jj4211

joined 3 years ago
[–] jj4211@lemmy.world 2 points 23 hours ago* (last edited 23 hours ago)

Have to dig into the nuance of this specific scenario.

A new memory vendor would be a huge capital expense, and investors are generally a bit apprehensive about that.

Further, it would be years before they could theoretically roll out product, a delay that investors would need to be awfully patient for under the best of circumstances. Further, we went through this dance in recent history, people thinking that the chip industry needed huge advancement and expansion of supply, only for demand to subside to normal before any of that expansion could even start.

And the stated payoff? Lower margin product than competition. Not exactly exciting to tell your investors your whole game plan is to make less money than your competition.

Then there's the reality that this is not an innate direct demand of memory for the sake of memory, it is intrinsically linked to these big AI companies, leading to the big question: Is this a bubble that has a risk of popping? If so, then the market will go poof before you have a single item shipped.

Even if broadly, you think the AI is viable, if any one company, especially OpenAI, gets left behind, the memory market could collapse. If not for Sam Altman's very specific purchasing commitments, the memory pressure would probably be much more modest.

Ok, fine, you are a ride or die believer in the durability of the AI boom and that every company is going to win. However, even if the AI companies do very well, what's to say they will still have the same appetite for hardware by the time this new enterprise gets going? A pivot from aggressive training to exploiting more what they have done, or some breakthrough that dramatically takes down their bloated memory requirements. If you believe in the AI boom, then just directly investing in the AI companies is the safer bet.

At the end of the day, an investor has a choice between being confident in the AI boom and investing directly in the AI companies, or being a bit less confident and investing in the memory vendors that are making bank now with a weaker, but still viable post-pop story. If you aren't comfortable directly investing in the AI companies now, then you almost certainly aren't comfortable with a long shot that only benefits if the AI boom keeps going exactly the way it has been going.

Yes, effort is underway to do this in China, but it's more about supply chain sovereignty than free market interests. It may have similar benefits, but here the free market is unlikely to be the impetus for increased supply in this scenario.

[–] jj4211@lemmy.world 2 points 1 day ago

SemVer isn't bad, but it's kind of pointless in the browsers. The value in SemVer is if you realistically promise to take bumping that first number seriously. Implying you take backwards compatibility seriously, and bugfixes seriously enough to keep patching an 'old' version. If you just maniacally bump the 'backwards incompatible change' number and never bother to revisit old releases, then I don't really care about the SemVer.

Of course, I also don't necessarily care about the CalVer either if there's update notification in play, the browsers will aggressively let you know you need an update. However if update notification isn't working or otherwise isn't in play, then CalVer can at least make you think "24.7... that seems like it might be old, maybe I should look for updates". In Windows world the CalVer has been informative as the system or corporate IT screw up has frozen a device at 22H2 and trigger some manual effort to figure out/fix whyever the hell the system won't go to new functional levels.

[–] jj4211@lemmy.world 13 points 1 day ago (4 children)

By definition, SemVer is supposed to have meaning to end users. If you see the third number increase, no worries, it's just bugfixes.

If you see the second number increase, well, in theory no worries, it's just cool new features but doesn't break anything you were doing, whatever you were doing should keep on working as always, and you can explore the new features at your leisure.

The first number changes: beware, something you may be used to can change/go away so it's not necessarily a slam dunk to update that.

The problem is that many projects just call it SemVer when they just play with arbitrary numbers. I'll call it "Marketing Versioning".

[–] jj4211@lemmy.world 21 points 1 day ago (1 children)

That's information superhighway thank you very much.

[–] jj4211@lemmy.world 24 points 1 day ago

Like the comment said, half.

[–] jj4211@lemmy.world 1 points 1 day ago

Maybe I just don't get it, but I just don't see there being anything vaguely inspiring of that sort of chemistry between the caracters of that specific show. Other duos in other shows, ok, but Sherlock just seemed so far from that dynamic.

[–] jj4211@lemmy.world 3 points 1 day ago

I feel like you could have just rolled with the clarification that the comment referred to all fan-shipping. Alternate is a perfectly reasonable word for "non canon"

Your initial reaction was perfectly understandable, and and relief at the clarification would have been great. Just seems unfortunate to get weird about seeming put out by "alternate" as a way to say "non canon".

[–] jj4211@lemmy.world 8 points 1 day ago* (last edited 1 day ago) (1 children)

Probably not even that.

For example: https://nvd.nist.gov/vuln/detail/cve-2026-43073

The short of it is they declared the name of a function to be a vulnerability, because some developers were confused by the name and used it when they shouldn't.

A fine critique of things, but the CVE is considered closed by merely renaming the function, and downstream misuses were considered separate issues.

A "vulnerability" fixed by:

-SYM_FUNC_START(__copy_user_nocache)
+SYM_FUNC_START(copy_to_nontemporal)
[–] jj4211@lemmy.world 2 points 2 days ago

I saw a headline where one of the big AI people said AI could do everything better than a human... Except make decisions. So the "executive" class is the only class that is "fine" by the logic.

I don't think they half the self awareness to realize they are in fact frequently pretty pointless even ignoring AI.

[–] jj4211@lemmy.world 8 points 2 days ago

Curl guy has written about a couple of these stupid CVEs, for example: https://daniel.haxx.se/blog/2023/09/05/bogus-cve-follow-ups/

One I recall was that if you asked curl to write out c code example of libcurl usage, you could get it to write out arbitrary code of your choosing. Note that this required you to have write permission and curl and then with your malicious c code, you then had to compile it and make it executable and run it yourself. So a very roundabout way to use curl as a text editor, and they considered it an arbitrary code execution issue, despite not actually executing the code.

[–] jj4211@lemmy.world 11 points 2 days ago (1 children)

Yeah, CVEs are usually nothing when you get down to understanding, especially kernel CVEs, which almost always declares a CVE for almost any bug, because it is easier that trying to think if it is a security issue or not and basically just assume it could be.

Huge pain as in my work we have a security policy where any unpatched CVEs that cannot be updated away must have a fairly significant writeup delving into the nuance of the CVE and what mitigation has been applied or a rationalization of why it isn't a risk and by policy we have to second guess every CVE assessment from our vendor, who we explicitly pay to triage and fix this stuff so we don't have to... They used to at least allow us a pass on "low severity" (that's still pretty flawed), but they decided that didn't sound "tough" enough and now every single one must have an answer. So every month a few people have to spend a few days just reading tons of CVEs that are not yet (and frequently never will be) patched by vendor and rationalize it away for the security team. Sometimes the security team will get odd and demand we build our own from upstream (most recently, vim of all things we were mandated to build from source).

[–] jj4211@lemmy.world 3 points 3 days ago* (last edited 3 days ago)

The content on Internet will invariably biased towards the novelty. Between that bias and enormous marketing spin and the most self important people gravitating towards it, it's an expected reality. One that will be applicable to some scenarios.

Content saying that for some situations, the existing methods remain best isn't going to light the world on fire. Also, tech folks tend to be more shy about "not getting" a seemingly great new tech.

In terms of how much it applies to an individual situation, it's too nuanced to really make a universal judgement. But in my local circle where I can grasp the nuance, the teams that have gone all in on deeply agentic are teams that already were kind of crappy.

view more: next ›