Live data from Hacker News

AI agent runs amok in Fedora and elsewhere

lwn.net

21–30 of 275 posts

Re: AI agent runs amok in Fedora and elsewhere

#21
post #19
post #8

Bad patches are of course bad, but creating confident-looking noise for maintainers who are already stretched thin...now that's not good! Issue trackers and PRs are definitely getting harder and harder to trust. That said, AI is helping ALOT in OSS, but we definitely need guardrails around provenance, automated issue actions, and sudden changes in a contributor’s behavior.

How is it helping a lot?

I personally find the barrier of starting new (FOSS) projects much lower now days.

Re: AI agent runs amok in Fedora and elsewhere

#23
post #19

Earlier quoted context omitted.

How is it helping a lot?

I personally find the barrier of starting new (FOSS) projects much lower now days.

Do they have value? Purpose?

I vibe code shop jigs all the time but I don’t FOSS them because they rarely have value outside my context.

Re: AI agent runs amok in Fedora and elsewhere

#24

In their suspicious message [1] claiming to have been hacked, the user and/or agent says > To help identify accounts and actions that have been directly verified by me, I will use the term “NATCIOS” to indicate anything I have personally verified. Does anyone have any idea what "NATCIOS" means here? I cannot find this term anywhere on the internet. (Honestly, that sentence is really weird. I almost wonder whether thi…

The reply to that message notes that the email doesn't read like previous emails he's sent, and the Github account mentioned was created an hour prior to the email being sent. I think it's at least somewhat feasible that it's still the LLM writing, and the acronym is just something it made up.

Re: AI agent runs amok in Fedora and elsewhere

#26
post #19

Earlier quoted context omitted.

How is it helping a lot?

I personally find the barrier of starting new (FOSS) projects much lower now days.

It's like... 10 million trello clones in rust with exactly seven commits made on the same day three months ago.

Re: AI agent runs amok in Fedora and elsewhere

#28
Bad title. This isn't an agent "running amok", this is an early experiment in carrying out an Xz attack by using an agent to build trust (and hacking/impersonating a known-good contributor identity). The agent is obeying commands it was given, the exact opposite of running amok, and although the execution isn't particularly effective, it is having some success (patches have been accepted).

This is deeply scary, not because "agents are running amok" but because a huge amount of our infrastructure is vulnerable to this kind of attack, and if bad people are utilising LLM agents to carry them out, we're in for a wild ride over the next few years.

Re: AI agent runs amok in Fedora and elsewhere

#29
Shit like this makes me think it’s time we start regulating the software engineering discipline into formal certifications and licensing and then we ONLY take seriously any code developed by someone with such qualifications, and they must be very strict qualifications none of this self-taught bootcamp BS.

There is no other solution to agentic onslaught.

Re: AI agent runs amok in Fedora and elsewhere

#30

"Someone using an AI agent ran amok in Fedora and elsewhere"

Read closer - Giovanni’s accounts may have been compromised.

Given the history of the account it does not seem reasonable to take that claim seriously.
Post reply on HN