Many years ago, when I was a PC repair tech, software that would behave like this was generally considered to be malware. Seems a little ironic that they're McAfee ads.
Not really surprised though. That's just how the Windows ecosystem is. I've never seen any other OS constantly support so much weird advertising bullshit all the time.
It's also possible to reduce perceived noise with some blade spacing tricks. I remember reading about how Apple designed the MacBook fan blades to seem really quiet under normal load. It was pretty interesting to read. I'm too lazy to find a link, but it should be easy to find with a quick search, if interested.
There are a LOT of different kinds of ammunition out there. I suppose if they get to choose what kind, they could opt for subsonic ammo (the kind that people usually use with suppressors). Otherwise, if it's randomly selected or something, then there's a pretty good chance that it'll break the sound barrier.
not creds that give access to the production system
...Isn't that what we're talking about though? Or did I misunderstand the OP?
Regardless, I'll just clarify anyway: Developers should not have a plaintext .env that can be used to drop (or risk in any other way) production data.
A practice like that is only as strong as the "weakest" member of the team – "Weakest" could mean the person who is the least careful, or least experienced, or least secure work computer/practices, etc. Scale up to 1,000+ engineers and the chances of disaster (data loss, leaks, etc.) greatly increase. That's just the human factor. Add LLMs into the mix and it's almost guaranteed.
Of course it's better than hard coded, but still pretty bad to store production creds locally in plaintext — if at all.
In the uncommon event that I need production creds, it's a manual human chore by design. Normal development/experimentation should almost never connect to prod environments. That was generally a bad practice long before AI agents existed.
Anyone know if this affects GrapheneOS users? I can install GrapheneOS like 50x faster than it would take to understand what I'm legally binding myself to by signing the petition.
I genuinely appreciate the cause, but to sign this, I have to provide PII, agree to their terms of service and privacy policy, and get automatically opted-in to their mailing list that I'll have to unsubscribe from later.
So to petition against this shitty tech stuff, I have to go through this other shitty tech stuff. It sucks how normalized this all has become.
I wasn't charged any high-demand surcharge though. I probably wouldn't have ordered it if I had to pay one of those.
I don't think my area will have high demand for Starlink anyway. Even their fastest options are slow. There are options for like 5-10x the speed around the same price in my area. The only downside: There's like a 50% chance of lightning frying my modem each year, and it takes like a week to get a tech on site.
Starlink is a great backup connection. It's cheap to just keep in standby mode (~$15/month, IIRC). An unexpected, heavy surcharge might be a deal breaker though
I also almost never play games, but when I do, they're very cheap. I recently got into Subnautica for like $7, so I have no problem paying that for a download.
I'd much rather have a physical copy for a game that's like $80, but I don't think I'll ever buy an $80 game
This is especially creepy right after watching a video about a cult that behaves similarly if you upset them.
(The cult is called AllatRa, btw. Very interesting rabbit hole)
My servers require manual unlock via SSH at boot. It has been great for years.
I'd try to return it to the owner, which will allow me to forget the whole situation eventually.
If I kept it, I would never forget that I did that. For some reason, things like that stick around in my brain for decades.
I've lived my entire life so far without that person's money, so I'll continue to be fine without it.
Yep, CAD and house building are still human jobs, for now.
Maybe
...this assumes that no one will ever connect LLMs to machinery, or generate code to run machinery (gcode, for example)?
Do it
Many years ago, when I was a PC repair tech, software that would behave like this was generally considered to be malware. Seems a little ironic that they're McAfee ads.
Not really surprised though. That's just how the Windows ecosystem is. I've never seen any other OS constantly support so much weird advertising bullshit all the time.
It's also possible to reduce perceived noise with some blade spacing tricks. I remember reading about how Apple designed the MacBook fan blades to seem really quiet under normal load. It was pretty interesting to read. I'm too lazy to find a link, but it should be easy to find with a quick search, if interested.
There are a LOT of different kinds of ammunition out there. I suppose if they get to choose what kind, they could opt for subsonic ammo (the kind that people usually use with suppressors). Otherwise, if it's randomly selected or something, then there's a pretty good chance that it'll break the sound barrier.
...Isn't that what we're talking about though? Or did I misunderstand the OP?
Regardless, I'll just clarify anyway: Developers should not have a plaintext
.envthat can be used to drop (or risk in any other way) production data.A practice like that is only as strong as the "weakest" member of the team – "Weakest" could mean the person who is the least careful, or least experienced, or least secure work computer/practices, etc. Scale up to 1,000+ engineers and the chances of disaster (data loss, leaks, etc.) greatly increase. That's just the human factor. Add LLMs into the mix and it's almost guaranteed.
Of course it's better than hard coded, but still pretty bad to store production creds locally in plaintext — if at all.
In the uncommon event that I need production creds, it's a manual human chore by design. Normal development/experimentation should almost never connect to prod environments. That was generally a bad practice long before AI agents existed.
Production creds in
.env? ...Why?Anyone know if this affects GrapheneOS users? I can install GrapheneOS like 50x faster than it would take to understand what I'm legally binding myself to by signing the petition.
I genuinely appreciate the cause, but to sign this, I have to provide PII, agree to their terms of service and privacy policy, and get automatically opted-in to their mailing list that I'll have to unsubscribe from later.
So to petition against this shitty tech stuff, I have to go through this other shitty tech stuff. It sucks how normalized this all has become.
Ah great. My Starlink hardware just arrived.
I wasn't charged any high-demand surcharge though. I probably wouldn't have ordered it if I had to pay one of those.
I don't think my area will have high demand for Starlink anyway. Even their fastest options are slow. There are options for like 5-10x the speed around the same price in my area. The only downside: There's like a 50% chance of lightning frying my modem each year, and it takes like a week to get a tech on site.
Starlink is a great backup connection. It's cheap to just keep in standby mode (~$15/month, IIRC). An unexpected, heavy surcharge might be a deal breaker though
American here. I get them in my brick house.
(Though it's a big country that spans many different climates and biomes, so the experiences of the few do not represent the experiences of the many)
I also almost never play games, but when I do, they're very cheap. I recently got into Subnautica for like $7, so I have no problem paying that for a download.
I'd much rather have a physical copy for a game that's like $80, but I don't think I'll ever buy an $80 game
I think I might officially be old now. I don't know what the bottom left two are and I have no desire to google them.