Live data from Hacker News

Bugtraq is back

lists.securityfocus.com

21–30 of 34 posts

Re: Bugtraq is back

#21

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.

It contains four emdashes, it overuses the Rule of Three (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...), it has the typical "not X, but Y" sentence, it unduly emphasizes the significance of Buqtrack (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...) ("preservation for the ages", really?).

Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.

Re: Bugtraq is back

#22
post #15

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.

I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.

Re: Bugtraq is back

#23
post #15

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.

Some hate mailing lists, not understanding how valuable the format and medium is. So they deride out of reflex, I suppose.

Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.

Re: Bugtraq is back

#24

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

> clearly 100% AI-generated First, show your working - just reads like generic announcement/PR speak from the last 30 years to me. Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in…

Pangram says 100% - "We believe that this entire text is AI."

Re: Bugtraq is back

#25
Interesting. But the styles chosen for hyperkitty displaying the archives is quite awful. Probably want either fixed width font or sensible reflow.

Re: Bugtraq is back

#26

Earlier quoted context omitted.

The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.

It contains four emdashes, it overuses the Rule of Three ( https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#... ), it has the typical "not X, but Y" sentence, it unduly emphasizes the significance of Buqtrack ( https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#... ) ("preservation for the ages", really?). Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to menti…

I think it's just regular corporate speech. LLMs do this, because they've learned on this kind of posts.

Re: Bugtraq is back

#27
post #15

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.

It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).

It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.

Re: Bugtraq is back

#29

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work. Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clea…

> clearly 100% AI-generated First, show your working - just reads like generic announcement/PR speak from the last 30 years to me. Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in…

I agree - most of my notifications do come right to my primary email and the discussion on these lists is invaluable to me. There's some really good ones with some of the smartest people in the world concentrated on them. Never had infosec twitter and don't want anything to do with it.

That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)

Re: Bugtraq is back

#30
post #15

Earlier quoted context omitted.

oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.

It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people). It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.

So where's the residue of vulnerabilities that don't get sent there? You know of anything better?
Post reply on HN