This whole blog-post is impressive with the chain of vulnerabilities involved. However...
> OpenAI also paid us a $6,500 bounty.
?
That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.
This is like getting close to breaching the main monorepo at Google: google3.
If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.
The unfortunate truth of doing the right thing. Also, correct me if I'm wrong but there are too many bad things out there and companies can't give 1 million bounty for stuff like that. I'm sure they could but in the long run, wouldn't it be unsustainable?
Pay next to nothing every time, accept one financially-depressed researcher sale to blackhats causing tremendous business disruption every n years. Cheaper than honest payouts to [keep] researchers [honest]? Keep paying chump change. (Booo)
No more unsustainable than these companies already are by default. The bounty should have been proportionate to how important and pressing the findings were.
You are conflating "divide people" in the sense of "turn people against each other in order to divide and conquer" with "divide people" in the sense of "define groupings so that it is possible to have conversations about differing experiences". One is discussing a goal while the other is discussing a tool. Notably that tool does not necessarily need to be used for evil and often isn't.
Who are we talking about? What's their role? (What agent? What is the job to be done?)
What is the status quo? What's the problem with the status quo? What else has been tried? What's the consequence of not solving the problem? What more important problem do you need to work on that you're blocked because of this problem? What's the ideal solution? What's the current offer? Why would someone say no to any given solution? How have you addressed those problems?
> Instead you propose that this project should be funded by a for-profit company with it's own objectives in this world (that often starts with "more money"), again leading me to ask why?
You understand that Mozilla Firefox is not funded by the "community" and is completely funded by Google's money. Even donating does not fund the browser.
Mozilla knows that the open source "community" has no money, and cannot replace the amount of money Google is paying them and the employees who work on the browser.
The question is are you ready to fill the $600M a year black hole for Google to NOT pay Mozilla to fund Firefox?
It only makes sense for Servo to get funding from for-profit companies at this point, which is one of the only ways open source can work.
As much as I am a fan of Woz on his technical achievements, at least he knows that he fell off out of relevancy when he launched / shilled a crypto coin and now goes out to sell (mediocre) merch. I respect that grift.
DF (daringfireball) however, continues to be increasingly so irrelevant that they sometimes veer off into unrelated Apple news to increase their clicks on their blog, without knowing it.
In fact, it makes sense. Apple cares more about X than they do about DF. Not even Apple cares about DF anymore ever since they didn't invite the author over to the HQ.
> they sometimes veer off into unrelated Apple news...
Gruber has always done that. Years ago I made a Chrome extension to filter out all of his detours into baseball, James Bond, politics, and I can't remember if I let the Kubrick stuff stay in or not.
Ultimately I just stopped using Macs, so the blog was no longer relevant to me. Mark Gurman seems to have taken over the role of Apple whisperer anyway.
I didn't know people read him regularly. All i know about him is he made markdown and then cried when people tried to standardize it because it was underspecified.
Stopped reading DF ever since his unhinged posts mocking the war crimes being committed in Palestine at the hands of Israel.
"F*k around and find out" he quote tweeted a news article that talked about how phone and internet services were cut out in Gaza as armed Israeli occupational forces entered Gaza.
First of all, this is a pre-1.0 release that requires a nightly Rust compiler (if you choose the SIMT track with cuda-oxide) so that one is going to be unstable software.
Secondly, When an issue occurs with a kernel or you want to write your own custom kernel in Rust, now we need to diagnose if the problem came from either cuda-oxide (SIMT), Rust's side, CUDA or Tile (If you decide to choose the Tile track).
Another dependency into the list and course everything is open source except CUDA itself. So any issue that happens on the CUDA level, you are forced to wait for them to fix it.
> OpenAI also paid us a $6,500 bounty.
?
That amount for this payout is beyond pathetic for a near $1.2T company, who just got themselves breached with a complete potential source code leak.
This is like getting close to breaching the main monorepo at Google: google3.
If this was on the black market and the leak included unreleased models and training material, it would easily be worth tens of millions. Even reporting crypto smart contract flaw pay way more than that on average of $100k - $10M.
Come on.
reply