Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

21–30 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#21
post #5
post #3

Earlier quoted context omitted.

Fortunately, they can beat an automated idiot agent, which is much closer to what we have today.

[flagged]

They still hallucinate (generate bullshit) too much. Nothing much to be done there, it is part of what they are.

They are still useful as code assistant. But the sort of overhype that you push for is actually detrimental to its healthy development.

Re: Curl: We still have not seen a valid security report done with AI help

#22
Didn't even have to click through to the report in question to know it would be all hallucinations -- both the original patchfile and the segfault ("ngtcp2_http3_handle_priority_frame".. "There is no function named like this in current ngtcp2 or nghttp3.") I guess these guys don't bother to verify, they just blast out AI slop and hope one of them hits?

Re: Curl: We still have not seen a valid security report done with AI help

#23

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I had to deal with someone who tried to check in hallucinated code with the defense "I checked it with chatGPT!"

If you're just parroting what you read, what is it that you do here?!

Re: Curl: We still have not seen a valid security report done with AI help

#24

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

As much as I'm also annoyed by that phrase, is it really any different from:

- I had to Google it...

- According to a StackOverflow answer...

- Person X told me about this nice trick...

- etc.

Stating your sources should surely not be a bad thing, no?

Re: Curl: We still have not seen a valid security report done with AI help

#25

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

Seriously. Being able to look up stuff using AI is not unique. I can do that too.

This is kind of the same with any AI gen art. Like I can go generate a bunch of cool images with AI too, why should I give a shit about your random Midjourney output.

Re: Curl: We still have not seen a valid security report done with AI help

#27
post #23

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I had to deal with someone who tried to check in hallucinated code with the defense "I checked it with chatGPT!" If you're just parroting what you read, what is it that you do here?!

Manage people?

Re: Curl: We still have not seen a valid security report done with AI help

#28

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

As much as I'm also annoyed by that phrase, is it really any different from: - I had to Google it... - According to a StackOverflow answer... - Person X told me about this nice trick... - etc. Stating your sources should surely not be a bad thing, no?

the first 2 bullet points give you an array of answers/comments helping you cross check (also I'm a freak, and even on SO, I generally click on the posted documentation links).

Re: Curl: We still have not seen a valid security report done with AI help

#29

Didn't even have to click through to the report in question to know it would be all hallucinations -- both the original patchfile and the segfault ("ngtcp2_http3_handle_priority_frame".. "There is no function named like this in current ngtcp2 or nghttp3.") I guess these guys don't bother to verify, they just blast out AI slop and hope one of them hits?

Reminds me of when some LLM (might have been Deepseek) told me I could add wasm_mode=True in my FastHTML python code which would allow me to compile it to WebAssembly, when of course there is no such feature in FastHTML. This was even when I had provided it full llms-ctx.txt

Re: Curl: We still have not seen a valid security report done with AI help

#30
post #20

Earlier quoted context omitted.

Clearly the answer is to have an AI assistant handle all the reports from bogus AI auditors. It's all turtles, all the way down.

[flagged]

Nothing intelligent about that loop. But a loop it is.
Post reply on HN