green text connoisseur | master proompter | oss/acc

Joined November 2022
28 Photos and videos
Lendrick Kumar retweeted
Today I was installing Hermes for someone and got stuck due to peer dependency issues with lite llm. Now I know why. Rotate your keys, heralds! x.com/i/status/2036487306585…

Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
1
2
6
689
Replying to @bvlldhist_alt
This is not QoL. This exists only because our infra is so shit no one wants to go outside. I would rather go to my coffee shop on some footpaths, see some trees and sunlight, while not breathing in poison. Now that’s QoL.
1
3
76
When you are boasting about this, think of the delivery partners' QoL, to whom you have outsourced the misery of Indian roads.
33
Lendrick Kumar retweeted
We offered 5 people a Porsche 911 GT3 RS if they could get @WisprFlow to make a mistake It's the fastest and most accurate AI voice dictation app that's 3x more accurate than ChatGPT, Claude, or Siri. Today, we’re finally launching on Android. Download now: play.google.com/store/apps/d… As a part of the launch, we’re giving away 6 months of Wispr Flow Pro for free. Like, retweet and comment ‘Wispr Flow’ to get it. Enjoy. — Written with Wispr Flow
4,535
2,976
10,916
4,402,324
I am too high for these new captchas fuck this, touching grass
58
Lendrick Kumar retweeted
29 Oct 2024
My classmates had a reunion. 2 nights’ cruise in Goa. The cost was ₹40-50K. I was horrified. That’s about the cost of one of the cheaper week-long South Pacific cruises from Sydney. Indian tourism is pricing itself out of the market.
75
293
4,314
189,914
so much good music in this world only thing that makes me believe in god
3
103
Lendrick Kumar retweeted
2 Sep 2024
Regardless of the politics, an ordinary citizen walking up to the Prime Minister and telling him to 'fcuk off' with his socialite policies because they don't cater to his needs should be a goal for every democracy. Here, we can't even say that to a gram pradhan without being beaten by his minions. Until last decade so many murders used to happen in our and nearby villages during Panchayat elections that they had to ban the elections in our village after 2011-2012 I guess.
Trudeau just got castrated by a steel worker:
56
641
4,020
204,988
Chase and Status are coming to India but the dates don't work for me 😭😭😭
48
God is testing me today. Missed my connecting flight , spilt my drink at McD right after they cleaned for closing. Sleeping on the airport floor after having to pay out of pocket to go to an airport 3 hours from my original destination.
1
71
But it's all gonna be okay because as soon as I set foot in Thailand I am gonna beeline to the nearest weed dispo and get so lit I forget this day ever happend
1
67
Almost missed my flight because the Indian immigration officer couldn't understand why a 20 year old would be travelling solo or if I could afford it
1
1
77
Solo travel is not as socially accepted as I thought
65
Lendrick Kumar retweeted
3 Jun 2024
Being around ur parents is like damn im emotionally traumatized but im eating so good rn
271
40,451
256,393
7,918,800
Lendrick Kumar retweeted
McAfee would have LOVED Solana shitcoins, just imagine.
83
103
1,819
158,883
Who wants to be my French cofounder
Replying to @alexanderisorax
What is today's trend? AI! AI logos, AI chatbox, AI interior, AI tweet generator, AI SEO automatization tool, AI headshots, AI page generator etc. Take any successful AI product and just clone it. Then bring it to France.
1
3
119
we have reached the ai generated art level of captcha
2
107
Lendrick Kumar retweeted
Mr. Netanyahu, antisemitism is a vile and disgusting form of bigotry that has done unspeakable harm to millions. Do not insult the intelligence of the American people by attempting to distract us from the immoral and illegal war policies of your extremist and racist government.
6,163
32,023
108,841
6,857,638
is warp going to be the paypal mafia for e/acc?
1
2
98