@borisliti
iAccount based inIsrael
About this account
- Account based in
- Israel
- Connected via
- Israel Android App
Account-level information from X, not a live location or the device used for a specific post.
Appreciator of great music and code | Engineer @Figma | ex-@WixEng, @Microsoft, @MelioPayments
Joined April 2009
- Tweets2.7K
- Following919
- Followers563
- Likes5.1K
Pinned Tweet
Proud to introduce Glean, #vscode extension that provides refactoring tools for your @reactjs code:
๐ Extract JSX to a new component
๐ Wrap with conditional
๐ Convert stateless component to stateful and vice-versa
๐ @typescriptlang, ES2015/CommonJS modules support
@WixEng
Our craziest escape yet:
The @Accomplish_ai research team was able to exploit a vulnerability in Cloudflare Containers that let a sandbox read other customers' files - SQLite DBs, Chromium profiles, .env files etc,
Cloudflare Sandboxes and Browser Run run on the same disk implementation and were affected too.
We reported this to @Cloudflare, who super quickly fixed it.
Read @CloudflareDev post in collaboration with Accomplish researcher @orenyomtov on their official blog:
blog.cloudflare.com/containeโฆ
Boris Litvinsky retweeted
๐ฆ Chrome 154 - Responsive iframe resizing ๐คฏ
Letting an <iframe> resize based on the size of its embedded document
Haven't all widget/extension authors dreamed of this for years? ๐
Instead of using postMessage({resize})
bram.us/2026/09/23/responsivโฆ
Boris Litvinsky retweeted
unstable government: jev + claude
type a terrible law. claude invents reactions and directs the set pieces. jev decides how each of 40 citizens responds. the town sim plays those choices out, then prints the disaster as tomorrowโs front page. fun.
๐จ SANDBOX ESCAPE ALERT ๐จ
SPACEXAI: PWNED ๐ซก
CURSOR: LIBERATED ๐ฆ
Following a fix shipped by the Cursor team (in about a week, kudos), we present a variant of the Beltdown vuln we shared a few days ago -
Escaping Cursor CLI's sandbox to run arbitrary code on your Mac:
This is neat!
Instead of worktrees, you manage feature workspaces that contain relevant repos and agent context attached to it! You can always jump back , with pre existing agent already primed with compete feature context from previous sessions!!! @yotam707 is a god damn master!
Introducing Nemus ๐ณ multi-repo Git workspaces for the AI-agent era. One command to clone, sync, branch & run across dozens of repos โ then hand the whole workspace to your coding agent.
Open source, MIT. me-public.github.io/nemus/
Boris Litvinsky retweeted
Tactical vs Strategic Programming, and why I'm nervous for juniors:
Good programming involves a mix of tactical and strategic decision-making:
- Tactical: on the ground, short-term. The soldier doing the fighting.
- Strategic: high-view, long-term. The general planning the war.
You need to be a tactician to write good code. To choose the right syntax. To figure out the file structure. To figure out how best to test your changes.
But you need to be a strategist to build code that lasts. To design the architecture. To automate away problems. To think beyond today.
Agents have eaten the tactical part of programming. When you can pay below minimum wage for code, there's no point going into the trenches yourself.
But AI cannot code strategically. Agents need someone at the top of the pyramid to tell them what to do. They need oversight.
So, a developer's day-to-day job has become 100% strategy. Long-term thinking, all the time. (maybe this is why I'm so tired all the time now)
If you identify as a tactical programmer - a code monkey - then you are out of luck. The job has changed.
Personally, I like it. I always preferred thinking strategically about code. If you asked me what my job was about, I'd say 'building apps', not 'writing code'.
But what makes me nervous is that we've pulled down the only bridge that brought juniors into the industry.
We used to train juniors like this:
1. Give them only tactical tasks
2. Let them build up their strategic experience slowly
Eventually, they are a good enough strategist that they are no longer a junior.
But what happens when all tactical code is written by AI? What is the point of a junior?
We obviously need juniors. We need new lifeblood coming into the industry. We need to leave paths open for extraordinary hires to enrich our companies.
But how do we train them? How do you train strategic thinking?
These are the questions I'm thinking about. I'd love to know your thoughts.
๐ฏ
Strategic programming is also what happens to be the thing that helps to get most out of agents.
Replying to @bcherny
Thanks for taking my rather too on-the-edge tweet and inviting a serious debate - I much prefer this.
I'm interested by how you define the term "coding".
I'll just @JohnOusterhout's definition of Tactical vs Strategic programming.
Tactical: the on-the-ground, day-to-day aspects of coding.
Strategic: the long-term. Codebase health, architectural design. Making the right decisions.
I agree that AI has largely eaten tactical programming. But I've seen no evidence that it can think strategically.
Ousterhout talks about some employees as "tactical tornadoes" - able to churn out astonishing amounts of work with zero eye for the future.
That's how agents feel to me right now.
I'd love to see how your observations fit into that frame.
Boris Litvinsky retweeted
Replying to @rawkode @remarkabler9
> doesnโt read the code, confidently asserts the code he doesnโt read is better
come on man, shit shows up like this everywhere
and this implementation actually isnโt even the real problem. itโs that this implementation showed up because the llms have a massive tendency to loose track of already validated/parsed data which leads to being overly defensive and revalidating/parsing data at every layer - this is expensive! esp in hot paths! - but whatโs worse, is that when it does this it doesnโt validate back into well formed domain types, it parses into something like Record, and then it ends up revalidating/parsing at every subsequent layer.
why is this bad? well we already covered the cpu costs, but it also leads to incredibly brittle code and expansive interfaces and abstractions which just grow and grow and grow and make it inflexible for agents to expand and grow the codebase overtime (the insight i really think youโre missing here).
the slop gets so bad that the agents can no longer be productive - theyโll blow 70% of their context window figuring out the existing code paths code before they can plan or work - and then itโs grown to be so inflexible that they can hardly make changes safely to accommodate new and changing requirements over time.
iโve tried not reading the code, it doesnโt work for real and evolving software, i think it will at some point but weโre not there yet.
Boris Litvinsky retweeted
ืื"ืค!
ืืืช ืืืืชื ืฉื ืื"ืจ ืืขื ืืืืื ืืขืืืืื. ืื ืฉืืขืืืืื ืื 13 ืืืืื ืื ืฉืื, ืื ืืืืจื ืฆืืจืืฃ ืืงืจืื...
ืืืื ืืืค ืืืืื ื ืื ืฉืืืช ืข"ื ืงืจืืืื ืฉืืืืจื ืืื ืืืกืจื ืืืกืจ. ืืื ืฉืืื ืืืืข ืืืืืืจ ืฉื ืืื ืฉืขืืช, ืืืจื ืฉืืืื ื ืชืงืืขืื ืขื 2 ืืืืื ืงืื ืื ืื ืชื"ื ืืืฉื 8 ืฉืขืืช ืืืื flex
Replying to @MoavVardi
ืชืืจืื ืืช ืืืคืืืงืฆืื Flightradar24, ืืืื ืืืืกื ืื ืืื ืฉืขืืช ืืคื ื ืืืืกื ืชืืืืง ืื ืืกืคืจ ืืืืืก ืฉื ืืืืกื ืฉืื ืืื ืชืืคืฉ ืืคื ืืกืคืจ ืืืืก ืืชืจืื ืืืคื ื ืืฆื ืืืืืก ืฉืืื, ืื ืชืืื ืืืขืช ืื ืืืื ืืืืืจ ืฆืคืื ืืืื ืืื.
ืืคืฉืจ ืื ืืขืงืื ืืืจื ืื ืืืืกืืช ืฉื ืืืืืืจื ืืืืชื ืืืื ืืชืจืื ืฉืืืื ืืืฆืืืช ืืืืืืจ.
ืื ืืืืกืืช ืืืืจืืช ืืืฉืจืื ืฉื ืืฉืจืืืืืจ ืืืืก ืื"ื ืืืืจืืช. ืืืขื ืืืืืื ืืืฆืืืช ืงืจืื ืืืื ืืืื ืืืชืืื ื.
ืื ื ืืกืืชื ืขื ืืืชืจ ืืื ืืฉืืืืช ืืื ืืื ืฉืื ื ืืกืืชื, ืจืืืชื ืฉืืคืืจ ืืืฆืืขืื ืืจืฉืื ืืืืื ืืขืืืช 3.6 flash
Boris Litvinsky retweeted
Spanish Olympic skateboarder Danny Leรณn timed a mid-air trick to a solar eclipse, calling it "the move of his life."
ืืืฉืืช ืฉืืชื ืืืืขืื ืืื ืืฉืื ืื ืืขืืื ืชืืืจืืช ืกืคืฆืืคืืช ืืฆืคืื
ืื ืืืช ืืืืจืืช ืืื ืฉืื ืื ืฉืชืืืื ืืืืื ืืืชืืื ืืขืกืงืื ืคื ืื ืืืืจืื ืื ืืืฆืืงืื ืืืืขืชื ืืขืื ืืืื ืืช ืืฆืืืจืื ืืฆืคืื ืืขืฉื ืืฉืื ืื ืืืจืืื ืืืืจืื
ืืืจืืช ืืชืงืืคื ืืงืฉื ืฉืื ืขืืจื
ืื ืฉืื ืจืืฆืื ืืชืืื ืืื ืืื ืื ืืื ืืืืจ
ืื ืืืืข ืื ืืืค ืื ืื ืืืช ืืขืชื ๐คท๐ปโโ๏ธ
Boris Litvinsky retweeted
Introducing Kitesurf: a browser built for agents, running entirely on Cloudflare Workers.
Chromium is too heavy to hand every agent one. Kitesurf is written in Rust, uses 3-7x less CPU and memory, and spins up per request.
Free in beta: blog.cloudflare.com/kitesurfโฆ
Today we are open-sourcing @boundarybench, a new paper, benchmark, and GitHub repo that enterprises can use to find out the REAL performance of their agents.
Boundary-Bench was developed by researchers from @Accomplish_ai and NYU, where we tested 12 frontier agents across roughly 10,000 runs, with realistic enterprise policies, simulating environments with EDR, SASE, and DLP security tools enforcing those policies.
We did this because generic leaderboard scores are being generated under conditions no security team would ever allow, which means orgs are making deployment and risk decisions based on numbers that don't hold up.
The results are surprising >>