Live data from Hacker News

Death by a Thousand Slops

daniel.haxx.se

91–100 of 149 posts

Re: Death by a Thousand Slops

#91

Earlier quoted context omitted.

It's a fair question and one that I've asked myself as well. I like to use the example of chess. I know that computers can beat human players and that there are technical advancements in the field that are useful in their own right, but I would never consistently watch a game of chess played between a computer and a human. Why? Because I don't care for it. To me, the fun and excitement is in seeing what a HUMAN can a…

But how can't you tell? To me AI generated art without repeated major human interventions is almost immediately obvious. There are things it just can't do.

> To me AI generated art without repeated major human interventions is almost immediately obvious.

You can’t know that for sure. It’s the toupée fallacy.

https://rationalwiki.org/wiki/Toupee_fallacy

Re: Death by a Thousand Slops

#92

[flagged]

No, we don't. AI slop is a worldwide phenomenon. Looking at just the users who submitted the reports on curl's AI slop list: * 4 users accounts are now closed/banned, so I don't know their activity * 12 users have only submitted invalid/spam reports to curl, and nobody else. They probably just open a new account each time, and they can come from anywhere, and claim to be anyone. * 5 users have at least one accepted r…

> at least one accepted report anywhere else

From a previous post, some of the accepted reports elsewhere had suspicious titles, like if some projects are accepting everything.

Re: Death by a Thousand Slops

#93
post #57

Earlier quoted context omitted.

An olympic weightlifter doing clean and jerk with 150kg is worthy of my attention. A Komatsu forklift doing the same is not.

> A Komatsu forklift doing the same is not ... [worthy of attention] It is, if you're managing a warehouse; then it's a wonderful marvel. And it is a hidden benefit to everyone who receives cheaper products from that warehouse. Nobody cares if it's a human or the Komatsu doing the heavy lifting.

You just made me realise why many people have trouble with analogies, to the point it seems they are arguing in bad faith. You have to consider the context the analogy is being applied to.

It is patently obvious (though clearly not to every one) that the person you’re replying to is describing a situation of seeing a human weightlifter VS a mechanical forklift doing the same in a contest, for entertainment. The analogy works as a good example because it maps to the original post about art.

When you change the setting to a warehouse, you are completely ignoring all the context and trying to undermine the comment on a technicality which doesn’t relate at all to the point. If you want to engage with the analogy properly, you have to keep the original art context in mind at all times.

Re: Death by a Thousand Slops

#94
post #32

Earlier quoted context omitted.

I think looking at one example is useful: https://hackerone.com/reports/2823554 What they did was: 1) Prompt LLM for a generic description of potential buffer overflows in strcopy() and a generic demonstration code for a buffer overflow. (With no connection to curl or even OpenSSL at all) 2) Present some stack traces and grep results that show usage of strcopy() in curl and OpenSSL. 3) Simply claim that the strcopy()…

> The problem is in strcpy in the src files of curl.. have you seen the exploit code ?????? The worst part is that once they are asked for clarifications by the poor maintainers, they go on offense and become aggressive. Like imagine the nerve of some people, to use LLMs to try to gaslight an actual expert that they made a mistake, and then act annoyed/angry when the expert asks normal questions

Yep.

My guess is that the aggression is part of the ruse. Trying to start drama/intimidating the other when your bluff is being called out is the oldest strategy...

(You could see a similar pattern in the xz backdoor scheme, where they were deliberately causing distress for the maintainer to lower their guard.)

Or maybe the guy here hoped that the reviewers would run the demo - blindly - and then somehow believe it was real? Because it prints some scary messages and then does open a shell. Even if that's the only thing it does...

Re: Death by a Thousand Slops

#95
post #12

Sort of separate but perhaps also relevant to the thousands cuts/slops: Isn't the scope of curl/libcurl a bit too big? It supports almost every file-related networking protocol under the sun and a few more just for fun. ( https://everything.curl.dev/protocols/curl.html ) Meanwhile 99.8% of users (assuming) just use it for HTTP. Here's a few complex protocols I bet many do not know that curl supports: - SMB - IMAP - L…

You can always use another library with more limited use-cases if you're worried about scope. There are thousands of libraries for making HTTP requests, many of which are language-specific and much more ergonomic than libcurl.

However, curl/libcurl would cripple itself and alienate a good portion of its userbase if it stopped supporting so many protcols, and specific features of protocols.

There's a similar argument made all the time: "I only use 10% of this software". But it doesn't mean they should get rid of the other 90% and eliminate 100% of someone else's use of 10% of the software...

And the real trouble is, there's there's no guarantee that your bargain with the devil would actually reduce the number of false reports, or reduce the time needed to determine they're false. It does not appear that the report submitters directly correlate to size of attack surface. The example AI slop includes several reports that don't even call curl code, and yet the wording claims that they do. There's no limit to the scope of bad reports!

Re: Death by a Thousand Slops

#96

> charging a fee [...] rather hostile way for an Open Source project that aims to be as open and available as possible The most hostile is Apple where you cannot expect any kind of feedback on bug reports. You are really lucky if you get any kind of feedback from Apple. Getting good feedback is the most valuable thing ever. I don't mind having to pay $5/year to be make reports if I know I would get feedback.

> You are really lucky if you get any kind of feedback from Apple.

Hard disagree. When you get feedback from Apple, it’s more often than not a waste of time. You are lucky when you get no feedback and the issue is fixed.

Re: Death by a Thousand Slops

#97

And it's not just vulnerability reports that are affected by this general trend. I use social media, X specifically, to follow a lot of artists, mostly for inspiration and because I find it fun to share some of the work that other artists have created, but over the past year or so I find that the mental workload it takes for me to figure out if a particular piece of art is AI-generated is too much and I start leaning…

Genuine question; if you cant tell, why does it matter?

A human artist puts in work and passion to create beautiful art from almost nothing. It brings them joy that their art brings someone joy. Every art piece has a story behind it, sharing their art with others gives them motivations to not only continue doing it and bless the world with more art but it also gives them feedback that yes this art is liked by someone out there. This feedback loop is part of what creates healthy civilizations.

Re: Death by a Thousand Slops

#98
post #48

Earlier quoted context omitted.

>They could offer value, but just rarely, at least with the LLM/model/context they used. Eating human excrement can also offer value in the form of undigested pieces of corn and other seeds. Are you interested?

Funnily enough, fecal transplants (Fecal Microbiota Transplants, FMT) are a thing, used to help treat a range of diseases. It’s even being investigated to help treat depression. So…

I'm sure it does. But would you like one every other week like the llm slop?

Re: Death by a Thousand Slops

#99

And it's not just vulnerability reports that are affected by this general trend. I use social media, X specifically, to follow a lot of artists, mostly for inspiration and because I find it fun to share some of the work that other artists have created, but over the past year or so I find that the mental workload it takes for me to figure out if a particular piece of art is AI-generated is too much and I start leaning…

Genuine question; if you cant tell, why does it matter?

For the same reason dealing in counterfeit money matters — just because I can't tell it's fake doesn't mean the person I try to pay won't know or care. If your reputation is your currency, you don't want to damage it by promoting artwork that other people know is AI generated, so it's likely better to play it safe.
Post reply on HN