Live data from Hacker News

Half a Second – a book about the XZ backdoor

half-second.com

31–40 of 54 posts

Re: Half a Second – a book about the XZ backdoor

#31
post #13

Earlier quoted context omitted.

"free book" "no paywall and nothing to buy." Might this not actually be a reasonable purpose for AI? I can tolerate the quirky style and AI signatures for something honest and free.

Why not just post the prompt you used? I have access to LLMs too.

I have over 6gb of material resulting from interactions with AI. Even a micro-essay of mediocre quality requires dozens of prompts. Why post dozens and dozens of prompts if the final product is cleaner, and easier to process? I see utterly zero reason.

Edit: One of the things I learned quickly while working with LLMs, is that the quality of the user, the input, determines the quality of the output. Not everyone's input is of equal quality.

Re: Half a Second – a book about the XZ backdoor

#32

> The catch is where the book begins, not what it is about.

Half expecting the next few paragraphs to contain, verbatim, "The smoking gun was a performance issue in a development build of Debian. It's was a sharp observation, and sharper than you may think."

Re: Half a Second – a book about the XZ backdoor

#33
post #14

Earlier quoted context omitted.

In last month or two I noticed semicolons getting used where previously it would be em-dash, in both cases excessively and often incorrectly. I assumed some of my coworkers added "replace all em-dashes with semicolons" into their CLAUDE.md as a really crappy attempt at hiding their inability to write a single sentence without assistance.

Come on now, you can't also take away my semicolons. What am I supposed to do now; I barely have any punctuation left.

Embrace the inner Cormac McCarthy in you and abandon punctuation altogether

Re: Half a Second – a book about the XZ backdoor

#34
post #9

So Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core

no, someone who just happens to work for microsoft doing something at home did something good.

Re: Half a Second – a book about the XZ backdoor

#35
post #2

Given the time and effort that went into this, and the luck that one diligent person noticed, investigated and discovered what was going on before it could get further... it seems very likely to me that this has happened already in other libraries without being discovered.

Anybody running opensnitch would notice

Re: Half a Second – a book about the XZ backdoor

#36
post #19

Earlier quoted context omitted.

You'd know that if you'd done any research at all. Compare this to Jeff Guo (NPR) or Henry van Dyck (Veritasium) or my contact at the WSJ. They all investigated this story, interviewed key people (more people were interviewed for the Veritasium video than appeared), and fact-checked everything with subject matter experts. The NPR story took about 3 months of work and the Veritasium video took 5 months. I was intervie…

> You'd know that if you'd done any research at all. I'm not in the habit of researching the people who respond to me before I ask them about what their role was in something they seem proud of. I thought I was being polite by asking about it. That's really cool that you were interviewed, which of the interviews do you think most represents your hand in this? I wouldn't mind checking it out. I also really like Verita…

In this case all it required was to follow the link to their blog on their HN profile just FYI. Although your question was reasonable either way.

Re: Half a Second – a book about the XZ backdoor

#37
Here's the tool developed by the author that was almost certainly used to generate this book in its entirety - "A structured pipeline for writing long-form nonfiction, packaged as a Claude Code skill":

https://github.com/AdrianMastronardi/bookwright

There's nowhere near enough public information about the xz vuln to be worth turning into a book, so the merits of AI-generated text aside, this is just a very inefficient way to learn about the topic.

Re: Half a Second – a book about the XZ backdoor

#38
post #2

Given the time and effort that went into this, and the luck that one diligent person noticed, investigated and discovered what was going on before it could get further... it seems very likely to me that this has happened already in other libraries without being discovered.

The effort of gaining trust over an existing project isn't even really required. All you need to do is monitor when popular GitHub repos get archived. That's usually when the original authors don't want to work on it any more. Then just quickly make a fork to continue the project (think Phabricator -> Phorge), and if you're quick enough and authoritative sounding enough, boom control of the project!

Maintain it for a bit so people switch to your version, and job done.

Re: Half a Second – a book about the XZ backdoor

#40

Well, the "About the Author" section should probably just be a link to claude.ai.

For anyone wondering, here's the author confirming it

https://news.ycombinator.com/item?id=48966159

And here's their Claude skill for writing

https://github.com/AdrianMastronardi/bookwright

Post reply on HN