Earlier quoted context omitted.
I did not see it but I was not affected since I had pinned the tag and used a cool down; practices whose value I reminded my coworkers of with this post.
Pinning the tag will not save you - the tags were force-pushed. The cooldown probably did save you but you should check for the indicators of compromise listed on the security advisory page.
Attempts to post the latest Trivy security incident have been marked [dead]
21–28 of 28 posts
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#22Earlier quoted context omitted.
Oh that's clever. Use the spambot ring to promote the story so that the story gets marked dead because of that! Instead of hiding the news, use the botnet to promote it and use the system against itself.
I've noticed some HN posts get a higher-than-average number of replies from LLM bots. I've wondered if this has a downranking effect due to the upvote/comment ratio, and whether people might be using bots to do this intentionally. Alternatively it could just be that the bots "like" certain keywords more than others.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#23You should just mail hn@ycombinator.com about this stuff. Or: write a short blog post about it, and post that, on your (different) domain.
What if their goal is more to raise awareness about HN moderation practices than to fix the problem quickly? It's certainly worked. Lots of people have seen this and now have a slightly worse opinion of HN moderation.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#24Earlier quoted context omitted.
What if their goal is more to raise awareness about HN moderation practices than to fix the problem quickly? It's certainly worked. Lots of people have seen this and now have a slightly worse opinion of HN moderation.
> raise awareness about HN moderation practices What practices?
I feel like the answer to "What practices?" is obvious: "The reason the submissions were being killed is that the GitHub account's address had been banned on HN due to previously being submitted by spam bots."
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#25Earlier quoted context omitted.
> raise awareness about HN moderation practices What practices?
Are you asking them to be specific about what they dislike or something? I feel like the answer to "What practices?" is obvious: "The reason the submissions were being killed is that the GitHub account's address had been banned on HN due to previously being submitted by spam bots."
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#26Earlier quoted context omitted.
I've noticed some HN posts get a higher-than-average number of replies from LLM bots. I've wondered if this has a downranking effect due to the upvote/comment ratio, and whether people might be using bots to do this intentionally. Alternatively it could just be that the bots "like" certain keywords more than others.
Please email links to the bot comments to the mods so they can remove this manipulation and its effects.
Re: Attempts to post the latest Trivy security incident have been marked [dead]
#27Earlier quoted context omitted.
Please email links to the bot comments to the mods so they can remove this manipulation and its effects.
What's wrong with the report button?
‘flag’, if that’s what you mean, only sends a mathematical algorithm signal, that does not lead to mod attention. I flag posts that are dupes, irrelevant, low-effort, or are hard paywalled without a bypass link. This is often sufficient and is like sweeping cobwebs out of an ignored corner: it’s not worth getting upset about, just grab the broom and sweep it up and move on.
I email mods for issues that I think should be addressed to keep HN a better place than the voting/flag algorithms can solve without human assistance: guidelines violations like high-karma users insulting others, or patterns of behavior observed unflagged over time, or suspicion of voting rings; or technical issues with the xyz.com/subdomain detector that prevent self-linking detection from working, or with the auto-dead-ifier that’s the topic of this post, etc.
tl;dr nope, the mods monitor emails not flags