• 219 Posts
  • 1.69K Comments
Joined 4 years ago
cake
Cake day: March 2nd, 2023

help-circle






  • Security companies termed the incident the “GemStuffer campaign”, while also noting confusion at the purpose of the attack. The malicious packages uploaded were used to retrieve … data that was available to the public. One news outlet writes: “It’s not clear what exactly the end goals are, as the information appears to be publicly accessible anyway.”

    Wasting everyone’s time, scrapping agressively while disrupting online services, that’s on brand for LLMs.

    I wonder if RubyGem is now blocking LLM agents and scrappers, by technical means and by policy. It may be inconvenient for vibe coders while helping protect the service, so only positives.




  • while unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models⁠.

    So either they don’t track what goes in their training data, or they do but their LLM is unable to precisely credit sources. Maybe a bit of both. That’s convenient, this way they claim great discoveries without crediting all prior work they’re relying on.

    LLMs are a great plausible deniability generator. These allow one to plagiarize while saying with a straight face no one knows what source material the result are based on.