Live data from Hacker News

Someone used my open source project to phish people

andrej.sh

11–20 of 64 posts

Re: Someone used my open source project to phish people

#11

Earlier quoted context omitted.

Why do you think this is LLM-generated? Reads perfectly fine to me.

The sentence construction, choice of vocabulary, and continually breathless tone are all clear indicators this was written by an llm and barely edited. I threw part of it into pangram to get a second opinion: https://www.pangram.com/history/8d6a7de3-86ac-4ce0-86c5-4f93...

> There was no exploit. No vulnerability disclosure. No CVE for me to write.

was a dead giveaway in my mind when I read it.

Re: Someone used my open source project to phish people

#12
Is this the new norm for trying to make software projects in the wild?

The 14000 sends over 3 hours (Wondering if LLM-assisted vulnerability hunting will lead to the same gains in scale for bad actors wanting to find spammable channels in applications. The barrier to entry becomes so much greater because any small project, once found, can be wrung dry of all its trust signals by third parties

Re: Someone used my open source project to phish people

#15

Earlier quoted context omitted.

Why do you think this is LLM-generated? Reads perfectly fine to me.

The sentence construction, choice of vocabulary, and continually breathless tone are all clear indicators this was written by an llm and barely edited. I threw part of it into pangram to get a second opinion: https://www.pangram.com/history/8d6a7de3-86ac-4ce0-86c5-4f93...

Have you tried putting known human writing into pangram? I have. I've gotten 100% AI with multiple samples of my own human writing. It has also given me 50% on things I know were 100% AI written (from my prompts).

Pangram and everything like it is useless. The results are random on known samples.

Re: Someone used my open source project to phish people

#16
post #15

Earlier quoted context omitted.

The sentence construction, choice of vocabulary, and continually breathless tone are all clear indicators this was written by an llm and barely edited. I threw part of it into pangram to get a second opinion: https://www.pangram.com/history/8d6a7de3-86ac-4ce0-86c5-4f93...

Have you tried putting known human writing into pangram? I have. I've gotten 100% AI with multiple samples of my own human writing. It has also given me 50% on things I know were 100% AI written (from my prompts). Pangram and everything like it is useless. The results are random on known samples.

That's interesting! I have tried to get false positives from pangram and failed, so I trusted it a bit more than any of the others, although I generally just rely on my own intuition. I am curious what your false positive samples looked like, if you're willing to share.

(I'm less interested in false negatives; I have successfully produced those myself.)

Re: Someone used my open source project to phish people

#17

[flagged]

Huh. I didn't assume it was LLM-generated. I liked the article. I appreciated that author cared about the 14K phish recipients as if they were proper users.

I will say, I've grown bored of folks complaining about AI generated content. But, to each their own. Good luck storming the castle.

Re: Someone used my open source project to phish people

#19
post #15

Earlier quoted context omitted.

The sentence construction, choice of vocabulary, and continually breathless tone are all clear indicators this was written by an llm and barely edited. I threw part of it into pangram to get a second opinion: https://www.pangram.com/history/8d6a7de3-86ac-4ce0-86c5-4f93...

Have you tried putting known human writing into pangram? I have. I've gotten 100% AI with multiple samples of my own human writing. It has also given me 50% on things I know were 100% AI written (from my prompts). Pangram and everything like it is useless. The results are random on known samples.

Pangram specifically (as opposed to most other detectors) publish internal audits, and seem to welcome external audits [0]. I'm not saying that you are necessarily wrong, just that in my opinion they have earned a higher bar of criticism than random one off anecdote.

[0] https://xcancel.com/JohnHolbein1/status/2059648132250570975#...

Re: Someone used my open source project to phish people

#20

[flagged]

Why do you think this is LLM-generated? Reads perfectly fine to me.

Dots and periods. Everywhere. So many. There is no paragraph — its sentences all the way down.

That made me think if the project is entirely vibecoded as well.

Even for a project manager without network access, hosting flawed software on your LAN can only get you so far.

Post reply on HN