Post B7RxFwHarJQ2DBUELI by dln@mastodon.social
 (DIR) More posts by dln@mastodon.social
 (DIR) Post #B7RtBi7ZeK3DMl57wG by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       working through the rest of the claude mythos #pkgconf 'findings'some of these are pretty meh 🙃
       
 (DIR) Post #B7RtW8m6GGhdp3mMs4 by whitequark@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne yeah this is the general conclusion i draw from these toolsthere are real bugs in there. there is complete bullshit there. if there were no externalities at all, the human cost of triaging the output from even better models could maybe make these things justifiable. as is... not really
       
 (DIR) Post #B7RtdhVJXMwnYoX5Jw by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       for example, it has found a number of paths where our out-of-memory handling was not as robust as it could be.  we are working through those.at the same time, it invented an entire security threat called 'sysroot injection' out of whole cloth, which is definitely not a thing
       
 (DIR) Post #B7Rtl6Y0pAprG6KDke by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @whitequark as an experiment, and to hedge against token utilization becoming a component of my performance reviews in the future, i have decided to try having claude figure out which bugs it hallucinated itself.  agentic!
       
 (DIR) Post #B7RtrC792ZweGEf6Lw by whitequark@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne i was using a service which already does that (v12)! it helps but only so much
       
 (DIR) Post #B7Ru9IEN2QOiRYfiO8 by icing@chaos.social
       0 likes, 0 repeats
       
       @ariadne The models are good at figuring out inconsistencies in all code path possibilities.Threat model evaluations, not at all.
       
 (DIR) Post #B7RuQfryP30igGU38q by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @icing i am so far underwhelmed, these things just primarily remain useful as autocomplete
       
 (DIR) Post #B7RuuhpXg3QxRvfOrY by ariadne@social.treehouse.systems
       1 likes, 0 repeats
       
       what was promised: hack anything modelwhat was provided: "sysroot injection is the classic pkgconf threat model"
       
 (DIR) Post #B7RvB7U83tBPeJTfou by andrew_shadura@mastodon.social
       0 likes, 0 repeats
       
       @ariadne it invented mythology!
       
 (DIR) Post #B7RvDYCzfuCL6tccZk by ariadne@social.treehouse.systems
       1 likes, 1 repeats
       
       it's so scary that trump had to ban ithttps://youtu.be/4QwBmStwK2w
       
 (DIR) Post #B7RvQ78fdAbkv4afUO by xyhhx@social.treehouse.systems
       0 likes, 0 repeats
       
       @ariadne okay hard
       
 (DIR) Post #B7RxFw1znIwTQoBm1w by charlotte@akko.chir.rs
       0 likes, 0 repeats
       
       @ariadne what the fuck does that even meanbeing able to change the sysroot?
       
 (DIR) Post #B7RxFwHarJQ2DBUELI by dln@mastodon.social
       0 likes, 0 repeats
       
       @charlotte @ariadne sysroots can inject anywhere and anytime! it might be happening right now!
       
 (DIR) Post #B7RxFwTI9omCnSxZZo by ariadne@social.treehouse.systems
       0 likes, 0 repeats
       
       @dln @charlotte look i'm stoned right now because it makes reading these silly reports more fun
       
 (DIR) Post #B7SH1eTYGbI00rXpaq by yildo@cosocial.ca
       0 likes, 0 repeats
       
       @ariadne Yep, it's non-deterministic, so a second instance with separate context can catch some of the BS from the first instance