Live data from Hacker News

Death by a Thousand Slops

daniel.haxx.se

41–50 of 149 posts

Re: Death by a Thousand Slops

#41

[flagged]

No, we don't. AI slop is a worldwide phenomenon.

Looking at just the users who submitted the reports on curl's AI slop list:

* 4 users accounts are now closed/banned, so I don't know their activity

* 12 users have only submitted invalid/spam reports to curl, and nobody else. They probably just open a new account each time, and they can come from anywhere, and claim to be anyone.

* 5 users have at least one accepted report (to curl or anywhere else). These should be people who care about their reputation, and yet they've been caught submitting AI slop at least once.

Of those 5, one is from Florida, USA, one is from Noida, India, and the other 3 don't disclose their location.

Re: Death by a Thousand Slops

#42
These AI reports are just an acceleration of the slop created by similar human “researchers”. The real root cause of this is that most security “professionals” have been trained to do the bare minimum of work and expect a payday from it.

There’s an entire industry of “penetration testers” that do nothing more than run Fortify against your code base and then expect you to pay them $100k for handing over the findings report. And now AI makes it even easier to do that faster.

We have an industry that pats security engineers on the back for discovering the “coolest” security issue - and nothing that incentivizes them to make sure that it actually is a useful finding, or more importantly, actually helping to fix it. Even at my big tech company, where I truly think some of the smartest security people work, they all have this attitude that their job is just to uncover an issue, drop it in someone else’s lap, and then expect a gold star and a payout, never mind the fact that their finding made no sense and was just a waste of time for the developer team. There is an attitude that security people don’t have any responsibility for making things better - only for pointing out the bad things. And that attitude is carrying over into this AI slop.

There’s no incentive for security people to not just “spray and pray” security issues at you. We need to stop paying out but bounties for discovering things, and instead better incentivize fixing them - in the process weeding out reports that don’t actually lead to a fix.

Re: Death by a Thousand Slops

#43

Earlier quoted context omitted.

Genuine question; if you cant tell, why does it matter?

It's a fair question and one that I've asked myself as well. I like to use the example of chess. I know that computers can beat human players and that there are technical advancements in the field that are useful in their own right, but I would never consistently watch a game of chess played between a computer and a human. Why? Because I don't care for it. To me, the fun and excitement is in seeing what a HUMAN can a…

But how can't you tell?

To me AI generated art without repeated major human interventions is almost immediately obvious. There are things it just can't do.

Re: Death by a Thousand Slops

#44
post #3

I think eventually all OSS projects/repos will suffer with this. My bet is that git hosting providers like GitHub etc. should start providing features to allow us for better signal/noise ratio

Githubs owner is betting the farm on pushing slop, so that seems unlikely to happen there anytime soon.

They just need to offer you more slop to review the slop and give it a sloppiness score.

Re: Death by a Thousand Slops

#45

For all the discussions about the slopification of the internet, the human toll on open source maintainers isn’t really talked about. It's one thing to get flooded with bad reports; it's another to have to mentally filter AI-generated submissions designed to "sound correct" but offer no real value. Totally agree with the author mentioning the emotional toll it takes to deal with these mind-numbing stupidities.

this type of social moderation exist well over decade and FB had thousands of people hired for these. They were filtering liveleak level or even worse type of content for years with human manually watching or flagging the content. So nothing new.

> hired

Do remember "we're" (hi, interjecting) talking about open source maintainers, we didn't all make curl or Facebook

Re: Death by a Thousand Slops

#46

These AI reports are just an acceleration of the slop created by similar human “researchers”. The real root cause of this is that most security “professionals” have been trained to do the bare minimum of work and expect a payday from it. There’s an entire industry of “penetration testers” that do nothing more than run Fortify against your code base and then expect you to pay them $100k for handing over the findings r…

Oh yes. AI has nothing to do with it! It is Totally Outrageous and Unexpected that AI would be abused to spew a lot of low value crap.

Haha, I kid. Make no mistake, this is the AI sales pitch. A *weapon* to use on your opposition. If the hackers were trying to win by using it to wear down the defenders it could not possibly be working better.

Re: Death by a Thousand Slops

#48
post #18

Earlier quoted context omitted.

> but offer no real value They could offer value, but just rarely, at least with the LLM/model/context they used. > toll it takes to deal with these mind-numbing stupidities. Could have a special area for submitting these where AI does the rejection letter and banning.

>They could offer value, but just rarely, at least with the LLM/model/context they used. Eating human excrement can also offer value in the form of undigested pieces of corn and other seeds. Are you interested?

Funnily enough, fecal transplants (Fecal Microbiota Transplants, FMT) are a thing, used to help treat a range of diseases. It’s even being investigated to help treat depression.

So…

Re: Death by a Thousand Slops

#49

Earlier quoted context omitted.

It's a fair question and one that I've asked myself as well. I like to use the example of chess. I know that computers can beat human players and that there are technical advancements in the field that are useful in their own right, but I would never consistently watch a game of chess played between a computer and a human. Why? Because I don't care for it. To me, the fun and excitement is in seeing what a HUMAN can a…

But how can't you tell? To me AI generated art without repeated major human interventions is almost immediately obvious. There are things it just can't do.

For the most part I can actually tell, but it also depends on the style of the art. A lot of anime-inspired digital images are immediately obvious - AI tends to add quite a lot of "shine" to its output, if that makes sense. And it's way too clean, sterile even. And it all looks the same.

But when the art style is more minimalist or abstract, I find it genuinely difficult to notice a difference and have to start looking at the finer details, hence the mental workload comment. Often times I'll notice an eye not facing the right direction or certain lines appearing too "repetitive", something I rarely see in the works of human artists. It's difficult to explain without actual inage examples in front of me.

Re: Death by a Thousand Slops

#50

These AI reports are just an acceleration of the slop created by similar human “researchers”. The real root cause of this is that most security “professionals” have been trained to do the bare minimum of work and expect a payday from it. There’s an entire industry of “penetration testers” that do nothing more than run Fortify against your code base and then expect you to pay them $100k for handing over the findings r…

Oh yes. AI has nothing to do with it! It is Totally Outrageous and Unexpected that AI would be abused to spew a lot of low value crap. Haha, I kid. Make no mistake, this is the AI sales pitch. A *weapon* to use on your opposition. If the hackers were trying to win by using it to wear down the defenders it could not possibly be working better.

It is at the same time being used to tear down faith in democracy, all open content in the Internet, workers' autonomy, and generally serving to attempt to make all thought derivative while minimizing incentives to create anything new that isn't an AI
Post reply on HN