InsanityBit @insanitybit.bsky.social · 01/04/2026I'm considering having an open project where opus becomes a cargo-vet producer that you can opt into trusting, that way we aren't all doing this individually. Plus it could leverage far better tooling (ie: "run in sandbox, eval results") to be more resilient. 000
InsanityBit @insanitybit.bsky.social · 01/04/2026Just updated rust deps. Ran `cargo-vet`, got lots of unaudited updates. Spawn an agent for each one with a prompt to review for unsafe or actively malicious dependencies. This took 11 minutes. Perfect? No. But imo a huge win. 100
InsanityBit @insanitybit.bsky.social · 01/04/2026Greg is so fucking dumb github.com/cisagov/vuln...github.comRequest: Exclude kernel.org CVEs from CVSS/CWE enrichment · Issue #262 · cisagov/vulnrichmentWe intentionally don't include CVSS scores or CWE identifiers in kernel.org CVEs, and we'd appreciate it if CISA's ADP stopped adding them. The kernel is used in everything from phones to supercomp... 000
InsanityBit @insanitybit.bsky.social · 01/04/2026Most of the code in this project is just calling `cargo manifest` or the cargo crate to resolve packages, query info about them, etc. 010
InsanityBit @insanitybit.bsky.social · 01/04/2026I'm not saying this is production worthy, but I think this proves the point pretty well. Package managers can solve a lot of our supply chain issues. 110
InsanityBit @insanitybit.bsky.social · 01/04/2026Out of 633 deps I was using, 478 had build scripts that work in the wasm sandbox with minimal effort. About 50 have proc macros that I'd have to audit (or use cargo-vet) to ensure are safe before I add the exclusion to my policy. 110
InsanityBit @insanitybit.bsky.social · 01/04/2026I vibe coded a cargo replacement that sandboxes build scripts with wasm, adds a Manifest.toml with cap policies + lockfile so you have to ack changes to dependency sandbox policies, and forces you to ack proc macros (since they can't be sandboxed without rustc help). It pretty much "just works". 130
InsanityBit @insanitybit.bsky.social · 28/03/2026Browsers have already solved the "sandbox arbitrary code" problem in a lot of ways that package managers could have adopted early. Why can a crate add a `build.rs` out of nowhere without that triggering consent? Why can the `build.rs` access my entire filesystem? Put policy in a signed manifest. 120
InsanityBit @insanitybit.bsky.social · 28/03/2026Something like `cosign` lets me say "This artifact with this hash was published from this OIDC provider on this date under these conditions, here is the transparency log for it", that alone is huge. 120
InsanityBit @insanitybit.bsky.social · 28/03/2026There are still going to be gaps like "trusted developer who had a very privileged, trusted package handed someone their yubikey and laptop in person" or whatever but we'd be in a very different spot. Right now I don't even know if a crate author uses *any* 2FA, publishes from their laptop, etc. 120
InsanityBit @insanitybit.bsky.social · 28/03/2026Yeah, I mean a ton of wins are easily gotten with *really* basic stuff like 2FA, OIDC flows, better audit logging on package services, lock files, etc. Then there are some more "advanced" options like package signing/TUF, sandboxing package managers and package manifests (browser ext model). 120
InsanityBit @insanitybit.bsky.social · 28/03/2026A lot of these supply chain issues could have been solved by package managers using any number of well known, well understood techniques that have been suggested a million times. Instead we're going to get "dependency cooldowns" lol 130
InsanityBit @insanitybit.bsky.social · 25/03/2026I hate that "FROM" comes after "SELECT" in sql. :[ 021
InsanityBit @insanitybit.bsky.social · 24/03/2026sccache thinking it can get away with 10GB lol, off by about 10x there 000
InsanityBit @insanitybit.bsky.social · 18/03/2026Does anyone know how DLSS5 works? I don't. Is it just a generic "filter" like from Snapchat or whatever? Or is it more like a tunable feature where devs can target it/ configure it? 000
InsanityBit @insanitybit.bsky.social · 18/03/2026There's lil pocket side floss picks and they can slip right into a wallet ez pz. Sadly no one has made a slim form of the breath strips. 001
InsanityBit @insanitybit.bsky.social · 17/03/2026Line Goes Up? Large Language Models are Poor General Reasoners jamesfodor.com/2025/06/22/l...jamesfodor.comLine Goes Up? Large Language Models are Poor General ReasonersIntroduction The recent development of large language models (LLMs) based on the transformer architecture has led to extensive discussion as to how to best measure their capabilities. The most comm… 000
InsanityBit @insanitybit.bsky.social · 16/03/2026YEP lol I've had that experience. It's so frustrating. 000
InsanityBit @insanitybit.bsky.social · 15/03/2026cdn2.qualys.com/advisory/202... It is very nice to read something like this and stumble upon work we did at Grapl. Valentina's exploits were genuinely stellar, it's always nice to see that work get referenced.cdn2.qualys.com 000
InsanityBit @insanitybit.bsky.social · 15/03/2026I hate how people respond with "XY" answers. If you think a question is XY, respond "Here's how you solve X, here's why I think you should solve it this way with Y". Instead you just get "Don't do X, here's Y". Killed SO for me. 101
InsanityBit @insanitybit.bsky.social · 14/03/2026cdn2.qualys.com/advisory/202... > Last-minute note: unfortunately, no CVEs have been assigned to these vulnerabilities yet, because "CVEs are assigned after-the-fact" Linux security remains a joke.cdn2.qualys.com 000
InsanityBit @insanitybit.bsky.social · 11/03/2026Having a very good time with Apache DataFusion. datafusion.apache.org I was skeptical that it could incorporate some optimizations I've been working on, but nope, I've managed to fit them all in and now I get SQL "for free".datafusion.apache.orgApache DataFusion — Apache DataFusion documentation 000
InsanityBit @insanitybit.bsky.social · 11/03/2026Openssl feels like a really clear counterexample to this. Redis too tbh. I guess I don't think it's a tall order to say "understand technology in a very basic way, make informed decisions" in a field where that's sort of the entire job. 010
InsanityBit @insanitybit.bsky.social · 11/03/2026I think it's been a disaster tbh, same with "choose simple", "avoid hype", and other thought terminators. I'm sure it makes for great talk titles, hence it being popular, but it's terrible rhetoric. 010
InsanityBit @insanitybit.bsky.social · 11/03/2026Of course. See, that's an actual nuanced take that advocates making informed choices. "Choose boring" means nothing. "Choose your problems" means you actually have to understand mapping the problem to a solution - a totally different (and proper) thing to do. 110
InsanityBit @insanitybit.bsky.social · 11/03/2026Redis has terrible durability/ consistency guarantees but people use it as a durable store. Postgres is amazing, but operating it at scale can be extremely painful, and it's obviously quite bad for numerous cases. Why "boring" instead of "choose wisely"? 220
InsanityBit @insanitybit.bsky.social · 11/03/2026No one should be reaching for openssl. Tons of bugs, terrible APIs. But a "boring" mindset would lead you there. It's certainly the most popular library. Why not just learn about these technologies? Postgres and Redis will cause massive pain if chosen improperly. 110
InsanityBit @insanitybit.bsky.social · 11/03/2026There are so many footguns you'll run into with both of those. If you want to say "low chance of bugs", okay, but then say that and not "boring"? Why muddy your "pros" with this vague wording? What if there's a new tech with even fewer bugs? Or old tech with tons of bugs? Is openssl boring? 110
InsanityBit @insanitybit.bsky.social · 11/03/2026Make informed choices. Proxies like "boring" are just nonsense. Postgres isn't boring, it's deeply complex, evolving software. But "it's boring". Redis isn't boring, it's complex and has deeply problematic failure modes. But it's "boring". 110
InsanityBit @insanitybit.bsky.social · 11/03/2026Yes, I also hate that concept. Total nonsense imo. 210
InsanityBit @insanitybit.bsky.social · 11/03/2026Basically, LLMs do one thing really well - they run a bunch of dumb bash commands and type very very fast. Offloading technology choices to them is a huge mistake. 010
InsanityBit @insanitybit.bsky.social · 11/03/2026I'm in a position to make nuanced choices about technology, what happens to the next generation of devs? Further, IMO LLMs don't just target the average, they target below average (because I assume quality is on a power curve). 120
InsanityBit @insanitybit.bsky.social · 11/03/2026> They'll only suggest solutions that are common in their training data but those tend to be the Boring Technology that's most likely to work. I consider this to be one of their worst qualities tbh. "Boring Technology" is a very silly idea. No such thing as "boring technology" and the limit is real 210
InsanityBit @insanitybit.bsky.social · 26/02/2026Also, like, compromised dependency? Well that's only loaded in that sandbox. No cookies, no pop-ups, no *networking* it's nuts. 000
InsanityBit @insanitybit.bsky.social · 26/02/2026It's such an aggressive move that I'd normally never be willing to pay the price for, but claude makes it trivial since it's just bespoke boilerplate every time I want to do it. XSS in the sandbox? Don't care. 100
InsanityBit @insanitybit.bsky.social · 26/02/2026I'd never have the patience for this normally, but I've had claude move basically all of my dynamic content into sandboxed iframes with strict CSPs that have to RPC back to the main page to do anything other than render content. Null origins, no networking, etc. 100
InsanityBit @insanitybit.bsky.social · 24/02/2026Someone needs to be brave and just start producing JSON parsers that produce/consume JSON with trailing commas. I don't care if everything breaks, enough is enough. 000
InsanityBit @insanitybit.bsky.social · 22/02/2026Contrast that to JS, Ruby, Python, etc, and it's not even close. A similarly sized codebase will have so many fewer stupid DoS etc, you'll link to far fewer C/C++ libs, etc. Just a hilarious way to win on a huge amount of dumb work. 020
InsanityBit @insanitybit.bsky.social · 22/02/2026Part of this is just that the Rust ecosystem is pretty solid, but the silly part is a lot of it comes down to the Rust ecosystem just not having a ton of people issuing CVEs for it. Regardless, you benefit massively on ops overhead for a rust codebase. 120
InsanityBit @insanitybit.bsky.social · 22/02/2026A very silly but insanely significant advantage to maintaining a Rust codebase is how significantly less likely you are to get "hey please patch this completely stupid CVE" requests every day for CVEs that aren't even valid. 120
InsanityBit @insanitybit.bsky.social · 21/02/2026Switching hash algorithms in Rust is such an easy win. 40% performance improvement on one of my project's benchmarks. 010
InsanityBit @insanitybit.bsky.social · 19/02/2026Letting this guy run a CNA is the biggest fuckup the CVE system as managed so far, which says a lot. 000
InsanityBit @insanitybit.bsky.social · 19/02/2026Decades later and Linux security is still a fucking joke; www.kroah.com/log/blog/202...kroah.comLinux CVE assignment processAs described previously, the Linux kernel security team does not identify or mark or announce any sort of security fixes that are made to the Linux kernel tree. So how, if the Linux kernel were to be... 100
InsanityBit @insanitybit.bsky.social · 18/02/2026I've never seen people say this but I'm not on LinkedIn/Twitter. Do you have a reference for that? 010
InsanityBit @insanitybit.bsky.social · 16/02/2026If you can go lower, do it. Even if you don't go down to 2^16, it's still beneficial to say "I only use 2^22 of 2^32 values" and now you have 10 bits to play with for all sorts of fun tagging. 10 bits is a lot. 000
InsanityBit @insanitybit.bsky.social · 16/02/2026Literally 1000s of times faster for so many operations, with 10x space savings easily, and even better if you can shave a few bits off. 100
InsanityBit @insanitybit.bsky.social · 16/02/2026Absolutely insane what kind of performance opportunities there are when you replace strings with integers. Especially 32bit integers. 100
InsanityBit @insanitybit.bsky.social · 16/02/2026I also have meta agents with their own rules. These check that the other agents are working effectively, with a sort of meta benchmarking suite that will fail if the other agents aren't performing the requisite tasks. Every agent has 1+ JSON files that they get verified against and a fail threshold. 000
InsanityBit @insanitybit.bsky.social · 16/02/2026Notably, I've set things up so that verification is at the absolute core. *Everything* is verifiable. Playwright tests, benchmarks, tons of logs and metrics that the agents all have the ability to call into, pre-commit hooks that force behaviors, etc. 100
InsanityBit @insanitybit.bsky.social · 16/02/2026There's these very uncomfortable periods where the gap exists but so far it hasn't been a problem, despite this being my most aggressively vibe coded project ever. I'm learning to not feel so nervous, and I'm learning a lot tbh. Those times where I sync up are very interesting. 100