Live data from Hacker News

We will ban you and ridicule you in public if you waste our time on crap reports

curl.se

211–220 of 653 posts

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#211

Long time ago Sourceforge and then GitHub promoted into the current default the model of open source distribution which is not sustainable and I doubt it is something that the founding fathers of Free Software/Open Source had in mind. Open source licenses are about freedom of using and modifying software. The movement grew out of frustration that commercial software cannot be freely improved and fixed by the user to…

> I doubt it is something that the founding fathers of Free Software/Open Source had in mind.

Free Software sure, that wasn't the point.

Open Source, that was exactly the point. Eric S Raymond, one of the original promoters of the concept of Open Source coined Linus' Law:

    Given enough eyeballs, all bugs are shallow
Which definitely points in the direction of receiving bug reports and patches from users of the application. He was also a proponent of the Bazaar model, where software is developed in public, as opposed to the Cathedral model where software is only released in milestones (he used GCC and Emacs as examples, which reinforces the part of your statement about the Free Software movement in particular).

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#212

Earlier quoted context omitted.

> Indian students Is this cultural? I ran a small business some years ago (later failed) and was paying for contract work to various people. At the I perceived the pattern that Indian contractors would never ever ask for clarifications, would never say they didn't know something, would never say they didn't understand something, etc. Instead they just ran with whatever they happened to have in their mind, until I cal…

Indian here (~15+ years in tech). I've seen this behavior a lot, and unfortunately, I did some of this myself earlier in my career. Based on my own experience, here are a few reasons (could be a lot more): 1. Unlike most developed countries, in India (and many other develping countries), people in authority are expected to be respected unconditinally(almost). Questioning a manager, teacher, or senior is often seen as…

I've seen an interesting behavior in India. If I ask someone on the street for directions, they will always give me an answer, even if they don't know. If they don't know, they'll make something up.

This was strange. I asked a lot of Indian people about it and they said that it has to do with "saving face". Saying "I don't know" is a disgraceful thing. So if someone does not know the answer, they make something up instead.

Have you seen this?

This behavior appears in software projects as well. It's difficult to work like this.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#213

I am friends with a solo maintainer of a major open source project. He repeatedly complains that at the beginning of some semester, he sees a huge spike of false/unproveable security weakness reports / GutHub issues in the project. He thinks that there is a Chinese university which encourages their students to find and report software vulns as part of their coursework. They don’t seem to verify what they describe is…

In china medical students are required to publish original papers. Instead they just pay someone to write it for them and pollute the literature.

Medical? What's the point? I'm happy with 98% of doctors being able to handle known conditions and only the few percent that are really interested to do research.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#214
post #3

Context: [1, 2] > Open source code library cURL is removing the possibility to earn money by reporting bugs, hoping that this will reduce the volume of AI slop reports. > cURL has been flooded with AI-generated error reports. Now one of the incentives to create them will go away. [1] https://news.ycombinator.com/item?id=46701733 [2] https://etn.se/index.php/nyheter/72808-curl-removes-bug-boun...

Money for a report and a patch, with convincing test cases, might be worthwhile. Even if a machine generates them.

Not necessarily. Reviewing an issue report is already enough time. Reviewing a patch is even more developer time.

The problem they had before was a financial incentive to sending reports, leading to crap reports that wasted time to review. Incentivizing sending reports + patches has the same failure mode, but they now have to waste even more time to review the larger quantity of input.

Anyway, for most cases I'd bet that Daniel can produce and get reviewed a correct patch for a given security bug quicker than the curl team can review a third-party patch for the same, especially if it's "correct, but ai-written".

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#215

I think this is probably less effective than if there was some sort of "credit" or reputational score for reporting that seems like something GitHub would have the information to implement.

Why no go the other direction and make it hard to identify a user, so people do not do it for fame. Open source worked before people were using it as self advertisement.

Might even be good for Microsoft - they would be the only one knowing who is who.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#216
post #11

I've been helping a bit with OWASP documentation lately and there's been a surge of Indian students eagerly opening nonsensical issues and PRs and all of the communication and code is clearly 100% LLMs. They'll even talk back and forth with each other. It's a huge headache for the maintainers. I suggested following what Ghostty does where everything starts as discussions - only maintainers create issues, and PRs can…

> Indian students Is this cultural? I ran a small business some years ago (later failed) and was paying for contract work to various people. At the I perceived the pattern that Indian contractors would never ever ask for clarifications, would never say they didn't know something, would never say they didn't understand something, etc. Instead they just ran with whatever they happened to have in their mind, until I cal…

> never ever ask for clarifications, would never say they didn't know something, would never say they didn't understand something

I experienced this same thing working with offshore Indian contractors 20 years ago. Interesting to hear someone else echo my observations.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#217
post #11

I've been helping a bit with OWASP documentation lately and there's been a surge of Indian students eagerly opening nonsensical issues and PRs and all of the communication and code is clearly 100% LLMs. They'll even talk back and forth with each other. It's a huge headache for the maintainers. I suggested following what Ghostty does where everything starts as discussions - only maintainers create issues, and PRs can…

> Indian students Is this cultural? I ran a small business some years ago (later failed) and was paying for contract work to various people. At the I perceived the pattern that Indian contractors would never ever ask for clarifications, would never say they didn't know something, would never say they didn't understand something, etc. Instead they just ran with whatever they happened to have in their mind, until I cal…

I used to work with colleagues from China in contracting and I had the same experience with them. If they don't know something they have hard time saying that they don't know something or don't understand something.

Ficticious Example could be

Q: is this car red? A: it's not green. Q: yeah I know it's not green. But is it red? A: today is Thursday.

One thing I leaned it's not worth pressing forward and causing a scene. Instead it's better to use other ways of finding the information.

When guiding team members I always found it useful to have them explain back to me in their own words what they're tasked to do. It become immediately obvious if they were on the right track or not.

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#218
post #50

Earlier quoted context omitted.

worked well for a bit. but then the program became popular and that’s when it hit the curb. terrible loss, imo. it was a brilliant idea to encourage open source work with a token reward. it relied heavily on good intentions, which quickly disappeared with the popularity.

It’s still ongoing. The difference is they now no longer offer t-shirts (at one point they planted trees instead, unsure if that still happens), and projects must opt-in.

They offered T-Shirts in 2025

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#219
post #99

Earlier quoted context omitted.

You could easily guard against bullshit issues. So you can focus on what matters. If the issue is legit goes ahead to a human reviewer. If is run of the mill ai low quality or irrelevant issue, just close. Or even nicer: let the person that opened the issue to "argue" with the ai to further explain that is legit issue for false positives.

How is an llm supposed to identify an llm-generated bullshit issue...? It's the fox guarding the henhouse.

Just try and you'll see if it can work. Just copy paste some of these issues give context of the project and ask if makes sense

Re: We will ban you and ridicule you in public if you waste our time on crap reports

#220

I think this is probably less effective than if there was some sort of "credit" or reputational score for reporting that seems like something GitHub would have the information to implement.

This already exists on the previous platform curl was using (HackerOne), it does not prevent the slop.

At my previous employer, I had access to the company’s bug bounty submissions and I can assure you no matter what you try to do, people will submit slop anyway. This is why many companies will pay for “triage services” that do some screening to try to ensure that the exploit actually works.

Unfortunately this means that the first reply to many credible reports are from people who aren’t familiar with the service, meaning that reports often take a long time to be triaged for no reason other than the fact that the reporter assumed that the person reviewing the report would actually understand the product. It’s hard to write good, concise reports if you can’t assume this fact.

Honestly, I don’t know what can be done to fix all of this. It’s a bad situation for everyone involved, and only getting worse.

Post reply on HN