[-] Septimaeus@infosec.pub 1 points 18 hours ago

Oh and to do this, just tap anywhere near the top of the screen

[-] Septimaeus@infosec.pub 2 points 18 hours ago

And we have to expect that trend will continue. I haven’t tested frontier capabilities since April but I know for a fact my local drafters are producing far fewer obvious smells than I remember seeing in frontier outputs even just last year.

Current frontier is likely still detectable by an experienced engineer, especially if they’ve seen enough gen code to recognize the patterns, but might otherwise be indistinguishable from junior-level work. That is, I wouldn’t be surprised if the current frontier models didn’t output ANY giveaway “slop” code or outright hallucinations. Symptoms might be more abstract like inelegant architectural decisions, obtuse alg/structure selection, or design choices that demonstrate no grasp of overall objectives.

My point was that from a project maintainer’s perspective, quality is more a side effect, and there’s no effective difference between no AI and no detectable AI. The actual point of a no-vibecode policy is (A) to communicate expectations, ensuring contributors know their PR must pass a sniff test, that their name is on it, so blind PR submission is never a safe choice, and (B) to have a bulletproof policy to refer to in retrospect if ever issues relating to AI use in the project arise.

[-] Septimaeus@infosec.pub 2 points 21 hours ago

Default scroll-to-top behaviors on status bar tap (or re-implementations of it in multiplatform PWAs) are a common culprit behind random scroll to top behaviors reported for mobile apps in the past decade or so. Not sure if that’s what’s up but worth checking if that gives you repro.

[-] Septimaeus@infosec.pub 3 points 22 hours ago

Yet in principle the social benefit described (amplifying voices of the unheard) isn’t entirely out of reach for social media as a category, especially if we can escape the era of closed platforms. Open alternatives are still relatively new. There is a plausible future in which closed platforms are left behind and we become much more capable of keeping mass public manipulation in check.

[-] Septimaeus@infosec.pub 2 points 1 day ago

BoTh SiDeS .… voting won’t work …. what “needs to be done”

Wow. Can you guys at least vary your scripts a little bit? And maybe don’t try to hit all the buzz phrases in a single comment. Your target audience never reads that far.

[-] Septimaeus@infosec.pub 4 points 1 day ago

That’s pretty much the subtext of bans anyway. To guarantee undetectable use the contributor must treat gen code like a junior’s draft and refactor prior to PR. If it’s undetectable, the end result is the same from the maintainer’s perspective.

And it’s not a new approach. This has long been true for contributions containing “found” code; we define what’s allowed knowing we can’t actually enforce the rule against the most artfully obfuscated violations because, aside from achieving ostensibly the same result, having that tappable sign protects the project from a lot of BS down the line.

[-] Septimaeus@infosec.pub 4 points 1 day ago

Agreed, I’m pretty used to security key unlocks and still wouldn’t want that friction on a personal device.

Also just for completeness, since I forgot to mention: enabling stolen device protection and findmy/mdm to enable remote wipe.

[-] Septimaeus@infosec.pub 3 points 1 day ago

Disclaimer: I only use iPhones for security testing, so this is more from related literature rather than first-hand experience.

IIRC the hardening unattended reboot could offer is already covered better by options like disabling biometric unlock, security key 2FA, enabling lockdown mode, enabling advanced data protection, disabling iCloud, disabling USB accessories, and so forth. Also unattended reboot seems like an easy prank vector or foot gun to render a device permanently inaccessible (i.e., device always reboots immediately after pin entry) requiring recovery mode reset or restore to fix.

[-] Septimaeus@infosec.pub 3 points 2 days ago

And surprise surprise, a quick check of posting history reveals no call to action during primaries, and often no mention of elections at all.

Only after primaries conclude does it become so imperative, suddenly, to convince everyone why not voting is the only virtuous choice.

How convenient.

[-] Septimaeus@infosec.pub 2 points 2 days ago

“…15 days ago”

[-] Septimaeus@infosec.pub 10 points 3 days ago

If similar to equivalent state regs, when access to customers residing in that market is gated by compliance and subject to lawsuits or ban, the first phase of business-side operations change is immediately setting up minimum compliance workflow like a special webpage coupled with countermeasures (like proof of residency; IP historically difficult in court but has been used successfully for state-specific age gating) and boundary testing cycles. With especially large markets, however, the overhead associated with maintaining multiple separate workflows fails the efficiency test and the workflows are merged, which is how everyone tends to benefit from pro-consumer laws like GDPR.

67
submitted 1 week ago* (last edited 1 week ago) by Septimaeus@infosec.pub to c/experienced_devs@programming.dev

ETA: summary…

Author describes how agentic coding tools have disincentivized the developer training and mentorship pipeline that the software industry has implicitly relied on to produce seasoned developers, predicting that once the shortage is fully realized it could take years to reverse.

The solution proposed is for managers and senior developers to get ahead of this shortage by foregoing the immediate yet shortlived productivity maximization offered by the agent-multiplied-senior structure in favor of longterm sustainability by deliberately facilitating experience fan-out to juniors.

The methodology proposed is based on a successful nuclear engineering apprenticeship program carried out on active service naval submarines.

view more: next ›

Septimaeus

0 post score
0 comment score
joined 3 years ago