Live data from Hacker News

AI Slop vs. OSS Security

devansh.bearblog.dev

61–70 of 124 posts

Re: AI Slop vs. OSS Security

#61

You can address the issue by putting the report and the code base in a sandbox with an agent that tries to reproduce it. If it can't reproduce it then that should be a strike against the reporter. OSS projects should absolutely ban accounts that repetitively create reports that are of such low quality that it can't be recreated. IMO the Hacker One reputation mechanism is a good idea because it incentives users who op…

And who pays for the tokens?

Re: AI Slop vs. OSS Security

#62
post #18

Earlier quoted context omitted.

Copyleft licenses are made to support freedom for everyone and particularly end-users. They only limit freedom of developers / maintainers to exploit the code and users. > Does GPL help the linux kernel get investment from it's corporate users? GPL has helped "linux kernel the project" greatly, but companies invest in it out of their self-interest. They want to benefit from upstream improvements and playing nicely by…

I would have thought supporting libcurl and libxml would also be in a company's self-interest. Is that companies do this for GPL'ed linux kernel but not BSD evidence that strong copyleft licensing limits the extent to which OSS projects are exploited/under-resourced?

  > I would have thought supporting libcurl and libxml would also be in a company's self-interest.
Unfortunately majority of companies don't have something special they really need to add to cURL. They okay using it as is - so they have no reason to pay salary to cURL developers regardless of licensing.

Yes they want it to be secure, but as always nobody except few very large orgs care about security for real.

  > Is that companies do this for GPL'ed linux kernel but not BSD evidence that strong copyleft licensing limits the extent to which OSS projects are exploited/under-resourced?
It certainly helped with "under-resourced" part. Whatever you considered "exploited" is up to discussion. From project perspective ofc copyleft licensing benefited the project.

Linus Torvalds end up with a good amount of publicity and is now somewhat well set-off, but almost all other kernel developers live in obscurity earning somewhat average salaries. I pretty sure we can all agree that Linux Kernel made a massive positive impact on whole humanity and compared to that payoff to stakeholders is rather small IMO.

Re: AI Slop vs. OSS Security

#63

Ironically, even this piece is significantly AI-generated: - Primarily relies on a single piece of evidence from the curl project, and expands it into multiple paragraphs - "But here's the gut punch:", "You're not building ... You're addressing ...", "This is the fundamental problem:" and so many other instances of Linkedin-esque writing. - The listicle under "What Might Actually Work"

My least favourite part of this timeline: anyone who writes well gets classified as AI. Some of us press Option+- to insert an em dash and have been for years.

AI does not write well. People who write as AI are not the people writing well.

Re: AI Slop vs. OSS Security

#64

Ironically, even this piece is significantly AI-generated: - Primarily relies on a single piece of evidence from the curl project, and expands it into multiple paragraphs - "But here's the gut punch:", "You're not building ... You're addressing ...", "This is the fundamental problem:" and so many other instances of Linkedin-esque writing. - The listicle under "What Might Actually Work"

My least favourite part of this timeline: anyone who writes well gets classified as AI. Some of us press Option+- to insert an em dash and have been for years.

I've been using the compose key for over a decade but only recently discovered you can type compose to produce an em dash. Before then, I always just typed a double-dash (--) to simulate it.

Re: AI Slop vs. OSS Security

#65

Ironically, even this piece is significantly AI-generated: - Primarily relies on a single piece of evidence from the curl project, and expands it into multiple paragraphs - "But here's the gut punch:", "You're not building ... You're addressing ...", "This is the fundamental problem:" and so many other instances of Linkedin-esque writing. - The listicle under "What Might Actually Work"

Pretty sad that they didn't even try our antislop sampler. Slop in LLM outputs is a choice: https://arxiv.org/abs/2510.15061

Re: AI Slop vs. OSS Security

#66
post #45
post #29

Earlier quoted context omitted.

Exactly and this is hell for programming. You don't know whose style the LLM would pick for that particular prompt and project. You might end up with Carmack or maybe that buggy, test-failing piece of junk project on Github.

You can tell it who's style to copy, it's actually decent at following instructions like that.

It's not bad at following my own style. I have longstanding quirks like naming any string that will end up in a DB query with a "q_" in front of the variable name, and shockingly Claude picks up on those and mimicks them. Wouldn't trust it to write anything without thorough review, but it's great at syntax.

Re: AI Slop vs. OSS Security

#67
post #20

Ironically, even this piece is significantly AI-generated: - Primarily relies on a single piece of evidence from the curl project, and expands it into multiple paragraphs - "But here's the gut punch:", "You're not building ... You're addressing ...", "This is the fundamental problem:" and so many other instances of Linkedin-esque writing. - The listicle under "What Might Actually Work"

Yesterday my wife burst into my office: "You used AI to generate that (podcast) episode summary, we don't sound like that!" In point of fact, I had not. After the security reporting issue, the next problem on the list is "trust in other people's writing".

I blogged about this fundamental demolition of trust a few months ago.

HN discussed it here https://news.ycombinator.com/item?id=44384610

The responses were a surprisingly mixed bag. What I thought was a very common sense observation had some heavy detractors in those threads.

Re: AI Slop vs. OSS Security

#69

Earlier quoted context omitted.

I'm so sick of people claiming things sound like AI, when it's so easily not true. Between this and the flip side of AI-slop it's getting really frustrating out here online.

I think people sometimes jump the gun over small things (emdashes, etc). That said, in this instance, your anger is very likely misdirected. The article is almost certainly substantially AI-generated.

I mean, I guess I just don't care as much, as long as the author proof read it and it says what they want it to say. Just like I don't care if an AI submits a vulnerability report that is actually real.

Re: AI Slop vs. OSS Security

#70

You can address the issue by putting the report and the code base in a sandbox with an agent that tries to reproduce it. If it can't reproduce it then that should be a strike against the reporter. OSS projects should absolutely ban accounts that repetitively create reports that are of such low quality that it can't be recreated. IMO the Hacker One reputation mechanism is a good idea because it incentives users who op…

And who pays for the tokens?

Sandbox a third AI that just bets on AI stocks and crypto. Add a fourth AI to check the third AI's bets, and a fifth one to go on forums and pump the relevant equities. A sixth AI can short sell when the fourth AI gets overheated.
Post reply on HN