Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

101–110 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#101
I handle reports for a one million dollar bug bounty program.

AI spam is bad. We've also never had a valid report from an by an LLM (that we could tell).

People using them will take any being told why a bug report is not valid, questions, or asks for clarification and run them back through the same confused LLM. The second pass through generates even deeper nonsense.

It's making even responding with anything but "closed as spam" not worth the time.

I believe that one day there will be great code examining security tools. But people believe in their hearts that that day is today, and that they are riding the backs of fire breathing hack dragons. It's the people that concern me. They cannot tell the difference between truth and garbage.

Re: Curl: We still have not seen a valid security report done with AI help

#102
post #58
post #57

Earlier quoted context omitted.

If it's not worth writing, it's not worth reading.

I mean, there is a lot of hand written crap to, so even that isn't a good rule.

>I mean, there is a lot of hand written crap to

You know how I know the difference between something an AI wrote and something a human wrote? The AI knows the difference between "to" and "too".

I guess you proved your point.

Re: Curl: We still have not seen a valid security report done with AI help

#103

There is or at various times was, nitter for twitter, Invidious for youtube, Imginn for instagram, and even many variations of ones for hackernews like hckrnews.com & ones that are lighter, work better in terminals, etc. Anything for linkedin, a light interface that doesn't required logging in? I pretty much stopped going to linkedin years ago because they started aggressively directing a person to login. I was shock…

> Anything for linkedin, a light interface that doesn't required logging in?

I just opened the site with JS off on mobile. No issues.

Re: Curl: We still have not seen a valid security report done with AI help

#104
post #93
post #76

Earlier quoted context omitted.

That rule does not imply the inverse

I mean we have automated systems that 'write' things like tornado warnings. Would you rather we have someone hand write that out? It seems the initial rule seems rather worthless.

[deleted]

Re: Curl: We still have not seen a valid security report done with AI help

#105
post #93
post #76

Earlier quoted context omitted.

That rule does not imply the inverse

I mean we have automated systems that 'write' things like tornado warnings. Would you rather we have someone hand write that out? It seems the initial rule seems rather worthless.

1. I think the warnings are generally "written" by humans. Maybe some variables filled in during the automation.

2. So a rule with occasional exceptions is worthless, ok

Re: Curl: We still have not seen a valid security report done with AI help

#106
post #40
post #35

Earlier quoted context omitted.

>but the three "sources" you mention are not worth much either, much like ChatGPT. I don't think I've ever seen anyone lambasted for citing stackoverflow as a source. At best, they chastised for not reading the comments, but nowhere as much pushback as for LLMs.

From what I’ve seen, Stack Overflow answers are much more reliable than LLMs. Also, using Stack Overflow correctly requires more critical thinking. You have to determine whether any given question-and-answer is actually relevant to your problem, rather than just pasting in your code and seeing what the LLM says. Requiring more work is not inherently a good thing, but it does mean that if you’re citing Stack Overflow,…

[deleted]

Re: Curl: We still have not seen a valid security report done with AI help

#107
post #55
post #48

Earlier quoted context omitted.

How do you know that ChatGPT is teaching you about the topic? It doesn't know what is right or what is wrong.

It can consult any sources about any topic, ChatGPT is as good at teaching as the pupil's capabilities to ask the right questions, if you ask me

I like to ask AI systems sports trivia. It's something low-stakes, easy-to-check, and for which there's a ton of good clean data out there.

It sucks at sports trivia. It will confidently return information that is straight up wrong [1]. This should be a walk in the park for an LLM, but it fails spectacularly at it. How is this useful for learning at all?

[1] https://news.ycombinator.com/item?id=43669364

Re: Curl: We still have not seen a valid security report done with AI help

#108

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I find that only acceptable (only little annoying) when this is some lead in case we're we have no idea what could be the issue, it might help to brainstorm and note that this is not verified information is important.

most annoying is when people trust chatgpt more that experts they pay. we had case when our client asked us for some specific optimization, and we told him that it makes no sense, then he asked the other company that we cooperate with and got similar response, then he asked chatgpt and it told him it's great idea. And guess what, he bought $20k subscription to implement it.

Re: Curl: We still have not seen a valid security report done with AI help

#109

Something that really frustrates me about interacting with (some) people who use AI a lot is that they will often tell me things that start “I asked ChatGPT and it said…” stop it!!! If the chatbot taught you something and you understood it, explain it to me. If you didn’t understand or didn’t trust it, then keep it to yourself!

I recently had this happen from a senior engineer. What's really frustrating is I TOLD them the issues and how to fix it. Instead of listening to what I told them, they plugged it into GPT and responded with "Oh, interesting this is what GPT says" (Which, spoiler, was similar but lacking from what I'd said). Meaning, instead of listening to a real-life expert in the company telling them how to handle the problem they…

You should ask yourself why this organization wants engineering advice from a chatbot more than from you.

I doubt the reason has to do with your qualities as an engineer, which must be basically sound. Otherwise why bother to launder the product of your judgment, as you described here someone doing?

Re: Curl: We still have not seen a valid security report done with AI help

#110
post #58
post #57

Earlier quoted context omitted.

If it's not worth writing, it's not worth reading.

I mean, there is a lot of hand written crap to, so even that isn't a good rule.

Both statements can be true at the same time, even though they seem to point in different directions. Here's how:

1. *"If it's not worth writing, it's not worth reading"* is a normative or idealistic statement — it sets a standard or value judgment about the quality of writing and reading. It suggests that only writing with value, purpose, or quality should be produced or consumed.

2. *"There is a lot of handwritten crap"* is a descriptive statement — it observes the reality that much of what is written (specifically by hand, in this case) is low in quality, poorly thought-out, or not meaningful.

So, putting them together:

* The first expresses *how things ought to be*. * The second expresses *how things actually are*.

In other words, the existence of a lot of poor-quality handwritten material does not invalidate the ideal that writing should be worth doing if it's to be read. It just highlights a gap between ideal and reality — a common tension in creative or intellectual work.

Would you like to explore how this tension plays out in publishing or education?

Post reply on HN