Android 17 QPR1 is the first release since Android Honeycomb (3.x) adding new APIs for app developers without a release to the Android Open Source Project. The new APIs are currently exclusive to the Pixel OS and aren't available to other Android OEMs.
https://developer.android.com/sdk/api_diff/37.1/changes
As they say it’s useful to find vulnerabilities which is true.
And as far as code they said:
Frontier models are very good at finding bugs but it requires an experienced developer to babysit it and extract the useful portion of the output. Important bugs are often found but mixed in with a bunch of low quality output.
Which is the opposite of vibe coding.
It’s fair to dislike any LLM usage. But it can have value. But it’s often coming from unethical entities like OpenAI and Anthropic etc
I think this is the distinction of uses I canost get behind. If you find an attack using any tool, whether that be a CVE, a script kiddy, or an LLM, then you can go on to understand how the vulnerability works and patch it. This leaves the understanding part to the programmer, but not the arduous task of trying to find problems. If you use vibecoding to do the actual fixing you never have the understanding of how the code works and therefore what the changes will actually do.
LLMs can be useful in a lot of ways, but they should never replace thinking and understanding. Just like you do need to memorise some things but not others, there are cognitive tasks you don’t have to do all the time but others you really have to in order to actually be a good programmer. If you outsource thinking you stop doing it and get weaker at it. If you outsource meaningless tasks or use systems to reduce the need for them that is actually useful for freeing up your mind for tasks which cannot be automated.
So in my view using these tools to find bugs in code can be useful. Knowing that if a bug is found it may not be disclosed to you by the tool because the provider of the tool wants to keep some bugs hidden is something people should consider, I mean that is exactly what the NSA has been going for decades with zero day exploits in various operating systems and platforms, why would they not do so now?
Hopefully Graphene is developing a hard fork of AOSP with Motorola, so they don’t have to be reliant on Google
That’s why I was so gutted that DivestOS shut down. It was such a good alternative to GrapheneOS and was usable on phones other than Pixel.
I guess CalyxOS is the next best thing nowadays, since it can be used on some Motorola phones, Fairphones and the ShiftPhone 8:
https://calyxos.org/install/
don’t hope too much, they have admitted they are vibing it
They specifically aren’t vibing it though.
As they say it’s useful to find vulnerabilities which is true.
And as far as code they said:
Which is the opposite of vibe coding.
It’s fair to dislike any LLM usage. But it can have value. But it’s often coming from unethical entities like OpenAI and Anthropic etc
I think this is the distinction of uses I canost get behind. If you find an attack using any tool, whether that be a CVE, a script kiddy, or an LLM, then you can go on to understand how the vulnerability works and patch it. This leaves the understanding part to the programmer, but not the arduous task of trying to find problems. If you use vibecoding to do the actual fixing you never have the understanding of how the code works and therefore what the changes will actually do.
LLMs can be useful in a lot of ways, but they should never replace thinking and understanding. Just like you do need to memorise some things but not others, there are cognitive tasks you don’t have to do all the time but others you really have to in order to actually be a good programmer. If you outsource thinking you stop doing it and get weaker at it. If you outsource meaningless tasks or use systems to reduce the need for them that is actually useful for freeing up your mind for tasks which cannot be automated.
So in my view using these tools to find bugs in code can be useful. Knowing that if a bug is found it may not be disclosed to you by the tool because the provider of the tool wants to keep some bugs hidden is something people should consider, I mean that is exactly what the NSA has been going for decades with zero day exploits in various operating systems and platforms, why would they not do so now?
Where?
Their mastodon profile is talking at length about it.
Shit, well that pretty much seals the deal on no Motophene for me. As if the Epstein Class price tag was not doing enough as a disincentive.