Live data from Hacker News

SQLite Critical CVEs or LLM Slop?

research.jfrog.com

291–300 of 406 posts

Re: SQLite Critical CVEs or LLM Slop?

#291
post #264

Earlier quoted context omitted.

What fields do you see devs think they know about? I’ve never personally seen this with other devs I work with but obviously small sample size…

find any econ related post on hn et voila

I don't think it is much of a problem that dabblers get into Internet arguments about things they are not experts in. After all the easiest way to get a correct answer/learn something is to say something wrong.

Of course this should be differentiated from a professional setting.

And under no circumstances should we put that stuff into the knowledge bases we base our "AI" on without making sure it takes into account the context.

Re: SQLite Critical CVEs or LLM Slop?

#292
post #52

We can chalk this up as another example of over-exhuberance by what folks believe LLMs can accomplish vs. what they actually are. LLM-based “AI” is able to use its vast corpus of inputs and calculate the most statistically likely output in a given situation. It is probabilistic, and when you are dealing with probabilities in a situation where certainties, not probabilities, matter, you’re going to get dinged on credi…

Does a dog possess intelligence? Does a bird? Does a cricket? An amoeba?

I hate AI slop as much as the next guy but the amount of tribalism over AI is taking near-religious forms.

Nobody knows what intelligence is, therefore we don't know what does or does not possess it, therefore we don't know whether LLMs currently, or in the future, possess it.

Yes, LLMs can be stupid, guess what: so can I. That doesn't really change the argument at all.

I feel like I'm on a deja-vu from when DALL-E was released and everybody was fighting over whether AI can be creative yes or no. Same story, different words.

Intelligence, creativity: we have no idea what these words mean, and AI is helping us understand them better. That alone is an achievement of epic proportions. I am not joking here. Any computer scientist before 2015 would be absolutely blown away by what you can now do for 10 cents and an API call, yet somehow because of the tech-bro-iness of it all we get a tribal war over what is plainly visible in front of us:

LLMs are uncomfortably close to what we thought intelligent machines would look like

Re: SQLite Critical CVEs or LLM Slop?

#293

Earlier quoted context omitted.

May I suggest the excellent & recent book: "The brain. In theory" by Romain Brette? This is going to elevate your thinking on this no end, if you're interested.

Looks interesting (added to my list, thank you for the recommendation), but not actually relevant to the topic at hand. We know that the brain is a probabilistic input → output machine because the universe is a probabilistic input → output machine. The brain is made of universe. There are deterministic relationships (which at high sensitivity or complexity become easier to describe as probabilistic), and quantum rela…

You're a fast reader :-D

No quantum bullshittery in there I promise.

Equating "classical" with "deterministic" is however pushing it a bit too far, when no one and nothing can ever do even a very small fraction of said determination...

Re: SQLite Critical CVEs or LLM Slop?

#294

Earlier quoted context omitted.

Also a buffer overflow in user space for a tool not serving internet traffic is not a big deal.

I would be careful with this line of thought: opening a malformed archive that gets you into user space is often the first step in a chain-of-attacks that ends up winning Pwn2Own, so I think that a 8-ish score makes sense for it. It won't be enough to do much on its own, but for the past decade or so it's been all about chaining enough small things together to get root, rather than single points of failure. I keep fe…

We should track and fix buffer overflows.

And you’re right, I don’t know all the ways this can be combined with other attacks related to the shell.

But when I design a system the security people at work tell me to assume any bad thing can happen in a user process and design the process isolation and policies to contain it.

Entire categories of attacks (Dos) etc are futile to do anything in user space. Just limit resources and call it a day.

Re: SQLite Critical CVEs or LLM Slop?

#295

Earlier quoted context omitted.

find any econ related post on hn et voila

I don't think it is much of a problem that dabblers get into Internet arguments about things they are not experts in. After all the easiest way to get a correct answer/learn something is to say something wrong. Of course this should be differentiated from a professional setting. And under no circumstances should we put that stuff into the knowledge bases we base our "AI" on without making sure it takes into account t…

There have always been people with no tech experience building startups generating spaghetti code. It's just that now it looks a lot more polished.

Re: SQLite Critical CVEs or LLM Slop?

#296

Earlier quoted context omitted.

find any econ related post on hn et voila

I don't think it is much of a problem that dabblers get into Internet arguments about things they are not experts in. After all the easiest way to get a correct answer/learn something is to say something wrong. Of course this should be differentiated from a professional setting. And under no circumstances should we put that stuff into the knowledge bases we base our "AI" on without making sure it takes into account t…

[deleted]

Re: SQLite Critical CVEs or LLM Slop?

#297

Earlier quoted context omitted.

I don't think it is much of a problem that dabblers get into Internet arguments about things they are not experts in. After all the easiest way to get a correct answer/learn something is to say something wrong. Of course this should be differentiated from a professional setting. And under no circumstances should we put that stuff into the knowledge bases we base our "AI" on without making sure it takes into account t…

There have always been people with no tech experience building startups generating spaghetti code. It's just that now it looks a lot more polished.

> It's just that now it looks a lot more polished.

Yes, and that is the problem. It used to be if a product looked polished it was fairly polished engineering wise as well if we compare to todays AI slop. You can see that on steam, before AI slop games a game that looked polished mostly worked. But today you can get a game that looks like they put in a lot of effort, but its all AI slop and everything is flaky and broken, I've had way more such experiences the last few months than before that.

A human coder that was capable of coding a complex game typically also was good enough and tested things to make most things work. There were bugs etc, but at least buttons did things.

Re: SQLite Critical CVEs or LLM Slop?

#298

Earlier quoted context omitted.

There is no reason to think that teapots were sent into orbit or spontaneously formed there. Likewise, there is no reason to think the brain employs super-Turing or quantum computations that cannot be approximated by LLMs.

The point is that you're asking someone to prove a negative.

Right, it follows naturally that one can never meaningfully discuss that which can only be settled by proving negatives. Hence the total lack of debate on religious topics, as everyone just gave up 1500 years ago and decided that God indeed may or may not exist and that's that.

Re: SQLite Critical CVEs or LLM Slop?

#299
post #276

Earlier quoted context omitted.

I just prefer HN comments to be better reflections of reality. There is an unspoken expectation here that people here know what they’re talking about especially when it comes to technical matters. The rise of LLMs has given way to a HN branded populism that willingly denies reality as well. “Next token predictor” truthism is just so dumb and completely ignores the reality of what these tool are able to do. Smash that…

> I just prefer HN comments to be better reflections of reality. You mean your particular version of it. It's interesting to see you consistently missing this point. You've decided LLMs are clearly more than just complex but mindless statistical models. You've decided that based on, it seems, the very impressive things these tools are capable of. Therefore if anyone claims they're just mindless stastical models--with…

It’s just a boring and unhelpful complaint that afaict largely serves to soothe the commenters ego rather than point at anything insightful that’s useful or predictive. Point me to your favorite “next token predictor” comment that was actually insightful or predictive. You have years of material to draw from.

Re: SQLite Critical CVEs or LLM Slop?

#300
post #265
post #69

Earlier quoted context omitted.

One can hope that will put pressure on the industry to design a better system than CVEs. The signal noise ratio was already terrible before LLMs, I cannot imagine that will still be a meaningful system in 10y. But I’m too cynical to not consider all the middlemen who benefit from the status quo

It's going to be very very difficult to build this system as the exploitability of any particular CVE can massively vary depending on your system configuration. There are a lot of things that are bugs, but cannot be exploited in a standard configuration, most people would wonder why this is even a CVE. But then you have those users that would have the application, then something like a report module that was imported…

> There are a lot of things that are bugs, but cannot be exploited in a standard configuration

And this describes the vast majority of CVEs you see when you scan your dependencies. Typical case: Your regex library has a denial of service vulnerability for crafted regular expressions but your program never allows users to have any influence over the regex.

Post reply on HN