Live data from Hacker News

You did this with an AI and you do not understand what you're doing here

hackerone.com

341–350 of 571 posts

Re: You did this with an AI and you do not understand what you're doing here

#341

What is the motivation behind posting such things? I understand if there is a bug bounty program, does cURL have one?

Yes they do. But I also wonder why curl seems to get so many of these. They don't have the highest payouts, have been around for long time so presumably most low hanging fruit the AI has even a remote chance of finding was fixed, and they are well known to be on the lookout and strict about AI reports.

Might be easier for AI to generate this specific bullshit because of curl's long history.

Re: You did this with an AI and you do not understand what you're doing here

#342
post #183

Earlier quoted context omitted.

On Linux I just type (in sequence): compose - - and it makes an em dash, it takes a quarter of a second longer to produce this. I don't know why the compose key isn't used more often.

[As an English typer] Where is this compose key on my keyboard? (This is a vaguely Socratic answer to the question of why the compose key is not more often used.)

In Vim it's Ctrl+K. ;)

Re: You did this with an AI and you do not understand what you're doing here

#343
post #101

Nice ending: > The reporter was banned and now it looks like he has removed his account.

We are witnessing a new eternal summer and the only way to stem to tide is to increase the amount of required personal identifying information to register, and then publicly shame these people as a warning to others. Maybe it is a good thing that I don't run any massively popular open source projects.

> the only way to stem to tide is

I see no evidence thats the only way. Its the only way that has crossed your mind as you were writing that message.

Re: You did this with an AI and you do not understand what you're doing here

#344
post #26

Earlier quoted context omitted.

Some people actually do that on Github too. Absolute psychopaths.

I think the JS/Node scene was the pioneer in spamming emojis absolutely everywhere, well before AI. Maybe that's where the models picked it up from.

Remember, if you’re going to do this, also make liberal use of ansi codes.

Make sure terminal detection is turned off, and, for god’s sake, don’t honor the NO_COLOR environment variable.

Otherwise, people will be able to run your stuff in production and read the logs.

Re: You did this with an AI and you do not understand what you're doing here

#345
post #32

It's kind of depressing to read Daniel's article[1] on this issue given the rising "popularity" of these lazy attempts at cash grabbing. I hope they manage to combat the AI slop in a way that does not involve fighting fire with fire though. [1] https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-s...

I went through some of these and the one that stood out to me was this one https://hackerone.com/reports/2823554 Where the reporter says, "Sorry didnt mean to waste anyones time Badger, I thought you would be happy about this.". People using LLMs think they are helping but in reality, they are not.

There's this very weird idea that makes some people think that the maintainer must have a godawful workflow and if I just showed him the output of _my_ workflow, I can ~~save the day~~ fix a bug for them.

Re: You did this with an AI and you do not understand what you're doing here

#346
post #284

Earlier quoted context omitted.

Yea but you can always tell it’s an Indian because they write differently from actual English speakers.

Indian English is not only a perfectly good dialect, it's one of the most popular worldwide. It doesn't have the prestige of the King's English, but I'd personally prefer it to some of the other colonies'.

A dialect is not good just because it is popular.

Re: You did this with an AI and you do not understand what you're doing here

#347

Earlier quoted context omitted.

Fascinating trace — what you’ve essentially demonstrated here is not just a failed TLS handshake culminating in a 500, but the perfect allegory for our entire discourse. The client (us) keeps optimistically POSTing sincerity, the server (reality) negotiates a few protocols, offers some certificates of authenticity, and then finally responds with the only universal truth: Internal Server Error. If helpful, I can follo…

Man you’re really good at that lol

Wait, this isn’t over yet.

Re: You did this with an AI and you do not understand what you're doing here

#348
post #45

Earlier quoted context omitted.

You do realize English is one of India's two official languages, I hope?

Yea but you can always tell it’s an Indian because they write differently from actual English speakers.

I feel like ‘actual English’ comes off as unnecessarily mean here. There is no ‘actual English’ there are just different regional and cultural variations.

You may personally like one or another better, you may find some particular varieties easier or harder to understand, but that doesn’t make those people any more or less ‘actual’ English speakers than you are. They are ‘actually’ speaking English, just like you.

If you wanted to phrase this in a less fraught way, you might say “Yea but you can almost always tell it’s an Indian because they tend to write characteristically distinct from English speakers” -

and I would agree with you, sentence structure and idioms do usually make it pretty easy to recognize.

Re: You did this with an AI and you do not understand what you're doing here

#349

Crazy how he doubled down by just pasting badger's answer into Chat and submitting the (hilariously obvious AI) reply: > Thanks for the quick review. You’re right — my attached PoC does not exercise libcurl and therefore does not demonstrate a cURL bug. I retract the cookie overflow claim and apologize for the noise. Please close this report as invalid. If helpful, I can follow up separately with a minimal C reproduc…

Is this for internet points?

If it's an individual, it could be as simple as portfolio cred ('look, I found and helped fix a security flaw in this program that's on millions of devices ')

Re: You did this with an AI and you do not understand what you're doing here

#350

Crazy how he doubled down by just pasting badger's answer into Chat and submitting the (hilariously obvious AI) reply: > Thanks for the quick review. You’re right — my attached PoC does not exercise libcurl and therefore does not demonstrate a cURL bug. I retract the cookie overflow claim and apologize for the noise. Please close this report as invalid. If helpful, I can follow up separately with a minimal C reproduc…

Was this all actually an agent? I could see someone making the claim that a security research LLM should always report issues immediately from an ethics standpoint (and in turn acquire more human generated labels of accuracy).

To be clear, I personally disagree with AI experiments that leverage humans/businesses without their knowledge. Regardless of the research area.

Post reply on HN