Live data from Hacker News

Death by a Thousand Slops

daniel.haxx.se

51–60 of 149 posts

Re: Death by a Thousand Slops

#51
post #12

Sort of separate but perhaps also relevant to the thousands cuts/slops: Isn't the scope of curl/libcurl a bit too big? It supports almost every file-related networking protocol under the sun and a few more just for fun. ( https://everything.curl.dev/protocols/curl.html ) Meanwhile 99.8% of users (assuming) just use it for HTTP. Here's a few complex protocols I bet many do not know that curl supports: - SMB - IMAP - L…

> Isn't the scope of curl/libcurl a bit too big?

No.

Re: Death by a Thousand Slops

#52

These AI reports are just an acceleration of the slop created by similar human “researchers”. The real root cause of this is that most security “professionals” have been trained to do the bare minimum of work and expect a payday from it. There’s an entire industry of “penetration testers” that do nothing more than run Fortify against your code base and then expect you to pay them $100k for handing over the findings r…

Oh yes. AI has nothing to do with it! It is Totally Outrageous and Unexpected that AI would be abused to spew a lot of low value crap. Haha, I kid. Make no mistake, this is the AI sales pitch. A *weapon* to use on your opposition. If the hackers were trying to win by using it to wear down the defenders it could not possibly be working better.

[deleted]

Re: Death by a Thousand Slops

#54
How about only sending submissions to humans if they include a reproducible test case? Actual compilable source code + payload that reproduces an attack. Would this be too easily gamed by security researchers as well?

Re: Death by a Thousand Slops

#55

And it's not just vulnerability reports that are affected by this general trend. I use social media, X specifically, to follow a lot of artists, mostly for inspiration and because I find it fun to share some of the work that other artists have created, but over the past year or so I find that the mental workload it takes for me to figure out if a particular piece of art is AI-generated is too much and I start leaning…

Genuine question; if you cant tell, why does it matter?

Much of what makes art fun is human effort and show of skill.

People post AI art to take credit for being a skilled artist, just like people posting others art as their own. Its lame.

If I am to be a bit controversial among artists; we're exposed to so much good art today that most art posted online is "average" at best. (The bar is so high that it takes 20+ years to become above average for most)

Its average even if a human posted it but fun because a human spent effort making something cool. When an ai generates average art its ... just average art. Scrolling google images to look at art is also pretty dull, because its devoid of the human behind.

Re: Death by a Thousand Slops

#56

Earlier quoted context omitted.

Genuine question; if you cant tell, why does it matter?

It's a fair question and one that I've asked myself as well. I like to use the example of chess. I know that computers can beat human players and that there are technical advancements in the field that are useful in their own right, but I would never consistently watch a game of chess played between a computer and a human. Why? Because I don't care for it. To me, the fun and excitement is in seeing what a HUMAN can a…

All the current active chess players learned by playing the computer repeatedly.

So what the human is achieving in this case is having been trained by AI.

Re: Death by a Thousand Slops

#57

Earlier quoted context omitted.

Genuine question; if you cant tell, why does it matter?

An olympic weightlifter doing clean and jerk with 150kg is worthy of my attention. A Komatsu forklift doing the same is not.

> A Komatsu forklift doing the same is not ... [worthy of attention]

It is, if you're managing a warehouse; then it's a wonderful marvel. And it is a hidden benefit to everyone who receives cheaper products from that warehouse. Nobody cares if it's a human or the Komatsu doing the heavy lifting.

Re: Death by a Thousand Slops

#59
As the only developer maintaining a big bounty program. I believe they are all trending downward.

I've recently cut bounties to zero for all but the most severe issues, hoping to refocus the program on rewarding interesting findings instead of the low value reports.

So far it's done nothing to improve the situation, because nobody appears to read the rewards information before emailing. I think reading scope/rewards takes too much time per company for these low value reports.

I think that speaks volumes about how much time goes into the actual discoveries.

Open to suggestions to improve the signal to noise ratio from anyone whose made notable improvements to a bug bounty program.

Re: Death by a Thousand Slops

#60
You could charge a fee and give the money back if the report is wrong but seems well-intentioned.

I see the issue with this, it's payment platforms. Despite the hate, cryptocurrency seems like it could be a solution. But in practice, people won't take time to set up a crypto wallet just to submit a bug report, and if crypto becomes popular, it may get regulations and middlemen like fiat (which add friction, e.g. chargebacks, KYC, revenue cuts).

However if more services use small fees to avoid spam it could work eventually. For instance, people could install a client that pays such fees automatically for trusted sites which refund for non-spam behavior.

Post reply on HN