@HalvarFlake

8.7K Followers
394 Following
2K Posts

I do math. And was once asked by R. Morris Sr. : "For whom?"

Accidental two-time founder. Mathematician by education. Infosec luminary (has-been?).

@HalvarFlake oh boy don't get me started, I had to build a benchmarking system for GitLab and we had to buy sole tenants, the variablity of noisey neighbors is just too high to do any realistic benchmarking.

I am seeing up to 30% wall-time fluctuation running the same code on the same data on the same VM type in GCE.

That seems crazy to me.

What's the worst variation you've seen? How do you deal with these things?

I mean, for any benchmarking you need to run the clickhouse tomato benchmark protocol? (E.g. run two instances of the same software on the same VM so they're exposed to the same noisy neighbor effects).

I am insanely proud about the following, even though I am not at all involved any more:

https://opentelemetry.io/blog/2026/profiles-alpha/

Working with the optimyze team was so awesome.

OpenTelemetry Profiling Enters Public Alpha

Since OpenTelemetry first introduced Profiles, momentum has only grown towards building a unified industry standard for continuous production profiling, standing alongside traces, metrics, and logs. Today, the Profiling SIG is proud to announce that the Profiles signal has officially entered public Alpha, and we are ready for broader community use and feedback. Production profiling for all Continuously capturing low-overhead performance profiles in production is a technique that has been used for decades. It helps troubleshoot production incidents, improves user experience by making software faster and reduces computation costs by making the same work take less resources. Historically, the industry lacked a common framework and protocol for continuous profiling, even with formats like JFR and pprof being popular.

OpenTelemetry

I wrote some lines about mitigating vibe-coding risks by adopting a development model inspired by old-school computer breakin folks:

https://addxorrol.blogspot.com/2026/03/slightly-safer-vibecoding-by-adopting.html

Slightly safer vibecoding by adopting old hacker habits

I have seen a lot of public discussion around supply-chain attacks on the Python ecosystem, prompt injection risks when using coding agents,...

Wieso darf Haferdrink nicht "Hafermilch" heißen, aber Cisco darf ihre Produkte "Cisco Secure Firewall" nennen?
Artificial intelligence will have an impact not only on programming games for old machines, but also on the demo scene. Not a single line of Assembly code was written by humans for this #Atari8bit computers rotating toroid. EDIT it's a news, I don't like AI for demo scene prods.
https://forums.atariage.com/topic/388112-ai-is-getting-too-good/ #atari #demoscene #AI

"Switzerland’s military has terminated its contract with Palantir… following a security audit… concluded that U.S. intelligence agencies could potentially access sensitive Swiss defense data… significant reputational warning for the data analytics firm"

https://www.newscase.com/palantirs-swiss-exit-highlights-global-data-sovereignty-challenge/

#Palantir #Dataprivacy #Security

Palantir’s Swiss Exit Highlights Global Data Sovereignty Challenge

Switzerland’s military has terminated its contract with Palantir Technologies Inc. following a security audit. The review concluded that U.S. intelligence agencies could potentially access sensitive Swiss defense data, a deal-breaker for the neutrality-focused Alpine nation. This move represents a significant reputational warning for the data analytics firm, with potential ripple effects across other international partnerships. […]

NewsCase
The zymtrace folks are killing it: https://zymtrace.com/article/anam-zymtrace/
How Anam Achieved 250% Faster Inference Using Zymtrace Continuous GPU Profiling - zymtrace

Anam builds interactive avatars that generate photorealistic video within latency budgets measured in hundreds of milliseconds. By continuously profiling GPU workloads with Zymtrace, they achieved 250% improvement in inference latency and 90% increase in throughput.

Just read this via repost from @HalvarFlake
https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/

This post from Sean Heelan is probably the most important post in that domain (being LLMs in offensive security contexts) in quite a while. We're already discussing this in my research group, and I have some initial thoughts. Exciting times!

On the Coming Industrialisation of Exploit Generation with LLMs

Recently I ran an experiment where I built agents on top of Opus 4.5 and GPT-5.2 and then challenged them to write exploits for a zeroday vulnerability in the QuickJS Javascript interpreter. I adde…

Sean Heelan's Blog

@HalvarFlake Here’s some better alt text…

A satirical tabloid page, with sensational colors and fonts.

German claim to Greenland!

Giant German towel DROPPED ON GREENLAND!

German air force STRIKES!

US claims denied!

Expert says: “WHERE GERMANS LAY THEIR TOWELS, no one else is allowed to go!”

German towel rule in effect!