• 1 Post
  • 102 Comments
Joined 2 years ago
cake
Cake day: July 4th, 2023

help-circle

  • Depends on your situation and objective. If you’re currently employed and want to increase potential earnings in the same track, then probably around 30/35 from my personal judgement. You should really have enough professional experience and context at that point to make up for a degree, especially if you’re engaging in continuing education, staying up to date on professional articles, watching conference talks, etc.

    If you’re looking to get an MBA to move into a management track, it’s probably worth it later in life until like your 40s and 50s earnings wise.

    If your current industry is tanking and you need to pivot to a new one, then you don’t really have any other options than to reskill no matter how old you are.

    If you just want to learn philosophy or history independent of your work, then there’s not really a point where it’s too late, just how many classes you have time for which is wholly dependent on your life circumstances and doesn’t depend on age.








  • An issue I’ve seen brought up in the open source community is that they have audits that look at the number of untriaged issues and time to resolve serious issues that their funding depends on.

    I’m in software, but not open source, so it seems like they don’t have someone aligned with their team who they can sit down and say “either we need more resources, cut scope for new features, or accept quality / security issues coming up” to, its kind of this weird game of politics they end up needing to play to get any kind of funding for full time maintainers.

    That’s the main reason they can’t just ignore issues that come up in their backlog, especially security ones.



  • Security vulnerabilities are different, especially when they also put a 90 day disclosure period in it which is more severe for a security exploit.

    That disclosure bit, not in the article, is really what tipped this all over the edge. If it was just hey, here’s a bug then its really just flooding the backlog for the maintainers who need to triage that. Disclosures are often used so people are aware that they’re using libraries that the maintainer has refused to patch, but in this case its really just holding the maintainers hostage so they end up wasting their time going through irrelevant issues.

    Also, many of these libraries get security audits to make sure they are actually triaging and working through their backlogs, so could lose actual funding they get.

    Ideally, they would either use their supposedly capable and powerful AI code gen to just make a fix and send over a patch, or at least use LLMs on their own end to triage the issues and only send over the most sever X periodically.