do you mean the machine which is connected through the victim's machine? if so, i should put this in a VM, run and see where it's sending/receiving requests from. i'll do that.
Yeah, exactly. If there's a C2 server, there's some protocol for communication between the C2 server and each victim node.
You can intentionally infect a machine with the malware but then watch the traffic between the victim node and the C2 server. If you get lucky, the C2 server assumes that the victim node is trusted and doesn't sanity check victim->server communication.
Note that this cranks up the danger quite a few notches, though it sounds like you know what you're doing.
Not directly the answer, the only weird part (albeit not LLM alike attribution) would the use of 'reach out', after the negative attitude towards corpo-speak.
"Contact", "call," "talk", "meet", etc. would be a lot better/normal/human words.
The answer is quite patently that, in this brave new world, people with noticeable writing skill will face that false cry on a regular basis from the literary lowest-common-denominator.
I keep getting people saying they think my posts are AI-generated because I use hyphens in sentences (not M-dashes though, I can never remember the compose key for it), and because I use the term "load bearing" in a pisstakey way - like for instance, "yet another instance of load-bearing idiocy by management".
I'm having trouble understanding where we disagree. It seems like you're arguing that she's correct because it was helpful for the mutual acquaintance to refer me to this vendor, which I agree it is.
My point is that the term "lead" implies that she's thinking about making the sale rather than serving me as her client. Do we disagree about the connotation of the word "lead?"
As a more extreme example, if you went to a doctor for an illness and they said, "Wow, I'm going to make so much money treating you," I imagine you'd find it off-putting even if the doctor would only earn the money because they're doing a useful thing by treating your illness.
Is your sentence supposed to be analogous? The difference between a great lead and a bad lead in that context would be sending a patient with a skin lesion to a dermatologist (great lead - “someone who will be happy with what I can do”) vs sending a patient with a brain tumor to a dermatologist (bad lead - “I can’t help this person”). In this context, a “great lead” is someone who has been appropriately prequalified so that both participants are going to benefit from the interaction.
Naturally the grievance writing style pre-supposes extractive malice “oh the dermatologist is happy because they’re going to make money off me” rather than the more mundane “oh the dermatologist is happy because they don’t have to spend this time telling me they can’t help me”.
In any case, far be it from me to tell you not to do this. As a content creator, you have certainly found writer-audience fit. It baffles me why, but this style is certainly popular on this website.
I think we disagree on the connotation of the word "lead."
To me, if someone describes me as a "lead," it implies that they are focused on making the sale rather than on anything else about the business relationship. I would also find it unsettling if a doctor told me that I was a "good lead" because I had a disease they treat.
Jargon is field-specific. In medicine you’d be a good referral (“I’m glad they sent you to me”) or an interesting case. The field does not use “lead” for that in the way that contemporary sales does. Discordant terminology is reasonable to be wary of.
Consider for the moment the two cases of an agent for a player or actor and a doctor. It’s normal for an agent to discuss commission and for a doctor to not, though both will make money off you participating. If you had an agent who said he’s just trying to get you the best deal and “don’t worry about money” that would also trigger red flags as much as a doctor discussing commission rates for referrals.
That doesn’t mean commissions are worse than undiscussed rates. Just that norm-violators are risky deal participants.
Given this discussion, I suspect the best interpretation of your post is not that it is grievance text. It is that unfamiliarity with the terminology of a field has resulted in transferring connotations from unrelated contexts.
To lighten the tone, I am reminded of a HN comment where someone said that “Khan Academy” was a terrible name because it naturally brings to mind a “con man”. Of course, this must have been natural because the two words are homophones in his accent (they are not so in mine). An example of connotation mistaken.
We should think about doctors that way. They are in business. Or if they aren't, they are employees of a business. The medical field is full of terminology and customs to disguise this.
I'm not trying to argue that art is sacred and we have to hold it up over everything else, but I am joking that there is still an implicit boundary where we don't use "content" to refer to things that we respect highly.
I think a lot of people that talk about "art" vs. "content" are talking about art vs. business, but I'm more arguing about big vs. small and aggregation vs. individuality.
It makes sense for YouTube and Twitter and Facebook to refer to everything on the Internet as "content" because there's so much variety and those platforms are trying to capture all of it. But I just realized it's silly for me, an individual author to refer to my work as "content" when I could just as easily say "book" or "blog posts."
I got all of that, I just found the David example to be distracting from and unrelated to the more interesting argument that you're making, which I do agree with, and which I think you summed it up neatly here:
> I just realized it's silly for me, an individual author to refer to my work as "content" when I could just as easily say "book" or "blog posts."
As regular reader of his blog, the David example worked for me because I felt revulsion for a second. I had to double check the URL to make sure I was reading the right blog. "When did he embrace the LinkedIn broetry?"
Sometimes when I'm thinking about a blog post, I fall in love with a joke I want to use, but then it constrains how I think about the topic. I still like the David example, but I'm too close to the post to have a balanced perspective, just having finished it today.
Paintings, sculptures, blog posts, HN comments, etc. are all examples of different things that can be reductively viewed as "content" by those who only want to exploit them for profit, just like the illustration shows. I don't think the article is saying that these things are all the same.
> I feel that all the terms mentioned are useful in specific contexts. Web traffic brings visitors to your resource. If they read your blog, they become readers. If they use your products, they become users. When someone buys something from you, they become a customer.
I'll respectfully disagree. I think those terms make sense if you're talking in general terms, but if you're an individual person talking about your work, they're generic catchall terms with better alternatives.
Like, in concrete terms, let's say I publish funny cartoons on my website and sell prints of those cartoons. It doesn't make sense for me to say "web traffic brings visitors to my resource." What traffic? What resource? It would be more meaningful to say, "Visitors find my website through Google search."
I don't really have anything against the existence of the catchall term "content." Like, I don't expect the CEO of YouTube to say, "music, short film, art, comedy, journalism, ..., creators" every time he talks about YouTube users. It makes sense from their perspective to bucket everything into "content."
The thing I found interesting was just that the language had crossed over to people where it doesn't make sense to bucket everything. If I'm a blogger, I can just say "blogger" and it's more meaningful than "content creator" but I think the people running small businesses or doing creative work have needlessly adopted the big bucket terminology of "content."
One of the things I find so disappointing about Kelley's behavior here is that he falsely accused Jarred Sumner of lying about fuzzing Bun, and then when Sumner showed evidence[0] that they've been fuzzing Bun for months, Kelley just silently edited his post[1] to walk back the accusation and never apologized or admitted he was wrong.
I commented on Mastodon[2] to point out to Kelley that it's dishonest to silently remove the accusation, as so many people were already talking about it, and it confuses the conversation if Kelley retroactively edits it, and he replied[3]:
> the false claim is in the bun blog post not mine. I only changed the text because it's easy to lazily argue against it. Please read more carefully. They are the ones being deceitful not me.
Loris Cro, Zig's VP of Community, gave a slightly clearer response[4]:
> Jarred's post has a section about what they "were already doing" to maintain their Zig codebase, which includes "24/7 fuzzing", which will make the average reader assume that the codebase has been fuzzed thoroughly, while in reality it has been for, what, 2 months before the rewrite?
Even then, I find it so bizarre that Loris thinks that if someone says, "We've been fuzzing Bun," and shows evidence of months of fuzzing, then that person is lying because "We've been fuzzing Bun" somehow implies something longer than two months.
The duration is irrelevant. If you say you've been fuzzing it and you've fixed bugs that your fuzzer found, then clearly you're fuzzing. The Zig team doesn't get to arbitrarily move the goalposts of what "fuzzing" means.
If Sumner says today, "We do X," then Kelley can say, "Nine months ago, Sumner did not do X," and both can be correct. What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.
Now you've misquoted me. Actual quote[1] is: "This appears to be an outright fabrication."
To quote yourself[2], "The honest thing to do is acknowledge that you were mistaken and apologize for the false accusation."
Are you going to do that for me now?
I don't expect you to, because I don't think you are being dishonest. I think you are earnestly trying to untangle the facts from two parties for whom you have no bias one way or the other, which is commendable.
Like you, I am an individual attempting to paint an accurate picture of reality for my readers.
Anthropic, on the other hand, is not an individual nor trying to be accurate. They are doing exactly as they are supposed to: maximizing value for shareholders. To do this, they need to make this rewrite appear successful, so they need to retcon this idea that they were doing good engineering practices in their zig codebase the whole time, including fuzzing, even though that is not the case.
> What Kelley can't do is say, "It's an outright fabrication that Sumner does X today," based on an observation from nine months ago.
I think it's clear that I presented it as a hypothetical dialog, not something you literally said. But I agree that the fairer way to present it would be to say, "Kelley can't say 'It appears to be an outright fabrication'," to match the original language in your blog post.
> I think you are earnestly trying to untangle the facts from two parties for whom you have no bias one way or the other, which is commendable.
Honestly, my bias is to support Zig. I personally like the Zig project and you as a person (this blog post notwithstanding) enough that I've contributed a small monthly financial amount for the last 2.5 years. You've never sucked up all my code and then tried to sell it back to me.
So, despite the fact that I have many reasons to favor you and Zig over Sumner and Anthropic, when I read both blog posts, the impression I walk away with is that your blog post is needlessly critical of Sumner as a person and that you made unsubstantiated accusations against him.
> To do this, they need to make this rewrite appear successful, so they need to retcon this idea that they were doing good engineering practices in their zig codebase the whole time, including fuzzing, even though that is not the case.
I don't get that from their blog post.
Both you and Loris seem to be saying that Sumner's "We've been fuzzing Bun" claim implies to everyone that they've been fuzzing it for a long time as much as they possibly can, but I think it just means what it says. They've been fuzzing it some, and some bugs fell out of it, not that they fuzzed it perfectly or followed every software engineering practice perfectly.
Dude just stop. This has been embarrassing and damaging enough to your reputation, you should just give it a rest for now. Your friends have made you self-aware enough to realize you have unprocessed emotions about this — process them. Best to get out of the comment section, and your head. The saying is if you’re explaining you’re losing. I’m not a fan of Bun or Jarred but of your Zig work. Stick to that, it’s where you serve the community best. In the future, just present the verifiable facts and you’ll be okay.
Yes, "their" refers to Bun's code, not the Zig compiler's code. Fuzzili is a fuzzing engine for JavaScript, so integrating it into Bun means that Fuzzili is fuzzing Bun.[0]
From the Bun post[1]
> We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore
From Andrew Kelley's post today[2]:
> The post claims they were fuzzing their Zig code, while during our calls the whole Bun team told us that they were not fuzzing anything. This appears to be an outright fabrication.
Sumner says that the Bun team has been fuzzing Bun's Zig code. Kelley says that this is a fabrication. Sumner showed proof that the Bun team has been fuzzing Bun's Zig code.
It looks like Kelley is incorrect and made an unfounded claim. The generous interpretation is that at the time Kelley and Sumner had a more collaborative relationship, Sumner was not fuzzing Bun's Zig code, but I'd expect Kelley to check if anything had changed since then before publicly accusing Sumner of lying in this week's Bun blog post.
AFAIU fuzzing code != fuzzing results. Through skimming it seems that integration tests were using fuzzing, but I would call it fuzzing the code itself.
From "product" perspective there's no difference, but in program-compiler perspective (and e.g. raising bugs about compiler), Fuzilli isn't fuzzing.
Per Wikipedia
> (then...) The program is then monitored for exceptions such as crashes, failing built-in code assertions, or potential memory leaks.
As for myself, I wouldn't use term fuzzing for integration testing such the one used by Fuzilla. I always caught it dynamic testing, scenario testing and in bigger cases property based tests. Fuzzing in my mind is reserved to a low-abstraction calls.
I don't understand what distinction you're trying to draw here. The very specific claim[0] in the Bun blog post that Kelley is calling a fabrication was:
> We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore
It does not look to be a fabrication, and is very explicit just about what they meant by fuzzing.
[0] I mean, that sentence doesn't actually match Kelley's paraphrase, but it is literally the only claim in the post related to what fuzzing was done on the Zig-based bun codebase. So it has to be what Kelley was referring to, and his paraphrase is as sloppy as his fact-checking.
For me, using Fuzzilli for testing a Zig code is not fuzzing, it's integration testing. If you're running code externally (e.g. wrapping binary) you cannot guarantee that side effect isn't caused by IO. I consider fuzzing a low level activity with many external variables removed.
Depending on where you are and how you communicate semantics matter more or less. It's very similar to compiler/transpiler. E.g. TypeScript "Compiler" is called compiler but in fact it's transpiler (it emits other high-level language as a result).
My point is that Kelley did not argue that what Bun does isn't really fuzzing. He wrote that the post's claim is a fabrication. But that claim is really specific, and to evaluate whether it is true it doesn't matter what Kelley's unstated definition of fuzzing is.
So an argument about definitions doesn't seem super valuable here.
I'm aware he edited it, but the original version isn't wrong, either. Just like Jarred's
> We fuzz Bun's runtime APIs 24/7 using Fuzzilli, the JavaScript engine fuzzer used by V8 & JavaScriptCore
isn't wrong, even though that was only being done for the last 5-6 months of Zig Bun, and not the previous 5 years when they were accruing all of their tech debt.
If I say, "I run 5 miles every day" and my old neighbor says, "I lived next door to him until 9 months ago, and he definitely doesn't run 5 miles a day," and then I show my GPS logs proving I've been running 5 miles a day for the last 9 months, I am correct and my ex-neighbor is incorrect.
If Sumner had said, "We've been fuzzing our code for years," then Kelley could justifiably say that's incorrect. But Sumner is saying that currently Bun fuzzes their code, which is true, so Kelley appears to be incorrect to claim it is a "fabrication."
That misses the mark here. Every other Kelley's claim has also been unsourced and not cited. I was able to guess that the integration might've simply been something which happened after they'd once not had it.
Given the lack of due diligence here, it seems Kelley's intentions weren't to be objective potrayal of truth but whatever was most damaging.
> For me, using Fuzzilli for testing a Zig code is not fuzzing, it's integration testing. If you're running code externally (e.g. wrapping binary) you cannot guarantee that side effect isn't caused by IO. I consider fuzzing a low level activity with many external variables removed.
I've never heard anyone restrict the definition of "fuzzing" in this way. If I repeatedly generate inputs to a program and then run the program with those inputs, that's fuzzing. It doesn't matter if there's IO or not.
> Depending on where you are and how you communicate semantics matter more or less. It's very similar to compiler/transpiler. E.g. TypeScript "Compiler" is called compiler but in fact it's transpiler (it emits other high-level language as a result).
It's still a compiler. It translates code from one language to another. You can argue whether we need the term "transpiler," but a source-to-source compiler is a compiler.
> You can argue whether we need the term "transpiler," but a source-to-source compiler is a compiler.
That's true today, but compiling was historically was defined as getting source code (human readable) to bytecode (machine runnable without an interpreter).
Some people didn't like that definition, and consequently the waters have been murkied. Just like with eg crypto. Or real time.
How historical? Compilers that have translated from a source language into C and have left the C-to-bytecode translation to another compiler have been around for a long time, as have compilers that translated from a source language to Assembly
I'm not sure what your point is, we all already acknowledged that people have been using the term differently, consequently changing the definition of the word over the years
The conversation amounts to “You should fuzz your code” “we’re already fuzzing the big external dependency, using their own fuzzing setup that they already use upstream”.
It’s not nothing, but clearly not what Andrew meant.
Based on timeline, it seems like both are true. They stopped communicating around the time of the acquisition per OP, which was announced December 3rd, and the PR integrating it is was merged the tail end of November.
This is what Jason Cohen did when he was getting WPEngine off the ground. He messaged 40 WordPress consultants on LinkedIn and offered to pay them higher than their hourly rate since it was a one-off task.[0]
Out of 40 messages, 38 replied and agreed to a phone call, and none of them actually asked for the money.
The Jason Cohen story gets read as "pay people and they'll talk to you," but the 38 out of 40 who declined the money tell you it was never about the money. What the offer really does is signal that you have costed their time before they have to, and that you are not planning to waste it.
I have run cold outbound to senior buyers for about twenty-five years, people who owe me nothing and get pitched daily.
Two things that I find move the reply rate more than anything else:
- First, a specific, bounded ask that names the twenty minutes and the exact question, so they can price the interaction in their head in one read. The article's "so short as to be unsummarizable" line is the same concept.
- Second, and this is the one people skip, evidence that you already know the answer to the easy version of your question, so the only thing left to ask them is the part that needs their judgement.
Offering to pay is a cruder version of both. It says the cost is real to you and you have thought about theirs.
The ones that land make the money almost incidental, the way Cohen's did. Make the ask cheap enough that saying yes costs them less than saying no.
Give them your answer to the easy version first, so the only thing left to ask is their judgement on the hard part. People will spend that on a problem they already feel daily, far sooner than they will do your thinking for you.
> Are reposts ok?
> If a story has not had significant attention in the last year or so, a small number of reposts is ok. Otherwise we bury reposts as duplicates.
https://news.ycombinator.com/newsfaq.html
While we're on the subject of following site guidelines:
> Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something.
https://news.ycombinator.com/newsguidelines.html
reply