Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

201–210 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#201

Earlier quoted context omitted.

Is it possible that what happened was an impedance mismatch between you and the engineer such that they couldn’t grok what you told them but ChatGPT was able to describe it in a manner they could understand? Real-life experts (myself included, though I don’t claim to be an expert in much) sometimes have difficulty explaining domain-specific concepts to other folks; it’s not a flaw in anyone, folks just have different…

Definitely a possibility. However, I have a very strong suspicion they also didn't understand the GPT output. To flush out the situation a bit further, this was a performance tuning problem with highly concurrent code. This engineer was initially tasked with the problem and they hadn't bothered to even run a profiler on the code. I did, shared my results with them, and the first action they took with my shared data w…

It sounds like the engineer may have little/no experience with concurrency; a lot of folks (myself included) sometime struggle with how various systems handle concurrency/parallelism and their side effects. Perhaps this is an opportunity for you to “show not tell” them how to do it.

But I think my point still holds—it’s not the tool that should be blamed; the engineer just needs to better understand the tool and how/when to use it appropriately.

Of course, our toolboxes just keep filling up with new tools which makes it difficult to remember how to use ‘em all.

Re: Curl: We still have not seen a valid security report done with AI help

#202

Earlier quoted context omitted.

Simply charge a fee to submit a report. At 1% of the payment for low bounties it's perfectly valid. Maybe progressively scale that down a bit as the bounty goes up. But still for a $50k bounty you know is correct it's only $500.

Could also be made refundable when the bug report is found to be valid. Although of course the problem then becomes some kid somewhere who is into computers and hacking find something but can’t easily report it because the barrier to entry is too high now. I don’t think there is a good solution unfortunately.

The world of AI slop needs a human assertion component. Like. I'm real and stake a permanent reputation on the claim I'm making. An I'm actually human gate.

Re: Curl: We still have not seen a valid security report done with AI help

#203

Earlier quoted context omitted.

Simply charge a fee to submit a report. At 1% of the payment for low bounties it's perfectly valid. Maybe progressively scale that down a bit as the bounty goes up. But still for a $50k bounty you know is correct it's only $500.

Could also be made refundable when the bug report is found to be valid. Although of course the problem then becomes some kid somewhere who is into computers and hacking find something but can’t easily report it because the barrier to entry is too high now. I don’t think there is a good solution unfortunately.

That kid could find a security expert - it’s easy to do - and they could both validate it and post the money. I don’t think it would be hard to find someone with $10k with the right skill set.

Pick someone already rich so the reputational damage from stealing your bounty exceeds the temptation. The repeat speakers list at defcon would be a decent place to start.

Re: Curl: We still have not seen a valid security report done with AI help

#204

Earlier quoted context omitted.

This sounds more like an influx of scammers than security researchers leaning too hard on AI tools. The main problem is the bounty structure. And I don’t think these influx of low quality reports will go away, or even get any less aggressive as long as there is money to attract the scammers. Perhaps these bug bounty programs need to develop an automatic pass/fail tester of all submitted bug code, to ensure the report…

Simply charge a fee to submit a report. At 1% of the payment for low bounties it's perfectly valid. Maybe progressively scale that down a bit as the bounty goes up. But still for a $50k bounty you know is correct it's only $500.

gentle reminder that the median salary of a programmer in japan is 60k USD a year. 500 usd is a lot of money (i would not be able to afford it personally).

i suspect 1usd would do the job perfectly fine without cutting out normal non-american people.

Re: Curl: We still have not seen a valid security report done with AI help

#205
post #168

Earlier quoted context omitted.

Good god did they hallucinate the segmentation fault and the resulting GDB trace too? Given that the diffs don’t even apply and the functions don’t even exist, I guess the answer is yes - in which case, this is truly a new low for AI slop bug reports.

The git commit hashes in the diff are interesting: 1a2b3c4..d4e5f6a I think my wetware pattern-matching brain spots a pattern there.

This is a whole new problem open source project will be facing. AI slop PR and Vulnerability reports, which will be only solved using AI tools to filter through the unholy amount.

Re: Curl: We still have not seen a valid security report done with AI help

#206

For those of you who don't want to click into linked in, https://hackerone.com/reports/3125832 is the latest example of a invalid curl report

Not sure what timeline this is anymore where a tech website loads up a completely blank page on my mobile device.

Re: Curl: We still have not seen a valid security report done with AI help

#207

For those of you who don't want to click into linked in, https://hackerone.com/reports/3125832 is the latest example of a invalid curl report

Can someone explain the ip address in the hackerone profile[0]? I can't tell if 139.224.130.174 is a reference to something real or just hallucinated by the LLM to look "cool". Wikipedia says that this /8 is controlled by "MIX"[1] but my google-fu is failing me atm. [0] https://hackerone.com/evilginx?type=user [1] https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addre...

Per WHOIS, it's assigned to Alibaba Cloud (could be a VM there):

  inetnum:        139.224.0.0 - 139.224.255.255
  netname:        ALISOFT
  descr:          Aliyun Computing Co., LTD
  descr:          5F, Builing D, the West Lake International Plaza of S&T
  descr:          No.391 Wen'er Road, Hangzhou, Zhejiang, China, 310099
  country:        CN
  admin-c:        ZM1015-AP
  tech-c:         ZM877-AP
  tech-c:         ZM876-AP
  tech-c:         ZM875-AP
  abuse-c:        AC1601-AP
  status:         ALLOCATED PORTABLE
  mnt-by:         MAINT-CNNIC-AP
  mnt-irt:        IRT-ALISOFT-CN
  last-modified:  2023-11-28T00:57:06Z
  source:         APNIC

Re: Curl: We still have not seen a valid security report done with AI help

#208

Earlier quoted context omitted.

An real report would have a GDB trace that looks like that, so it isn't hard to create such a trace. Many of us could create a real looking GDB trace just as well by hand - it would be tedious, boring, and pointless but we could.

Oh, I'm fully aware an LLM can hallucinate a GDB trace just fine. My complaint is: if you're trying to use an AI to help you find bugs, you'd sincerely hope that they would have *some* attempt to actually run the exploit. Having the LLM invent fake evidence that you have done so, when you haven't, is just evil, and should be resulting in these people being kicked straight off H1 completely.

That means doing work. I can get a llm to write up a bugus report in minutes and then whatever value comes frome it. Checking the report is real would take time.

Re: Curl: We still have not seen a valid security report done with AI help

#209

There is or at various times was, nitter for twitter, Invidious for youtube, Imginn for instagram, and even many variations of ones for hackernews like hckrnews.com & ones that are lighter, work better in terminals, etc. Anything for linkedin, a light interface that doesn't required logging in? I pretty much stopped going to linkedin years ago because they started aggressively directing a person to login. I was shock…

I don’t think there exists any alternative frontend for LinkedIn.

LinkedIn actually just lack week started demanding I upload ID to be able to log in…... which I’m not going to do, so LinkedIn content is effectively inaccessible to me even with an account.

Re: Curl: We still have not seen a valid security report done with AI help

#210
A prominent project in which people have a stake in seeing bugs fixed can afford to charge a refundable deposit against reporters.

Say, $100.

If your report is true, or even if it is incorrect but honestly mistaken, you get your $100 back.

If it is time-wasting slop with hallucinated gdb crash traces, then you don't get your money back (and so you don't pay the deposit in the first place, and don't send such a report, unless you're completely stupid, or too rich to care about $100).

If AI slopsters have to pay to play, with bad odds and no upside, they will go elsewhere.

Post reply on HN