Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

61–70 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#61

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

It is supremely annoying when i ask in a group if someone has experience with a tool or system and some idiot copies my question into some LLM and paste the answer. I can use the LLM just like anyone, if i'm asking for EXPERIENCE it is because I want the opinion of a human who actually had to deal with stuff like corner cases.

It's the 2025 version of lmgtfy.

Re: Curl: We still have not seen a valid security report done with AI help

#62
post #56
post #39

Earlier quoted context omitted.

We cannot blame the tools for how they are used by those yielding them. I can use ChatGPT to teach me and understand a topic or i can use it to give me an answer and not double check and just copy paste. Just shows off how much you care about the topic at hand, no?

We can absolutely blame the people selling and marketing those tools.

Yeah, marketing always seemed to me like a misnomer or doublespeak for legal lies.

All marketing departments are trying to manipulate you to buy their thing, it should be illegal.

But just testing out this new stuff and seeing what's useful for you (or not) is usually the way

Re: Curl: We still have not seen a valid security report done with AI help

#63

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I recently had this happen from a senior engineer. What's really frustrating is I TOLD them the issues and how to fix it. Instead of listening to what I told them, they plugged it into GPT and responded with "Oh, interesting this is what GPT says" (Which, spoiler, was similar but lacking from what I'd said). Meaning, instead of listening to a real-life expert in the company telling them how to handle the problem they…

Those people weren't engineers to start with.

Re: Curl: We still have not seen a valid security report done with AI help

#64

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

This happens to me all the time at work. People have turned into frontends for LLM, even when it's their job to know the answer to these types of questions. We're talking technical leads.

Seems like if all you do is forward questions to LLMs, maybe you CAN be replaced by a LLM.

Re: Curl: We still have not seen a valid security report done with AI help

#65
> evilginx updated the severity from none to high

Well the reporter in the report that stated it that they are open for employment https://hackerone.com/reports/3125832 Anyone want to hire them? They can play with ChatGPT all day and spam random projects with the AI slop.

Re: Curl: We still have not seen a valid security report done with AI help

#66

Earlier quoted context omitted.

I recently had this happen from a senior engineer. What's really frustrating is I TOLD them the issues and how to fix it. Instead of listening to what I told them, they plugged it into GPT and responded with "Oh, interesting this is what GPT says" (Which, spoiler, was similar but lacking from what I'd said). Meaning, instead of listening to a real-life expert in the company telling them how to handle the problem they…

Those people weren't engineers to start with.

Software engineers rarely are.

I’m saying this tongue in cheek, but there’s some truth to it.

Re: Curl: We still have not seen a valid security report done with AI help

#67
post #39
post #36

Earlier quoted context omitted.

It depends on if they are just repeating things without understanding, or if they have understanding. My issue is that people that say "I asked gpt" is that they often do not have any understanding themselves. Copy and pasting from ChatGPT has the same consequences as copying and pasting from StackOverflow, which is to say you're now on the hook supporting code in production that you don't understand.

We cannot blame the tools for how they are used by those yielding them. I can use ChatGPT to teach me and understand a topic or i can use it to give me an answer and not double check and just copy paste. Just shows off how much you care about the topic at hand, no?

I see nobody here blaming tools and not people!

Re: Curl: We still have not seen a valid security report done with AI help

#68

Reading the straw that broke the camel's back commit illustrates the problem really well: https://hackerone.com/reports/3125832 . This shit must be infuriating to dig through. I wonder if reputation systems might work here - you could give anyone who id's with an AML/KYC provider some reputation, enough for two or three reports, let people earn reputation digging through zero rep submissions and give someone like 10,…

Reputation systems for this kind of thing sounds like rubbing some anti-itch cream on bullet wound. I feel like the problem seems to me to be behavior, not a technology issue. Personally I can't imagine how miserable it would be for my hard-earned expertise to be relegated to sifting through SLOP where maybe 1 in hundreds or even thousands of inquiries is worth any time at all. But it also doesn't seem prudent to jus…

I consider myself a left leaning soyboy, but this could be the outcome of too "nice" of a discourse. I won't advocate for toxicity, but I am considering if we bolster the self-image of idiots when we refuse to call them idiots. Because you're right, this is fundamentally a people problem, specifically we need people to filter this themselves.

I don't know where the limit would go.

Re: Curl: We still have not seen a valid security report done with AI help

#69
If I wanted to slip a vulnerability into a major open source project with a lot of eyes on it, using AI to DDOS their vulnerability reports so they're less likely to find a real report from someone who caught me seems like an obvious (and easy) step.

Looking at one of the bogus reports, it doesn't even seem like a real person. Why do this if you're not trying to gain recognition?

Re: Curl: We still have not seen a valid security report done with AI help

#70

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

Wow that's a wildly cynical interpretation of what someone is saying. Maybe it's right, but I think it's equally likely that people are saying that to give you the right context.

If they're saying it to you, why wouldn't you assume they understand and trust what they came up with?

Do you need people to start with "I understand and believe and trust what I'm about to show you ..."?

Post reply on HN