• 0 Posts
  • 397 Comments
Joined 7 years ago
cake
Cake day: August 24th, 2019

help-circle
  • What I mean is the best you can hope for is to minimize the damage done to yourself. sure the nazis can just make up whatever charge and condemn you to whatever they want. But the Filton 24 trial showed that to date, it wasn’t always a slam dunk. The fact that the prosecution leaked selected bits of evidence footage helped shift the jury and even the case.

    this is also why people have got to stop filming everything btw. Filming ought to be strategic; it’s a tool, not a ritual. Basically the best you can do is limit what they can get on you, and make it difficult for them (and it might also protect your comrades since they look for connections). Same reason I encrypt my hard drives; Al Capone was done in for tax evasion, not for the murdering and killing. If they want to compel me to surrender my decryption key, it still affords me some time to think about it.

    Of course a VPN alone is not going to save anyone, we should make that clear. If you have a VPN but still connect to a google account to do google searches with, police will just ask for your search history from google directly, they don’t need to decrypt your hard drive to access it.

    Browsers also fingerprint you, and there are add-ons and even browsers such as Librewolf to fake your fingerprint, but I’m not sure how secure you truly are after it.


  • Where’s the evidence for that? Now YOU’RE moralizing, what are you doing to help ppl understand that they can keep themselves safe by not paying with a credit card? "personaly-responsibility"ing is uuuuuh, yeah, not the best framework.

    I’m not moralizing. You can pay for mullvad with a cash envelope with no return address, they explain this procedure on their website and it’s in fact one of the main reasons you would want mullvad.

    Give me the evidence of this, not just words. Was there ever an instance of them being under judicial pressure? (which is what most corps break down under. i think i remember reading something about the telegram or signal ceo refusing to hand in its users private data.)

    In 2023 swedish police raided the mullvad HQ, they wanted to seize a server for some customer’s data. The employees explained how their servers operate (no-logs and ram-only servers), and police left empty-handed. Even if they had seized the server there would have been nothing on it to tie the customer to the mass of traffic, unless the customer used something such as an email address or a credit card payment to mullvad. Only weak link is if police monitors your devices and finds your mullvad account ID, but that wouldn’t be the fault of the VPN.

    What other VPN provider do you propose we use? Which one gets your seal of recommendation? Everyone in this business in the imperial core is a chud, because marxists are a tiny minority. The only other option if you want to remain morally pure is to not use the internet at all, which is valid, but if you have a bank account, go grocery shopping, buy stuff online, or work for literally any company, you participate in the system that perpetuates these chuds. Your boss also bankrolls far-right shitheads, he just doesn’t say it.

    As long as mullvad’s service remains the same, which is definitely a question but not one that has been brought up, because all that has been brought up has been “cancel mullvad immediately”, then what exactly is “my” responsibility in this? that circus party works on 5M SEK, meanwhile the Moderate Party, the biggest right-wing party in Sweden - and also in government - made 140M SEK in 2024, with 100M coming from the State itself as it pays elected parties/officials. That’s not even talking about my actual national parties that have way worse politics than these Moderates do. We’re not gonna defeat fascism with the power of our wallets and individual actions.


  • They hand over data to the authorities like it’s candy at Halloween. They don’t really have a choice to cooperate, but the workaround is to simply not collect all that data or collect as little of it as possible so that there is nothing to hand over.

    Some stuff like metadata (such as when you send the email and to whom) will always remain in cleartext, Proton has it and hands it over too. It’s a problem with email, though all chat platforms that I know of haven’t really found a way around encrypting metadata.

    This also means when registering on a service you need to give them as little info about yourself as possible. Like I said, using a VPN doesn’t mean you can say whatever on the internet without repercussions. There was a case where proton handed the authorities the recovery email to the user’s proton account. (edit: meaning, keep your proton profile as separate from anything else you do as much as possible. Don’t link it to anything about yourself)

    The problem with tuta is they hand over inventory data (banking info, credit card payment data etc), real-time metadata, even the entire emails, encrypted or not.

    Neither tuta nor proton have fully sourced their code so people can’t audit it.

    Ultimately it’s a company in the imperial core, in Germany of all places lol. Proton Mullvad and Signal have the same problem - they want privacy but they set it up right in the belly of the beast.

    Email in general is just not meant to be private, it’s tech from before they even had to worry about privacy or spam.

    There are more specific issues, their severity depending on how important this is to you, but:

    • tuta relies on Amazon Web Services for its DNS… odd
    • encryption is only possible between tuta users, as mentioned
    • they restrict access from the tor network (tor itself is not without its controversy lol)

    • corporations we buy from every day do the same shit and worse. Proton fundraised for the (US) Congress outfit Freedom House.
    • 5 million SEK sounds like a lot until you realize it’s 500k USD, not 5 million USD. I would still love half a million to do communist stuff with lol, but it’s not 5 million dollars.
    • mullvad has no idea who I am and which customer of theirs I am. If you pay for your VPN with a credit card you’re a chump.
    • they are also the only vpn with a proven track record of not leaking customer info, because they don’t have it.
    • this is a tiny no-name party that he’s supporting. At least for now - in 10 years it could be an AfD situation. Current perspective is euro govs are going to ban VPNs faster than this party will win an election.
    • the other co-founder distanced himself from that donation, at least publicly. Who knows if something will be dug up on him too later.
    • europe is fash central, and there’s also a LOT of fascists in software, including open software! (and just terrible politics in general)

    Important news and absolutely worth being aired out, but I don’t see anything that will do anything for me except be able to tell myself that I’m morally pure. Like I disagree with “Even if you’re comfortable with funding this” (I know you just crossposted OP) - I’m not funding anything. Let’s not do “vote with your wallet” politics in a communist space; Mullvad’s founder is funding this, not me.

    Proton is not trustworthy, tutanota is not trustworthy, there is no such thing as a private internet. There is only harm reduction so that when the fascist state comes for you, they find very little info to convict you with. At this point if you really want to be private not using the Internet is your only option. Being on a VPN is not an invitation that you can do whatever without legal repercussions.

    You can rent a Virtual Private Server and host your own VPN on it, but that also won’t hide you, because all requests you make will be coming from the VPS, and you’re the only person on it. I looked into it when deciding on a VPN, and it doesn’t seem to be an option (unless you live in a place where internet is restricted, in which case you are not looking for anonymity but simply bypassing restrictions).

    If there’s ever something better than mullvad that comes along I’ll switch. In the meantime keep an eye on the situation.

    Also switch away from Google search because they save every search you make whether you use a VPN or not.


  • It’s always the same story with the west when news of chinese tech hits us.

    First it’s “they’ll need at least ten years to catch up! By then we’ll be soaring a century ahead!”

    then “well okay they made a huge leap earlier than expected, but it’s not actually good. they still have this or that bottleneck to close. I don’t see them doing it any time soon, it took us 50 years to do it.”

    finally “oh, it’s only been 2 years and they’re already at our level. well um, chinese quality! ban imports! taiwan!”



  • From what I understand it makes the model lighter overall, thus you could fit a bigger param model on the same amount of Vram. It would also make generation faster in terms of tokens/sec. Layers get loaded into vram and are part of the model, and basically a loop goes deeper and deeper into each layer to generate each token. At each layer, it gets refined a little more, and you do this over and over again. Bigger param models have more layers.

    You unfortunately can’t apply the fix in the .safetensors or .gguf file, the model curators need to bake it in





  • Dump the source code into a folder on your machine, cd to it, then open mimo/opencode (it opens in the folder you are currently in terminal). In plan mode (tab to switch to it) tell it exactly what you want, e.g. “this is a dead android app, I want to add the following features to it: 1. 2. 3.” (use ctrl+J to line break, I don’t think it changes anything for the LLM but it’s easier on our eyes lol). Initial prompts are usually very long, you can really fill it in.

    If you only have the apk you can tell it that as well, “what do I need to do to add these features” and it will figure out your options. It’s scarily fast at first but you get used to it. It will guide you through a plan that you can refine, brainstorm, etc and when you’re ready, switch to compose with tab and say something like “ready to implement what we planned” (or “okay, let’s do it” if you want to sound cool).

    Careful: mimocode and opencode has no permission gates out of the box, meaning it will start running commands and tools without asking you. You only get asked for permission if it tries to do something outside of the working directory. On opencode I have a json file that gates some commands (anything that isn’t purely read-only needs to ask me for confirmation), but I haven’t found where to put it yet on mimo.

    json code
    {
    "$schema": "https://opencode.ai/config.json",
      "permission": {
        "*": "ask",
        "read": "allow",
        "glob": "allow",
        "grep": "allow",
        "list": "allow",
        "lsp": "allow",
        "repo_overview": "allow",
        "skill": "allow",
        "external_directory": "allow",
        "todowrite": "allow",
        "bash": {
          "*": "ask",
          "tutor init":"deny",
          "tutor *": "allow",
          "ls *": "allow",
          "cat *": "allow",
          "head *": "allow",
          "tail *": "allow",
          "wc *": "allow",
          "nl *": "allow",
          "rg *": "allow",
          "grep *": "allow",
          "file *": "allow",
          "stat *": "allow",
          "realpath *": "allow",
          "readlink *": "allow",
          "dirname *": "allow",
          "basename *": "allow",
          "du *": "allow",
          "df *": "allow",
          "uname *": "allow",
          "echo *": "allow",
          "whoami": "allow",
          "id": "allow",
          "printenv *": "allow",
          "which *": "allow",
          "pwd": "allow",
          "type *": "allow",
          "uptime": "allow",
          "free": "allow",
          "ps *": "allow",
          "lscpu": "allow",
          "lsblk *": "allow",
          "git status": "allow",
          "git diff *": "allow",
          "git log *": "allow",
          "git show *": "allow",
          "git ls-files *": "allow",
          "git describe *": "allow",
          "git rev-parse *": "allow",
          "git stash list": "allow",
          "git blame *": "allow",
          "qalc *": "allow",
          "tmux has-session *": "allow",
          "tmux capture-pane *": "allow",
          "tmux list-sessions": "allow",
          "tmux list-panes *": "allow",
          "tmux display *": "allow"
        }
    }
    }
    

  • oh damn. @[email protected]

    edit: going to install it… wish me luck lol

    edit2: it comes out with a free model out of the box. I’m not sure about the usage limits but if you were wondering about getting started with agentic this could be a solution! Didn’t have to connect anything, just start the app and start chatting. It’s multimodal and seems to understand images pretty well!

    Can’t generate them though. Generating images has a very good use: using placeholders that the AI understands well and can compose in your project (like placing them on a canvas). You’re limited to image vision. Well, that’s what the model itself says lol who knows.

    The free agent thinks it’s on Opencode lol, not Mimocode.

    Free model seems to have 1 million tokens context - at 50k tokens, it said I only used 5%. But again, I haven’t found out what the rate limits are yet.

    Like with factory opencode, there are very few permission requests out of the box. You’ll need to add an opencode.json file to enable them to your liking, otherwise it will do most things without ever asking you.

    Mimocode (start with ‘mimo’ in terminal) does a few things differently from opencode. It has a ‘Compose’ agent - TBA on this one but the assistant explains it’s an orchestration layer. I know these are becoming popular in coding agents, I still don’t quite get it though. I think compose is to like, follow specific skills in the process instead of reinventing the wheel every time and just yolo’ing it. It’s tailored for software dev in this case, so if you build software, you would use Compose instead of Build.

    ‘Plan’ saves a plan file to .config/mimo about the project, so it can refer to it later. Probably ties in with the memory features they talked about. It has a ‘plan_exit’ hook that triggered: I asked it to explain a project I was working on just to see, it saved the explanation as a plan then ran ‘plan_exit’ which asked me if I wanted to start building right away. I said no because I was asking it to explain the plan, not just jump to building whatever it was going to build.

    In ‘plan’, the agent is able to ask you questions about implementation etc to properly plan out, well, your plan. This is already available in opencode, but Mimocode asked me a multiple-choice question where I could select more than 1 item. Never saw that in opencode.

    It’s interesting that it can ‘spawn’ sub-agents (as opposed to ‘running’ them). Spawning lets the model let a sub-agent work in the background while it keeps doing its stuff. Basically, it removes wait times and the bottleneck of “I must now stay completely still while the sub-agent finishes its work”. I’m not sure opencode does that - if it does, deepseek never used it.

    Token usage seems a bit high… their system prompt is definitely bigger than opencode’s default one (about 20k tokens versus 10k tokens).

    It also introduces an auto-complete feature which is… fun? for five seconds, but then gets in the way. What I mean by auto-complete is the LLM suggests your next prompt, which you send by just pressing tab. Doubt I’d use it but hey it’s a feature and I’m here reviewing features so.

    I don’t have any project to give it right now unfortunately to test its abilities, but I might tomorrow.

    I imagine since it’s the free model they train with your data on it but… the PRC can have whatever it needs from me 🫡 (never transfer API keys and passwords over APIs regardless)



  • you know, I can see it lol. This was in the Ardour pull requests when someone added an MCP server:

    Basically they want the software other people make freely to cater exactly to their use of it. there’s always someone like that showing up. “I’m sure there are other accessibility options” = “I only think of myself and try to impose my views”, all accessibility options can live side-by-side, that’s how inclusive software is made. But they’d rather throw disabled people under the bus because it doesn’t impact them directly (6 heart emoji reacts under their post btw).

    Software lives and changes, as does everything else. To want it to be immutable so it caters specifically to one’s own sensibilities indeed looks reactionary.


  • the entire list wears its heart on its sleeve frankly, a whole manifesto that lumps everything in together. “Permissive AI policy” = “A policy that permits the use of AI/LLMs in any capacity”. So accepting AI bug reports would be enough to be put in the list, because… you realized your software has security vulnerabilities you need to fix? Per their own criterion to not be in the list a maintainer would have to actively refuse bugs found with AI and then… I don’t know, find them themselves instead?

    Like I exclusively use deepseek or kimi, I don’t see what their angst against western AI has to do with me lol. In general it’s just very US-centric and somehow it’s once again the entire world’s responsibility to soothe down USians’ anxieties (not that Europe where I live doesn’t rely on US tech or has a better AI policy lol).

    Ardour features in it as “Permissive AI policy” because someone created an MCP server. That’s it. An MCP server is a way of communicating data to an LLM and back, it’s an API.

    Just the fact they have a row called “Last Untainted Version or Commit ID” says it all really. By all means yell at Microsoft or OpenAI, but FOSS software is already unpopular enough as it is lol.


  • I feel it’s a matter of just finding the part you vibe with. I could show cool AI pictures that absolutely don’t look AI but there is little point to it as they would probably only speak to me. It’s like with everything else, there’s also paintings and drawings I don’t like or don’t find interesting. It has enabled a lot of spam to be created but the spam was already there, it just looked different. I used to have to trudge through pages and pages of stock image websites to find the one I could use, there’s some really improbable stuff in there (like this whole set of a sick employee eating a salad while working from home with the screen reflecting glare in his glasses and a random guitar in the background), and they somehow all have this look of being stock photos.

    So I figure, if we’re going to stop ourselves from doing things we enjoy or want to do just because there’s also slop of it that exists, there would be very little left to enjoy!