@ehsanianno

Software Engineer | Distributed Systems | Platform | MSc. AI

Joined January 2012
This is insane. Running DeepSeek-V4-flash locally and it's a great model. If you ask introduce yourself in English it says DeepSeek but I asked the model to try to think in Persian and seems like it bypassed its instructions - the model thinks it's @GoogleDeepMind !😀
6
107
My timeline is full of articles, mostly AI generated ones! What’s going on? Is there a secret sauce in loop engineerin or the method is the secret sauce for increasing token usage?
28
Using OpenClaw. It’s pretty cool but can be much better. IMO context management and seamleasly switching models to gain speed/efficiency could improve it a lot. Hope @steipete’s team tackles those.
5
9
5,722
درس اول آمار: کسی که ۳۰ میلیون ثبت‌نام واقعی «جان‌فدا» دارد می‌تواند از آن ده‌ها نوع نمودار، به تفکیک سن و جنس و شهر و تاریخ در معرض دید عموم بگذارد. کسی که از کل ثبت‌نام‌ها فقط یک «عدد» منتشر کرده، با همان عدد رسوا می‌شود. درس دوم آمار: روند ثبت‌نام مردم در طول یک پویش خطی نیست؛ در تعطیلات آخر هفته، نوروز، آتش‌بس و... متفاوت است. هنگام عددسازی بعدی، کمی نویز اضافه کنید. داده‌های خام: tinyurl.com/janfadaa توضیحات: ۱) بین سایت‌های مختلف خبری که آمارهای روزانه‌ی «جان‌فدا» را منتشر کرده‌بودند، خبرگزاری مهر منظم‌ترین اخبار را داشت. ۲) آمارهای پویش جان‌فدا در روزهای ۱۰ تا ۲۷ فروردین جستجو شد. ۳) چون در طول روزهای مختلف، آمار در ساعت متفاوتی منتشر شده بود، ساعت و دقیقه‌ی انتشار خبر هم در نظر گرفته شد. ۴) عدد R^2=0.995 نشان می‌دهد داده‌ها با کم‌ترین خطا از یک روند کاملا خطی تبعیت می‌کند (اگر با این مفهوم آشنا نیستید، پیشنهاد می‌کنم حتما از هوش‌مصنوعی یا دوستان مسلط به آمار در مورد آن بپرسید و ببینید چقدر ممکن است چنین چیزی در داده‌های واقعی متاثر از رفتار مردم مشاهده شود. ۵) در واقع این نمودار نشان می‌دهد در طول ۱۷ روز، نرخ ثبت‌نام مردم در پویش جان‌فدا یک عدد کاملا ثابت بوده و اتفاقاتی نظیر تعطیلات نوروز، روزهای کاری یا پایان هفته، زمان اعلام آتش‌بس هیچ اثری روی آن نداشته است. ۶) اگر همین نرخ خطی ادامه می‌یافت، به زودی عدد ثبت‌نام از ۱۰۰ میلیون هم بالاتر می‌رفت. لذا احتمالا صلاح دیده‌اند بعد از ۲۶ میلیون، ثبت‌نام با روند آهسته‌تری ادامه یابد.
738
2,078
129
10,957
564,145
Ehsan 🇮🇷 retweeted
Whether or not Europe stands with us, whether or not your journalists do their jobs, whether or not your politicians demonstrate the courage to act, I will fight for my people and my country.
25,344
59,707
8,852
123,739
20,969,408
Ehsan 🇮🇷 retweeted
Software horror: litellm PyPI supply chain attack. Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords. LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm. Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks. Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages. Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
LiteLLM HAS BEEN COMPROMISED, DO NOT UPDATE. We just discovered that LiteLLM pypi release 1.82.8. It has been compromised, it contains litellm_init.pth with base64 encoded instructions to send all the credentials it can find to remote server + self-replicate. link below
1,335
5,223
1,317
27,566
66,651,728
به نظرم فقط در این دو حالت مهاجرت کنید: ۱. با خانواده ۲. فراری از خانواده حتی اگر کمی دلبسته باشید، پیر می‌شوید. #تجربه_شخصی #پیرمرد_نقاش
57
187
8
2,906
75,291
از زاویه‌ای دیگر #Feb14ForIran
3
75
Just tested fast mode of @claudeai in claude code. Changed 5 files and 135 lines. Accuracy is the same as normal mode. It took 4mins to impl a task. The exact same task with a clean context implemented in 5.30 mins in normal mode. 6x more expensive but only < 1.5x faster
1
45
Ehsan 🇮🇷 retweeted
150,000 demonstrators and zero incidents. Thanks to the meticulous planning, effective on‑the‑ground work, and professionalism of our members and specialized units, yesterday’s event in the heart of our city remained safe and peaceful.
11,976
2,764
35,354
3,293,694
Success is product of daily habits — not once-in-a-lifetime transformations.
1
116
O3 is crazy good in reasoning. I am impressed by its capabalities.
1
128