Live data from Hacker News

We stopped AI bot spam in our GitHub repo using Git's –author flag

archestra.ai

201–210 of 254 posts

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#201

Earlier quoted context omitted.

Possibly the worst idea I've heard this month. No one, meat or chip, would just set aside $10 "for the opportunity to contribute" This is "let them eat cake" level of out of touchness.

I have 3 PRs on https://github.com/django-oauth/django-oauth-toolkit/pulls that haven't been merged for OVER AN YEAR due to the maintaners being overloaded and who are expected to work on this for free. The fact that these PRs are not being promptly reviewed have cost me at least 3000€ in potential grant work. If I was told that I could make a deposit of $10 to get less stressed maintainers and a faster PR review cyc…

How did it cost you money in grant work? Can't you just fork and use that?

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#203

Earlier quoted context omitted.

> trying to optimize the number of potential random PRs. You're misrepresenting my comment. I didn't say at need to optimize, just consider. Don't strawman me here You can't just hand wave them away as if this isn't an important factor. If you don't care about them at all I got a much much simpler solution: don't allow issues or PRs. Problem solved! But that's not a real solution either

> You can't just hand wave them away as if this isn't an important factor.. There are plenty of ways to indicate in the project that the Pfand is meant as one way to filter out bad actors, but it doesn't mean that it should be the only way to accept external contributions. You can find somewhere else on the thread where I listed some alternatives that can be used as well. > If you don't care about them at all I got a…

If I have to trust you to give me back my $10, I'm never contributing to your code. Ever.

If I have to trust GitHub to give me back my $10, frankly, I have more trust for a random person on the internet at this point.

Also, you glossed over my banana joke, but it did hold meaning[0]

  > Yes, and what is the problem with [closing down PRs and Issues] solution?
Are you serious? I mean it is an acceptable solution but it's completely orthogonal to the one we've been discussing. I can see you're not serious. I was skeptical because the first comment, but thanks for making that clear now.

[0] https://www.youtube.com/watch?v=Nl_Qyk9DSUw

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#204
post #78

This is what we get for telling everyone how amazing AI is at writing code. It started with the people selling AI and for some reason tons of independent developers, some quite well respected in our field, piled on. Facebook now laying people off and saying it's because AI is just so good adds more fuel to the fire. Now you have a bunch of people fully confident that their AI friend is pumping out amazing code and su…

The astroturfing successfully broke a lot of people's brains

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#206

PR spam is a major problems for repo that run bounties. Maybe GitHub should temporarily block accounts from raising PRs if like 95%+ of them are getting rejected.

I've gotten tons of spam on repos that were purely ml research code. Things I saw copy pasted over hundreds of repos.

  > Maybe GitHub should temporarily block accounts from raising PRs if like 95%+ of them are getting rejected.
It's so bad I'd be okay with a lower bar where it's flagged if they're posting the same message over multiple repos... FFS they aren't even stopping this shit https://news.ycombinator.com/item?id=47964617

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#207
post #61

This is great example of the toxic effect money has on open source. Reward people with respect and recognition instead. Weird anonymous accounts no one's ever heard of will leave, because someone (or something) who's concealing their identity has nothing to gain from recognition. Honestly GitHub should have a real names policy. Because if you're not Satoshi Nakamoto then there's only three reasons I can think of to b…

> someone (or something) who's concealing their identity has nothing to gain from recognition

The xz supply chain attacker hid their real identity, created fakes one and gained recognition over time in order to gain more access and add the backdoor. So TLAs and other bad actors at least are interested in gaining recognition.

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#208
post #113

Is the solution to everything simply more catgirls [1]? Proof-of-work was, after all, about countering email spam. PR spam is but the latest in that long tradition. 1- https://anubis.techaro.lol

Anubis is actually not a cat. The original Egyptian deity is a god of death, and has a canine head. Anime catgirls and dog girls can look similar at first glance.

I believe they are referencing the person who wrote the program, not the name itself.

Re: We stopped AI bot spam in our GitHub repo using Git's –author flag

#210
post #207
post #61

This is great example of the toxic effect money has on open source. Reward people with respect and recognition instead. Weird anonymous accounts no one's ever heard of will leave, because someone (or something) who's concealing their identity has nothing to gain from recognition. Honestly GitHub should have a real names policy. Because if you're not Satoshi Nakamoto then there's only three reasons I can think of to b…

> someone (or something) who's concealing their identity has nothing to gain from recognition The xz supply chain attacker hid their real identity, created fakes one and gained recognition over time in order to gain more access and add the backdoor. So TLAs and other bad actors at least are interested in gaining recognition.

I know, right? It's like, finally—a threat actor who's intelligent enough to understand what capital means in the open source community and is willing to devote resources to engage with it authentically (even if it's for evil nefarious ends). The xz incident showed that the open source community has many other good defense mechanisms for verifying and spotting malicious work and then solving it. But we won't even get to play that game if we're inundated with anonymous agent spam so that GitHub can juice its MAU numbers. Maybe they should require every account buy a $40 yubikey. I don't know what the answer is. But I know that no one gains when your measure of success is driving the cost of burning open source developers out down to literally zero.
Post reply on HN