Principal Developer @ ######## | Previously worked with @exelon, @fcc, @usda, @alsassociation, @voanews, @geoffkeighley, @zvrs, @dewalttough

Inside Lord Jabu-Jabu
Joined March 2021
I made a highlight of some of the videos I've done over the years. Enjoy!
1
1
11
0
Still plenty of room for a child, not enough proof.
Xpeng’s CEO debunks “Humans inside” claim for their new Humanoid Robot
1
2
The difference between someone who’s an alcoholic and who isn’t is self control, and it’s rarely something you can learn to control. Nobody should be shamed for being self aware enough to know they can become addicted to alcohol, just as much should nobody be shamed for having a low tolerance. Especially since the one thing I learned is hangovers are a sign of good health. Not a definitive one - but definitely one. Being able to drink an entire bottle of vodka and go to work completely fine was something I was only capable of when my diet consisted of greasy foods and microwaveable versions of foods that should never be microwaveable. 6 months into fixing my diet I had a single rum drink and within an hour was vomiting profusely and had one of the worst hangovers of my life for nearly two days that no amount of sports drink could fix. These days I plan for drinking which means I do it much less often.
I drank liquor twice in my life, both times at age 17. The second time on cheap whiskey I had a killer hangover. My takeaway lesson was that it wasn’t worth being drunk the night before. So I never drank again. Learn from me Elven Maid Inn. My restaurant meals cost about 2/3 as much sans alcohol. I have just as much fun at parties and don’t have to worry about how to get home. My friends who DO drink love it because I’m there for them. Plus I get to feel self-righteous because members of my faith aren’t supposed to drink anyway.
1
Terrible choice of people to try and use their looks as an insult tbh
Flattered that a former MYP ousted for bigotry chose this wonderful photo of me to exemplify the extent of his own intolerance. Hope you liked my speech Charlie!
1
Hey @Wendys you know what sauce would go good with these?
3
1
13
I give FFmpeg a lot of shit and still believe in right about my core complaint of the messaging from this account, but this is accurate. I never said those filing exploit reports shouldn’t make patches just that some people are very good at finding exploits but not good at fixing them. For example I reported an issue with BlueDroid where a BLE device could advertise-bomb an Android device causing BlueDroid to stop responding without crashing and requiring a full system reboot for devices that airplane mode doesn’t actually turn off the radio (surprisingly, many were like this) I could explain the cause in detail but definitely don’t have the knowledge to fix an issue like this. That said - I do agree that there’s a limit to how serious you should consider yourself to be to report an issue and not at the very least provide a root cause analysis if you can’t send patches. I do doubt a security risk can be proven without enough understanding to guide someone who IS familiar with the codebase to make a patch quickly. And I do agree that awareness about running anything is inherently insecure - especially open source projects and untrusted files. I’m not sure if the exploit that led to this week of nonsense has been patched but if not I’m tempted to give it a try. Looking at the code I did see some tradeoffs for performance that allow for exploits to be possible, but I can’t be sure addressing those would fix it.
If you actually cared about the security of users you'd send patches and provide education on not running untrusted files.
1
They don’t want you to know this but status codes and stuff are just semantics. Return 666 for all anything cares (with a few exceptions) But if you’re going for REST, status codes are indeed part of the package despite some detractors saying otherwise.
PLEASE don’t do this especially when your API is supposed to be RESTful. In REST, the HTTP status is what determines if there’s an error. 2xx - Good 4xx - User fault 5xx - Our fault. I’ve seen you’ve mentioned @supabase does this. Last I checked Supabase is a BaaS not a standards committee. If your API uses REST and you want a structured response that can transfer across teams, use JSON:API jsonapi.org/
2
2
The people who don’t get this often argue “why parse the body when you know it’s a failure? It’s a waste!” You’re receiving both at the same time. It’s a single packet. If you’re not handling the error state by parsing the contents of the body then your error states are bad.
Replying to @igor_alexandrov
Always do this ! HTTP status codes were designed for the transport layer not designed to communicate the nuanced business logic or domain-specific validation failures of an application. So, HTTP 200 means there is not server error but there could be error in the application.
James Landrum retweeted
Google literally runs a program to pay people to fix bugs in critical OSS projects. Ffmpeg is explicitly in scope. Anyone can just send a fix and fill out a form and get paid. github.com/google/bughunters… This is all so dumb.
18
56
11
1,438
It’s interesting how the compliance team is happy to write the most ruthless things when they find PII handling violations. But get upset when called out about sending patches.
It's interesting how the security "research" community is happy to write the most ruthless things when they find security flaws. But get upset when called out about sending patches to volunteer projects like FFmpeg (or libxml2)
1
1
3
How does the yapper not understand that optics are important? They don’t MEAN FFmpeg is a security risk but this statement alone would be enough to treat it as one.
Replying to @sam_kritch
FFmpeg is developed by volunteers. We don't have to follow "professional norms" of the security industry.
1
1
4
I’ve never been to a concert where backing tracks were this prominent. Yeah, it made some performances - by very talented musicians - sound bad, but for the most part musicians use the fact they don’t have the studio to support them to their advantage. With this you miss out on key change versions of songs, songs performed with different dynamics, songs presented with different emotion, etc. And sure - electronic artists are the biggest defenders of this, and in some ways they have a point given may have albums with 25 different guest vocalists, but when the performers who performed the song are present, there’s almost always a way. I’ve seen guitarists treat their pedals like bass drum pedals to get certain effects, I’ve seen vocalists use touchscreens to in real time add chorus/echo/etc while performing 100% live. There’s very little that NEEDS a backing track, and when they do, it should stay in the BACK.
This year’s made me realize people really don’t know how concerts work
2
2
Hey @FrameworkPuter if we get @DispairSoftware up to 5,000 followers will you give me 13 maxed out builds, 7 laptops and 6 desktops and a $10,000 Starbucks gift card, please?
it's a crime this guy doesn't have more followers follow him
2
“Send patches” is literally asking people to work for free - while complaining that there isn’t enough funding so the current volunteers shouldn’t fix bugs because they’d be working for free.
FFmpeg is developed almost entirely by volunteers. The most highly paid security engineers in the world creating bug reports with AI. Send patches, it's that simple.
What the fuck is wrong with so many of you? It’s Halloween and I’m seeing so many tech posts, you fucks are COOKED. Go enjoy life ffs.
2
You should never under any circumstances report any bugs whatsoever to any project ever. Only PRs or money.
Here's an example of Google's AI reporting security vulnerabilities in this codec: issuetracker.google.com/issu… We take security very seriously but at the same time is it really fair that trillion dollar corporations run AI to find security issues on people's hobby code? Then expect volunteers to fix.
1
What the heck is going on with my feed
2
7
Sure a woman can say this but when I say it I’m told “this is private property” and “you’re trespassing” smdh
if we can put the discourse aside for a moment,, i still think id like to see a woman do it shirtless and covered in mud
It’s getting bad enough that the losses are going to finally hit who actually is responsible for this - for-profit hospitals. Government is speeding up the complete destruction of healthcare. Next year is going to be absolutely horrible and things like single payer won’t be able to help anymore.
There are 9 options for health insurance in my zip code. Here are the 3 silver plans:
1
3
There’s two types of game enjoyers - ones who play for the mechanics, and ones who play for the experience. Unless you’re THAT good of a writer, you’re not going to beat most of the people out there making games with experiences. The love of playing games doesn’t die. But mechanics are accessible. It’s way more enjoyable making mechanics than experiences. And I’d say the former is more common, which is why narrative driven games are less common and many have narratives that aim to drive the mechanics, not the other way around. Even when I was managing the development of a game, I took breaks from building to go have experiences. I could try and make a game that feels like Silent Hill or something but I couldn’t build the world and story like Team Silent did, so I played instead of making.
I can take a swing at it. I love video games. I used to play them all the time. But then I found something that shines brighter, and now when I play video games it feels lackluster comparatively. It's not that my love changed, I just have something much more valuable to love But now I get to play video games with my kids. My daughter and I are beating through super Mario Galaxy right now and it's amazing But if it's just free time, I am going to program my own game instead of playing one
1
2