Live data from Hacker News

AI Slop vs. OSS Security

devansh.bearblog.dev

121–124 of 124 posts

Re: AI Slop vs. OSS Security

#121
post #9

> This is the fundamental problem: AI can generate the form of security research without the substance. I think this is the fundamental problem of LLMs in general. Some of the time looks just enough right to seem legitimate. Luckily the rest of the time it doesn’t.

No, it is the problem of any ceremonial barrier in existence. If substance wasn’t required in the first place, people were faking it already.

Re: AI Slop vs. OSS Security

#122
post #9

> This is the fundamental problem: AI can generate the form of security research without the substance. I think this is the fundamental problem of LLMs in general. Some of the time looks just enough right to seem legitimate. Luckily the rest of the time it doesn’t.

There's another term for this that I think should catch on: Cargo Culting

Everything looks right but misses the underlying details that actually matter.

There is a larger problem that I think we like to pretend that everything is so simple you don't need expertise. This is especially bad in our CS communities where there's a tendency of thinking intelligence in one domain cleanly transfers to others. In this respect I generally advise people not to first ask LLMs what they don't know but what they are experts in. That way they can properly evaluate their responses. Least we all fall for Murry Gelmann amnesia lol

https://en.wikipedia.org/wiki/Cargo_cult

Re: AI Slop vs. OSS Security

#123

The solution isn't to block aggressively or to allow everything, but to prioritize. Put accounts older than the AI boom at the top, and allow them to give "referrals", ie stake a part of their own credibility to boost another account on the priority ladder. Referral systems are very efficient at filtering noise.

Works only for old projects. What happens with new ones?

Re: AI Slop vs. OSS Security

#124
I think this piece was a good summary of the state of affairs.

If I would have written it, I would have perhaps mentioned that similar problems exist also in other domains, including science, arts, and media. Maybe the solutions might be similar too? I am particularly pointing toward the following quote that wasn't yet discussed here:

"New reporters could be required to have established community members vouch for them, creating a web-of-trust model. This mirrors how the world worked before bug bounty platforms commodified security research. The only downside is, it risks creating an insider club."

Post reply on HN