• 0 Posts
  • 142 Comments
Joined 2 years ago
cake
Cake day: July 9th, 2023

help-circle




  • Could you let me know what sort of models you’re using? Everything I’ve tried has basically been so bad it was quicker and more reliable to to the job myself. Most of the models can barely write boilerplate code accurately and securely, let alone anything even moderately complex.

    I’ve tried to get them to analyse code too, and that’s hit and miss at best, even with small programs. I’d have no faith at all that they could handle anything larger; the answers they give would be confident and wrong, which is easy to spot with something small, but much harder to catch with a large, multi process system spread over a network. It’s hard enough for humans, who have actual context, understanding and domain knowledge, to do it well, and I’ve, personally, not seen any evidence that an LLM (which is what I’m assuming you’re referring to) could do anywhere near as well. I don’t doubt that they flag some issues, but without a comprehensive, human, review of the system architecture, implementation and code, you can’t be sure what they’ve missed, and if you’re going to do that anyway, you’ve done the job yourself!

    Having said that, I’ve no doubt that things will improve, programming languages have well defined syntaxes and so they should be some of the easiest types of text for an LLM to parse and build a context from. If that can be combined with enough domain knowledge, a description of the deployment environment and a model that’s actually trained for and tuned for code analysis and security auditing, it might be possible to get similar results to humans.


  • I’m unlikely to do a full code audit, unless something about it doesn’t pass the ‘sniff test’. I will often go over the main code flows, the issue tracker, mailing lists and comments, positive or negative, from users on other forums.

    I mean, if you’re not doing that, what are you doing, just installing it and using it??!? Where’s the fun in that? (I mean this at least semi seriously, you learn a lot about the software you’re running if you put in some effort to learn about it)


  • ‘AI’ as we currently know it, is terrible at this sort of task. It’s not capable of understanding the flow of the code in any meaningful way, and tends to raise entirely spurious issues (see the problems the curl author has with being overwhealmed for example). It also wont spot actually malicious code that’s been included with any sort of care, nor would it find intentional behaviour that would be harmful or counterproductive in the particular scenario you want to use the program.


  • No, you cannot meaningfully delete your posts or comments, but that’s not because of any issue with lemmy, but because you posted them publically. They will be archived and indexed in other services.

    It is always best to remember that all your activity here is public, and will be linked to your username. Given that, you may wish to minimise any personally identifying information you post, and use several accounts to split up your activities by topic.









  • That only gives you 364 daya per year and we need just fractionally less than 365.25. You end up needing an extra day every year, and if we want to keep midnight in the middle of the night, and extra full day every four years (except when we don’t). Adding those sorts of bodges onto an otherwise elegant system would be awful to work with.

    Instead, I propose we build giant rocket engines pointing straight up on the equator, and adjust the Earth’s orbit until one orbit around the sun takes exactly 364 days.


  • notabot@lemm.eetoxkcd@lemmy.worldxkcd #3081: PhD Timeline
    link
    fedilink
    English
    arrow-up
    33
    ·
    2 months ago

    I did the same, pressed on it for the text, got sent straight to the video, and swore under my breath in admiration. In the current climate what he’s done isn’t risk free, despite the fact it a) should be, and b) shouldn’t be needed in the first place.

    Nothing but respect for people calling out the crimes of thus administration, and when it’s someone with an unrelated platform and an audience, so much the better.


  • I’m not a truck-nut-ologist, so I don’t have much to go on, and it’s frustratingly difficult finding accurate dimensions for them online. I have found this delightfulawful pair (I had to look at them, so so do you).

    The entire structure is approximately 40cm tall, and I measure that as 660 pixels, it look like the main ‘bulk’ of it is in the lower 330 pixels, or 20cm, and about 375 pixels wide, or around 23cm. If we assume that section is half as thick as it is wide, and approximate it as a cuboid (I’ve rounded the numbers, and unrounded the shape), that gives a volume of 5290cm^3, which is disturbingly close to the value you calculated as necessary. Allowing for the top section, I think they might just do the job.

    Obviously those numbers are very approximate, but I’ve started at that model enough that it’ll haunt my dreams, and ‘Ten million aircraft carriers’ is an approximate enough description, that I think we can say it’s within reasonable tolerances of being accurate.