025
Running into a particularly challenging issue. I want anonymous structs in my language. Doing this in a way that's zero cost + compiling to Rust is *hard*. In particular, the first pass I have is to gen `HasX` traits for each prop, but then rust borrows the entire `self`, making moves impossible.
110
InsanityBit @insanitybit.bsky.social · 23/06/2025
My language is now faster than rust... sometimes. Faster default hasher + the effects system opens up novel optimization opportunities.
110
InsanityBit @insanitybit.bsky.social · 22/06/2025
got capabilities done
000
InsanityBit @insanitybit.bsky.social · 20/06/2025
Spent time writing some basic optimizations for codegen. I've doubled the performance of some operations. Still much slower than Rust, but I'm about to write a CFG to do a lot more optimization. And there's still low hanging fruit.
100
InsanityBit @insanitybit.bsky.social · 19/06/2025
My language now supports inference of union types in a way that's really neat and compiles to a rust enum under the hood. Full Hindley-Milner with unification, lots of type tracking info that I may use later like *where* a type comes from (for flow typing and refining later!).
010