Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

71–80 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#71
post #58
post #57

Earlier quoted context omitted.

If it's not worth writing, it's not worth reading.

I mean, there is a lot of hand written crap to, so even that isn't a good rule.

It is a necessary but not sufficient condition, perhaps?

Re: Curl: We still have not seen a valid security report done with AI help

#72

Earlier quoted context omitted.

It is supremely annoying when i ask in a group if someone has experience with a tool or system and some idiot copies my question into some LLM and paste the answer. I can use the LLM just like anyone, if i'm asking for EXPERIENCE it is because I want the opinion of a human who actually had to deal with stuff like corner cases.

It's the 2025 version of lmgtfy.

Nah, that’s different. Lmgtfy has nothing to do with experience, other than experience in googling. Lmgtfy applies to stuff that can expediently be googled.

Re: Curl: We still have not seen a valid security report done with AI help

#73

Didn't even have to click through to the report in question to know it would be all hallucinations -- both the original patchfile and the segfault ("ngtcp2_http3_handle_priority_frame".. "There is no function named like this in current ngtcp2 or nghttp3.") I guess these guys don't bother to verify, they just blast out AI slop and hope one of them hits?

>"ngtcp2_http3_handle_priority_frame"

I wonder if you could use AI to classify the probability factor that something is AI bullshit and deprioritize it?

Re: Curl: We still have not seen a valid security report done with AI help

#74
post #72

Earlier quoted context omitted.

It's the 2025 version of lmgtfy.

Nah, that’s different. Lmgtfy has nothing to do with experience, other than experience in googling. Lmgtfy applies to stuff that can expediently be googled.

In my experience, usually what people had done was take your question on a forum, go to lmgtfy, paste the exact words in and then link back to it. As if to say "See how easy that was? Why are you asking us when you could have just done that?"

Yes is true there could have been a skill issue. But it could also be true that the person just wanted input from people rather than Google. So that's why I drew the connection.

Re: Curl: We still have not seen a valid security report done with AI help

#75
post #72

Earlier quoted context omitted.

Nah, that’s different. Lmgtfy has nothing to do with experience, other than experience in googling. Lmgtfy applies to stuff that can expediently be googled.

In my experience, usually what people had done was take your question on a forum, go to lmgtfy, paste the exact words in and then link back to it. As if to say "See how easy that was? Why are you asking us when you could have just done that?" Yes is true there could have been a skill issue. But it could also be true that the person just wanted input from people rather than Google. So that's why I drew the connection.

I largely agree with your description, and I think that’s different from the above case of explicitly asking for experience and then someone posing the question to an LLM. Also, when googling, you typically (used to) get information written down by people, from a much larger pool and better curated via page ranking, than whoever you are asking. So it’s not like you were getting better quality by not googling, typically.

Re: Curl: We still have not seen a valid security report done with AI help

#77

Earlier quoted context omitted.

It is supremely annoying when i ask in a group if someone has experience with a tool or system and some idiot copies my question into some LLM and paste the answer. I can use the LLM just like anyone, if i'm asking for EXPERIENCE it is because I want the opinion of a human who actually had to deal with stuff like corner cases.

It's the 2025 version of lmgtfy.

That’s exactly how I feel

Re: Curl: We still have not seen a valid security report done with AI help

#78
post #70

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

Wow that's a wildly cynical interpretation of what someone is saying. Maybe it's right, but I think it's equally likely that people are saying that to give you the right context. If they're saying it to you, why wouldn't you assume they understand and trust what they came up with? Do you need people to start with "I understand and believe and trust what I'm about to show you ..."?

I do not need people to lead on that. That’s precisely why leading on “I asked ChatGPT and it said…” makes me trust something less — the speaker is actively assigning responsibility for what’s to come to some other agent, because for one reason or another, they won’t take it on themselves.

Re: Curl: We still have not seen a valid security report done with AI help

#79
post #55
post #48

Earlier quoted context omitted.

How do you know that ChatGPT is teaching you about the topic? It doesn't know what is right or what is wrong.

It can consult any sources about any topic, ChatGPT is as good at teaching as the pupil's capabilities to ask the right questions, if you ask me

It may well consult any source about the topic, or it may simply make something up.

If you don't know anything about the subject area, how do you know if you are asking the right questions?

Re: Curl: We still have not seen a valid security report done with AI help

#80

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I recently had this happen from a senior engineer. What's really frustrating is I TOLD them the issues and how to fix it. Instead of listening to what I told them, they plugged it into GPT and responded with "Oh, interesting this is what GPT says" (Which, spoiler, was similar but lacking from what I'd said). Meaning, instead of listening to a real-life expert in the company telling them how to handle the problem they…

If I had a dollar for every time I told someone how to fix something and they did something else...

Let's just say not listening to someone and then complaining that doing something else didn't work isn't exactly new.

Post reply on HN