naugtur's Avatar

naugtur

@naugtur.pl

Working on supply chain security for JS. LavaMoat and Endo contributor. meet.js Poland organizer. Node.js user since v0.8. Addicted to teaching. https://naugtur.pl

1,240
Followers
260
Following
2,918
Posts
12.04.2023
Joined
Posts Following

Latest posts by naugtur @naugtur.pl

In the context of securing software, the core imbalance with AI is:
When it's used in creating software we worry it might sometimes be wrong.
When it's used offensively we're in trouble if it sometimes gets it right.

06.03.2026 06:02 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

I hear what you did there

06.03.2026 05:51 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Periodic reminder: Meta's engineering culture 11 years ago.
The company was founded in 2004, so about midway between its founding and now.

www.bitdefender.com/en-us/blog/h...

05.03.2026 22:47 πŸ‘ 7 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Unearned Confidence: AI Security Reviewers Don't Really Get It - Checkmarx AI-based security reviewers can be great helpers. But the gap between the certainty they express in their findings and the reality of their current capabilities can lead to problems. Understanding…

LLM-based tools are probabilistic, require significant context to get meaningful results, and make important mistakes in analysis that can mislead users.

But there's real value available IF you understand the strengths and limitations and use them wisely. Learn more: buff.ly/a6yvxiJ

05.03.2026 22:08 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
Reverse Centaur Made for the Character Design Challenge group on Facebook, under the theme "centaurs". Pretty fun to do.

Well, there's also all of the reverse centaur conversation I enjoy. I'm interested in how humans can/should position themselves no matter what their attitude and willingness to use AI

pluralistic.net/2025/12/05/p...

www.flickr.com/photos/johan...

05.03.2026 22:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
The Pro-Human AI Declaration The Pro-Human AI Declaration

humanstatement.org obvious stuff, but good to have traction on these

05.03.2026 22:10 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

what the fuck

03.03.2026 10:38 πŸ‘ 240 πŸ” 65 πŸ’¬ 6 πŸ“Œ 0

Why capitalize only the I? πŸ˜›

03.03.2026 06:34 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

13 years later and the story of Aaron Swartz still fills me with anger and sadness

02.03.2026 11:04 πŸ‘ 196 πŸ” 57 πŸ’¬ 0 πŸ“Œ 4

Across social media and the Al industry, people immediately began to challenge Altman's claim.
Why, they asked, would the Pentagon suddenly agree to the red lines that it had said β€” in no uncertain terms β€” that it would never do so?
The answer, sources told The Verge, is that the Pentagon didn't budge. OpenAl agreed to follow laws that have allowed for mass surveillance in the past, while insisting they protect its red lines.
One source familiar with the Pentagon's negotiations with Al companies confirmed that OpenAl's deal is much softer than the one Anthropic was pushing for, thanks largely to three words: "any lawful use." In negotiations, the person said, the Pentagon wouldn't back down on its desire to collect and analyze bulk data on Americans. If you look line-by-line at the OpenAl terms, the source said, every aspect of it boils down to: If it's technically legal, then the US military can use OpenAl's technology to carry it out. And over the past decades, the US government has stretched the definition of
"technically legal" to cover sweeping mass surveillance programs - and more.

Across social media and the Al industry, people immediately began to challenge Altman's claim. Why, they asked, would the Pentagon suddenly agree to the red lines that it had said β€” in no uncertain terms β€” that it would never do so? The answer, sources told The Verge, is that the Pentagon didn't budge. OpenAl agreed to follow laws that have allowed for mass surveillance in the past, while insisting they protect its red lines. One source familiar with the Pentagon's negotiations with Al companies confirmed that OpenAl's deal is much softer than the one Anthropic was pushing for, thanks largely to three words: "any lawful use." In negotiations, the person said, the Pentagon wouldn't back down on its desire to collect and analyze bulk data on Americans. If you look line-by-line at the OpenAl terms, the source said, every aspect of it boils down to: If it's technically legal, then the US military can use OpenAl's technology to carry it out. And over the past decades, the US government has stretched the definition of "technically legal" to cover sweeping mass surveillance programs - and more.

Sam Altman got played and spun it like a win - @haydenfield.bsky.social has the scoop from a weekend’s worth of reporting from inside the Pentagon AI negotiations. www.theverge.com/ai-artificia...

02.03.2026 14:30 πŸ‘ 275 πŸ” 102 πŸ’¬ 16 πŸ“Œ 5

You can invent, you can decide and you can be accountable and learn from mistakes. You can be responsible.

02.03.2026 17:17 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

If I wanted to go more quantitative and see levels or types split, can I do it? Can you do it? πŸ˜…

02.03.2026 17:06 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

I miss learning about weird situations from your life, but this is also good 😁

02.03.2026 15:27 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
A clean looking graphic with sharp lines and crisp colour

A clean looking graphic with sharp lines and crisp colour

The same graphic, but muddy and blocky. The previously sharp lines are blurry.

The same graphic, but muddy and blocky. The previously sharp lines are blurry.

I think it's often overlooked that AVIF is also really good at flat colour & sharp edges.

Don't go straight for a lossless format just because it's the kind of image that would look bad as a JPEG.

Here's an 11kb image as an AVIF, vs JPEG XL.

02.03.2026 14:08 πŸ‘ 143 πŸ” 22 πŸ’¬ 9 πŸ“Œ 1

Same

02.03.2026 15:26 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Theoretically/legally that means a y IP you produce in that time belongs to the company under some of the popular contracts and anything that happens to you is under work insurance.

But these are all silly problems in comparison

02.03.2026 15:22 πŸ‘ 2 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

Not cool!

02.03.2026 15:16 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

It doesn’t matter why they say there are layoffs. Unless a CEO is taking a 99% pay cut, the reason is greed.

02.03.2026 14:50 πŸ‘ 8 πŸ” 3 πŸ’¬ 1 πŸ“Œ 0
Post image

Our Schedule is out - get to see 35+ talks from speakers such as rich harris @@carlyrichmond.bsky.social and naugtur - Find out all the latest trends in #JavaScript, Fullstack and AI

Register now - london.cityjsconf.org

01.03.2026 13:36 πŸ‘ 2 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

Next month we got our #CityJSLondon with 35+ exceptional speakers such as Faris Aziz
@Nikkitaftw and @nic_o_martin - lots to learn from our speakers #workshops and #talks, find all the latest trends and get ready for the new AI Age!

Register now
london.cityjsconf.org

02.03.2026 10:52 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0

Agree, but with Deezer :P

02.03.2026 11:03 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

grooveshark almost got there before it was destroyed

02.03.2026 11:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Next month we got our #CityJSLondon with 35+ exceptional speakers such as Faris Aziz @Nikkitaftw and @nic_o_martin - lots to learn from our speakers #workshops and #talks, find all the latest trends and get ready for the new AI Age!

Register now
london.cityjsconf.org

02.03.2026 10:00 πŸ‘ 1 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
New alternatives to innerHTML getHTML, setHTML, setHTMLUnsafe, declarative shadow DOM and sanitization

New alternatives to innerHTML (setHTML) by @ollie-williams.bsky.social

02.03.2026 10:01 πŸ‘ 24 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0

maybe trains are in the hobby category

02.03.2026 10:06 πŸ‘ 4 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image
02.03.2026 03:09 πŸ‘ 743 πŸ” 161 πŸ’¬ 68 πŸ“Œ 187
Post image
28.02.2026 15:02 πŸ‘ 19693 πŸ” 6336 πŸ’¬ 579 πŸ“Œ 289

Getting fewer but higher quality proposals than usual was also helpful

28.02.2026 13:33 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
meet.js Summit 2026 - 15th Anniversary Join us for meet.js Summit 2026, celebrating our 15th anniversary with the AI Devs Edition.

I checked one more thing off my bucket list.

Did it way later than I should, but I gave every CFP proposal author at least two sentences of individual feedback. I've organized a bunch of conferences and always wanted to do it, but didn't find time to go individual.

summit.meetjs.pl

28.02.2026 13:33 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0