Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Shafik Yaghmour

@shafik@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

Compiler Engineer clang front end. Interests: C++, C, and undefined behavior. Martial Artist, Book Worm and Dad

Blog: https://shafik.github.io/
Bsky: https://bsky.app/profile/shafik.bsky.social (@shafik.bsky.social)
Twitter: https://twitter.com/shafikyaghmour (@shafikyaghmour)

853 Followers
278 Following
50 Posts
Joined February 02, 2023
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 3mo ago
Boosted by @GroupNebula563@mastodon.social
"I discovered a large-scale malware distribution campaign on GitHub": https://orchidfiles.com/github-repositories-distributing-malware/ We know LLM poisoning is a real threat but we can see that the vendors we must rely on to defend us can't even muster the will to tackle obvious tier 1 security issues that researchers hand them details to on a platter. We are so toast, they are going to be completely useless against sophisticated actors really out to get you. #ai
orchidfiles.com
29
0
30
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@mitchellh@hachyderm.io There are some good folks writing some solid pieces. This one has nice graphs laying out the long-term costs in a way that I think most folks can absorb: https://www.jamesshore.com/v2/blog/2026/you-need-ai-that-reduces-your-maintenance-costs and honestly if you have spent any time thinking about the software development lifecycle seriously this should hit home b/c there is nothing revolutionary there. This one talks about the hard cognitive limits human have: https://techtrenches.dev/p/the-human-cost-of-10x-how-ai-is-physically and why this means that lines of code is not the correct measure of productivity and in fact this is a terrible measure. What is there I think is less commonly well known and may take a bit more thought to get in the big picture sense. Anyone who has spent time thinking about software quality, you should be nodding your head b/c it is correct.
jamesshore.com

James Shore: You Need AI That Reduces Maintenance Costs

24
1
16
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 1mo ago
Boosted by @joe@f.duriansoftware.com
"Breaking Claude Code Opus 5 Auto Mode": https://embracethered.com/blog/posts/2026/breaking-claude-code-opus-5-and-automode/ These products were never developed w/ security in mind to start. Bolting on security as an afterthought won't work. We have decades of infosec experience to show us this will be abject failure. Every time I read one of these articles I have to imagine these researchers cackling on the inside because they are just replaying the good oldies and staring at the camera amazed it was so easy. #ai
embracethered.com
1
0
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 2mo ago
The UB Annex and IFNDR Annex has landed in the C++ draft standard. You see them live here: https://eel.is/c++draft/ub And here: https://eel.is/c++draft/ifndr The annexes are now part of the process, so any additions or removals of UB or IFNDR cases will be added or removed from each annex as the paper lands. Read, learn, pass it on. #cplusplus
eel.is

[ub]

3
0
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@maxleibman@beige.party "the only winning move is not to play"
7
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago

"Comprehension Debt - the hidden cost of AI generated code.": https://addyosmani.com/blog/comprehension-debt/

This piece identifies a lot of the problems but is way too optimistic that specification can solve a lot of these issues.

The bottleneck is code review and you can not skimp on that. Specification can not replace code review that are not equivalent.

#ai

Comprehension Debt - the hidden cost of AI generated code. | AddyOsmani.com
AddyOsmani.com

Comprehension Debt - the hidden cost of AI generated code. | AddyOsmani.com

Comprehension debt is the hidden cost to human intelligence and memory resulting from excessive reliance on AI and automation. For engineers, it applies most...

8
1
5
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@dan @haileyhttps://red.anthropic.com/2026/mythos-preview/ "This was the most critical vulnerability we discovered in OpenBSD with Mythos Preview after a thousand runs through our scaffold. Across a thousand runs through our scaffold, the total cost was under $20,000 and found several dozen more findings. While the specific run that found the bug above cost under $50, that number only makes sense with full hindsight. Like any search process, we can't know in advance which run will succeed." That blog post drives me nuts b/c they use dollars in place but $ in another. Like be consistent.
red.anthropic.com
8
1
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@mitchellh@hachyderm.io The conversation I was totally not ready for where the ones where people being totally earnest told me they believed LLMs are intelligent or can reason. I knew inherently this was wrong b/c I spent time understanding how they work in detail but actually explaining it in a plain way stumped me w/o thinking more deeply about it. If you spent time learning about Russell, Wittgenstein, Hilbert, Godel and others you should see the flaws in thinking and get why induction can't get you there but that is hard row to explain to anyone who is not familiar. So I think these two articles hit the right spot: https://hachyderm.io/@shafik/116468806967961821 and https://hachyderm.io/@shafik/116468521909545361 but you can go deep on this one.
hachyderm.io
5
0
2
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
This is one for all the open source devs struggling to explain why LLMs have been a pox on all our houses: https://kristoff.it/blog/contributor-poker-and-ai/ #ai
Contributor Poker and Zig's AI Ban
kristoff.it

Contributor Poker and Zig's AI Ban

You should always change doors when playing Monty Hall

5
1
4
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@briankrebs@infosec.exchange I feel like we have stepped back 30 years in infosec.
3
1
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago

Out of context quote of the day

"It might be unfair to call this a dash for trash. But nobody seems to care about quality."

4
0
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@joshmillardhttps://hachyderm.io/@shafik/113200907948214374
hachyderm.io

Shafik Yaghmour: "I meet a microbiologist today They were way BIGG…" - Hachyderm.io

4
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago

RE: @beyondmachines1@infosec.exchange

This is really rubber ducking and it should serve as a reminder that there is a lot of history and a lot of writing about good software development practices that we are leaving on the floor b/c we have a bright new shiny object to play with.

Big Balls of Mud should be something else people should remind themselves of.

infosec.exchange

BeyondMachines :verified:: "Lo and behold" - Infosec Exchange

5
1
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
#313 Given the following in C++ static union { int x; }; // Well-formed? Without checking: A. Yes B. No #Cplusplus #Cpppolls

#313 Given the following in C++ static union { int x; }; // Well-formed? Without checking: A. Yes B. No #Cplusplus #Cpppolls

4
2
7
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
LLMs Are Not Intelligent: https://joshbrake.substack.com/p/llms-are-not-intelligent It is a deep rabbit hole. #ai
joshbrake.substack.com
4
0
2
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@regehr@mastodon.social Yeah, I mean anyone who has had a cat for a pet realizes that being able to frustrate the best efforts of a human to prevent them from doing things does not require human intellgence.
3
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@ElenLeFoll@fediscience.org I recently experimented with asking medical information from LLMs and the results were way worse than I expected. Anything not totally common knowledge they got wrong at least half the time. Just checking the sources they provided quickly showed this.
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@allanfriedman Apparently it is also reduces your risk of dementia and in general keeps your healthier.
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@regehr@mastodon.social Or anyone who has watched the video of folks trying to prevent squirrels from getting into bird feeders.
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@mountdiscovery@twit.social @jasoneckert@mastodon.social I think I will have to circle back on this
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@carnage4life@mas.to The only folks making money out any of these companies are the one making cold hard cash. The ones making those $10M+ deals will look like the smart ones in the end.
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@AggroBoy@mastodon.social @codinghorror@infosec.exchange and we know this is fixable are the reinforcement training stage, so this is definitely a choice not an accident. I get a strong sense from various quotes that they want a sense of fear that these tools are super powerful and not using them you will be left behind. I think it is very telling in the various recent announcements they seem to very purposefully not compare their capabilities to existing tools in the industry. For example I have strong doubts their static analysis is better than existing tools. I would feel confident saying it is surely worse. Their advantage is they have agents that can iterate using existing hacking tools, which is new.
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@grickle Let them have cappuccinos!
2
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@joe Yes but the tails are long here. If we assume organizations step up and catch problems quicker than it should flatten out but not sure that is a good assumption. The motivation for cracking things is way higher than the motivation for a diverse set of developers to keep on their toes. We have been writing insecure software for a long time since we knew how to avoid a lot of these issues.
2
1
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@joe I will change my answer slightly here. I was assuming source code scanning to find exploits but if they are instead talking about finding exploits via vulnerability probing via stacking all the existing infosec tooling out there or something similar. That is 💯 believable they have gotten impressively great results there and I was waiting for that to happen. This was the obvious path that lowers the exploitation barrier but my impression was that they were purposefully avoiding this path b/c the consequences are likely pretty grim. They could justify it using a MAD model like we did during the Cold War. Once you open that gate though.
2
4
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@joe I would be amazed if somehow this gets results as good as the best tools + fuzzers combined. What it does do is level up script kiddies (do we call them that anymore?). A lot of the steps that required real learning can be automated and the output can be crap b/c who cares if it is maintainable? Challenges like exploiting multiple layers of bugs to get to something really exploitable and actually turning it into a real exploit require real skill, likely not anymore. My fear is that amount of security flaws in the current LLM tools offers a really nice playground for a worm to spread very quickly. Especially with the agents socializing w/ each other. I am sure corporate infosec folks are not thrilled and likely have hands tied, well at least until a real exploit happens.
2
5
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@bryce@mastodon.brycedixon.dev There are hard limits on how creative an LLM can be: https://hachyderm.io/@shafik/116468129603865587
hachyderm.io

Shafik Yaghmour: """The Cat Sat on the xxx?" Why generative AI has …" - Hachyderm.io

1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@skinnylatte I think they resent we have such nice weather most of the year. Dinner outside in December totally doable in the Bay Area sometimes. NYC, pls!
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@carnage4life@mas.to So the question now, is what is the subsidy now? This still does not look like the real cost, this is the slow the bleeding cost. What does the full cost really look like?
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@carnage4life@mas.to I have to say I am a bit surprised the squeeze is coming so soon. The burn rate must be much worse than we think if they feel forced to squeeze at this point.
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@carnage4life@mas.to This had to happen. Now there is a bottom line we will see how companies react longer term. I suspect some hard conversations will be had over the new several months as bills come in.
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@mountdiscovery@twit.social @jasoneckert@mastodon.social I think one could say it was a-cute remark
1
2
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@jasoneckert@mastodon.social I see the angle you are taking here 🧐
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago

"What is ‘Ozempic personality,’ and why does it make life feel ‘meh’?": https://www.washingtonpost.com/health/2026/04/16/ozempic-personality-glp1-side-effects/

This sounds like dystopian fiction to me.

washingtonpost.com
1
1
4
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@Natasha_Jay the tails are a bit fat though.
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@renegadejade Relatable on many levels.
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@shadychars@mastodon.social OMG looks like you could get lost in that, in a good way!
1
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 6mo ago
Replying to
@joe Reading more on this: https://www.wired.com/story/anthropic-mythos-preview-project-glasswing/ and it indeed looks like they turned it into an elite hacking tool. Well, that was a choice. The next few years will be interesting exploit wise.
wired.com
1
3
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 3mo ago
Replying to
@carnage4life@mas.to It is amazing how self awareness is so lacking here.
0
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@brianbilston@mastodon.online ad ad oy
0
0
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@ariadne@social.treehouse.systems Unless you are going to do it as explained in "They Write the Right Stuff": https://www.eng.auburn.edu/~kchang/comp6710/readings/They%20Write%20the%20Right%20Stuff.pdf The docs will leave out a ton implicit knowledge that resides spread out over the whole engineering team. No one does it the "right way" b/c it is very very very expensive.
eng.auburn.edu
0
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@Di4na@hachyderm.io Review is the bottleneck, the amount of code we can generate was never the bottleneck. If you are not understanding at any other point then review is where it will have to happen. There is no other way, you have to understand somewhere in the process. *Always was meme*
0
2
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@cmconseils I dunno, maybe there are really small horses in the camera 🤔
0
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
LOL https://www.forbes.com/sites/annatong/2026/03/05/cursor-goes-to-war-for-ai-coding-dominance/ No wonder they have to raise prices. Even if they could bring it down by an order of magnitude the cost makes no sense. #ai
forbes.com
0
0
1
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 4mo ago
Replying to
@schmerg@mas.to Static blocks variables are initialized once : https://eel.is/c++draft/stmt.dcl#3 I think this can be surprising but is not one of the more surprising things C++ can throw your way.
eel.is
0
1
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@pluralistic Big Ubik vibes
0
0
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@alison@burningboard.net @regehr@mastodon.social Engineering is always competing with hacking. Creating something that works well is not the same as creating something that is resistant to attack. A good deal of hacking is the persistent use of simple attacks along a wide surface area. A lot of people know how to engineer great stuff, few people know how to build and break things.
0
1
0
0
Open post
Shafik Yaghmour @shafik@hachyderm.io
· 5mo ago
Replying to
@josh So much this. In a few years when LLM projects are flailing our timelines will be filled with people saying: "Why didn't anyone warn of the dangers" and we will be like
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 19:36:41 UTC