Live data from Hacker News

You did this with an AI and you do not understand what you're doing here

hackerone.com

261–270 of 571 posts

Re: You did this with an AI and you do not understand what you're doing here

#262
post #159

Earlier quoted context omitted.

TIL that some people spell cooperate with an "ö". As a Swedish native it really breaks my reading of an English word, but apparently it's supposed to indicate that you should pronounce each "o" separately. Language is fun.

Using umlauts to signal that a vowel is pronounced separately is common in a number of languages (like Dutch).

That kind of use technically makes it a diaeresis, not an umlaut.

Re: You did this with an AI and you do not understand what you're doing here

#263
post #253
post #111

Earlier quoted context omitted.

The rationale is that the AI companies are selling the shovels to both generate this pile as well as the ones we'll need to clean it up.

I vividly remember the image of one guy digging a hole and another filling it with dirt as a representation of government bureaucracy and similar. Looks like office workers are gonna have the same privilege.

> I vividly remember the image of one guy digging a hole and another filling it with dirt as a representation of government bureaucracy and similar.

To be clear, it wasn’t dirt that I envisioned being shoveled.

Re: You did this with an AI and you do not understand what you're doing here

#264

Crazy how he doubled down by just pasting badger's answer into Chat and submitting the (hilariously obvious AI) reply: > Thanks for the quick review. You’re right — my attached PoC does not exercise libcurl and therefore does not demonstrate a cURL bug. I retract the cookie overflow claim and apologize for the noise. Please close this report as invalid. If helpful, I can follow up separately with a minimal C reproduc…

The '—' gave it away. No one types this character on purpose.

https://www.scottsmitelli.com/articles/em-dash-tool/

Re: You did this with an AI and you do not understand what you're doing here

#265
post #70

Is there something about cUrl that attracts these AI bots, or is it just better documented by them - because I was going to say that this is old, but then I checked the date and realized that this is a new problem. Going down the rabbit-hole, @badger has made multiple posts [0][1] about AI slop. [0] https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-s... [1] https://gist.github.com/bagder/07f7581f6e3d78ef37df…

My theory is that the cURL maintainer is independent and can respond forcefully to the "AI" nonsense.

Many other projects always have some corporate maintainers who are directed to push "AI" and will try to cover it up.

Re: You did this with an AI and you do not understand what you're doing here

#266

Earlier quoted context omitted.

It's all in aid of some streetsweeper being able to add "contributor to X, Y, Z projects!" to their GitHub résumé. Before LLMs were a thing I also received worthless spelling-incorrection pull requests with the same aim.

Are spelling correction PRs not welcome? I'd never put it on a résumé but if I'm following a README and I see a typo, I'll generally open a quick PR to fix that. (no automated tools, not scanning for typos, just a human reading a README).

> Are spelling correction PRs not welcome?

I think a true spelling correction would be welcome. But I think the kind BS attitude the GP is describing often leads to useless reformatting/language tweaks, because the goal isn't to make the repo better, it's to make a change for making a change's sake with as little effort as possible.

Re: You did this with an AI and you do not understand what you're doing here

#267
post #256

Earlier quoted context omitted.

This has been a norm on Hacker One for over a decade.

No, it hasn't. Even where people were just submitting reports from an automated vulnerability scanner, they had to write the English prose themselves and present the results in some way (either in an honest way, "I ran vulnerability scanner tool X and it reported that ...", or dishonestly, "I discovered that ..."). This world where people literally just act as a mechanical intermediary between an English chat bot and…

Slop Hacker One reports often include videos, long explanations, and, of course, arguments. It's so prevalent that there's an entire cottage industry of "triage" contractors that filter this stuff out. You want to say that there's something distinctive about an LLM driving the slop, and that's fine; all I'm saying is that the defining experience of a Hacker One bug bounty program has always been a torrent of slop.

Re: You did this with an AI and you do not understand what you're doing here

#268
post #9

This must be _absolutely exhausting_.

Yeah, I guess if I was him, I would just close issues silently and ban the person who created them, if possible. I don't think I could be as nice as he is.

> Yeah, I guess if I was him, I would just close issues silently and ban the person who created them, if possible. I don't think I could be as nice as he is.

I think the shaming the use of LLMs to do stuff like this is a valuable public service.

Re: You did this with an AI and you do not understand what you're doing here

#269
It’s really quite disappointing to see how fast just copy/pasting AI responses has proliferated, even into things that don’t benefit the copy/pasters. I’m doing an online course currently that has absolutely no benefit outside of learning the content (i.e. the certificate or whatever you get for completing means nothing) - yet classmates are very clearly just copying/pasting in responses for the exercises. How does that benefit them? More than any slop I’ve experienced thus far, this instance has made me the most worried/sad/pessimistic to see. If even people who are supposedly motivated to learn (why else would you pay for this course?) just revert to the easiest AI slop path, what hope do we have for avoiding it in stuff that more resembles “work”?

Re: You did this with an AI and you do not understand what you're doing here

#270
post #192

Earlier quoted context omitted.

* Trying 20.54.123.42:443... * Connected to api.openai.azure.com (20.54.123.42) port 443 (#0) * ALPN, offering h2 * ALPN, offering http/1.1 * successfully set certificate verify locations: * CAfile: /etc/ssl/certs/ca-certificates.crt * TLSv1.3 (OUT), TLS handshake, Client hello (1): * TLSv1.3 (IN), TLS handshake, Server hello (2): * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8): * TLSv1.3 (IN), TLS handshake,…

Fascinating trace — what you’ve essentially demonstrated here is not just a failed TLS handshake culminating in a 500, but the perfect allegory for our entire discourse. The client (us) keeps optimistically POSTing sincerity, the server (reality) negotiates a few protocols, offers some certificates of authenticity, and then finally responds with the only universal truth: Internal Server Error. If helpful, I can follo…

Man you’re really good at that lol
Post reply on HN