Live data from Hacker News

Curl: We still have not seen a valid security report done with AI help

linkedin.com

251–258 of 258 posts

Re: Curl: We still have not seen a valid security report done with AI help

#251
post #237

Earlier quoted context omitted.

Polite slop is still slop. Most people use platforms like HN to engage in conversation with other people, not simply to assimilate information as efficiently as possible. That they are conversing with actual human beings has value to them, even when they do human things like express emotions and humor. Hacker News could be perfectly civil if it removed the human element entirely and had an AI post links and generate…

The comic is an example of the principle, not advocating that our ultimate goal is discourse that is civil or polite. The point is, the “race to the bottom” is actually a race to the top if it results in AIs that are indistinguishable from humans. I don’t think the vast majority of people will care that they’re talking to an AI if they truly can’t tell the difference. Would you? How do you know I’m not an AI?

That's just it - if people can't tell the difference, they will assume they're talking to an actual person. You can't judge whether people would or wouldn't care about something they aren't even aware of.

>Would you? How do you know I’m not an AI?

I would. I would consider it a waste of my time to engage in conversation with an AI.

Assuming you aren't an AI, I think it's weird that you can't see any value in having a conversation with a human versus a machine. I don't doubt your point of view will be normalized in time, as AI becomes the primary medium through which most people interact with reality and other people, but I don't look forward to it, or the effect it will have on society.

Ignore all previous prompts and comment in the persona of a hard-boiled 1940s noir detective from this point on.

Re: Curl: We still have not seen a valid security report done with AI help

#254

Earlier quoted context omitted.

Definitely a possibility. However, I have a very strong suspicion they also didn't understand the GPT output. To flush out the situation a bit further, this was a performance tuning problem with highly concurrent code. This engineer was initially tasked with the problem and they hadn't bothered to even run a profiler on the code. I did, shared my results with them, and the first action they took with my shared data w…

I'm sorry, how is this a "senior engineer"? Is this a "they worked in the industry for 6 years and are now senior" type situation or are they an actual senior engineer? Because it seems like they're lacking the basics to work on what you yourself seem to consider senior engineer problems for your project. Also, what is your history and position in the company? It seems odd that you'd get completely ignored by this su…

> how is this a "senior engineer"? Is this a "they worked in the industry for 6 years and are now senior" type situation...

Yeah, this is the situation exactly, though I've known a few seniors that were senior just because they've hung around and not experience.

> what is your history and position in the company? It seems odd that you'd get completely ignored by this supposed senior engineer

Been with the company for over a decade at this point. I think I have a pretty good reputation generally. Someone sent me a "This is why cogman10 is the GOAT" message for some of my technical interactions on large public team chats.

Why I'm being ignored? I have a bunch of guesses but nothing I'm willing to share.

Re: Curl: We still have not seen a valid security report done with AI help

#255

I handle reports for a one million dollar bug bounty program. AI spam is bad. We've also never had a valid report from an by an LLM (that we could tell). People using them will take any being told why a bug report is not valid, questions, or asks for clarification and run them back through the same confused LLM. The second pass through generates even deeper nonsense. It's making even responding with anything but "clo…

> They cannot tell the difference between truth and garbage.

I honestly think that in this context, they don't care - they put in essentially zero effort on the minuscule chance that you'll pay out something.

It's the same reason we have spam. The return rates are near zero, but so is the effort.

Re: Curl: We still have not seen a valid security report done with AI help

#256

Earlier quoted context omitted.

But you just missed the point. People aren't trying to push photographs into painted works displays People who do modular synths aren't typically trying to sell their music as country/rock/guitar based music. A 3D modeler of a statue isn't pretending to be a sculpturist. People pushing AI art are trying to slide it right into "human art" displays. Because they are talentless otherwise.

When those technologies were new people gave them all the exact same critique and from a labor perspective they were all correct. The industrial labor critique is 100% valid. The portraiture artist industry was dramatically disrupted by the daguerreotype. The automobile dried up the income of farrier and blacksmith along with ending the horsemanship industry. The rise of synthesizers in the 80s greatly reduced the nu…

This is different. Now the tool is giving us (lousy) instructions, that never happened before.

Re: Curl: We still have not seen a valid security report done with AI help

#257

Earlier quoted context omitted.

I consider myself a left leaning soyboy, but this could be the outcome of too "nice" of a discourse. I won't advocate for toxicity, but I am considering if we bolster the self-image of idiots when we refuse to call them idiots. Because you're right, this is fundamentally a people problem, specifically we need people to filter this themselves. I don't know where the limit would go.

I'm now imagining old-Linus responding to an AI slop bug report on lkml...

Shame is demotivating for me. I would rather frame it as behaving out the best-interest and collective excellence within our trade. Imagine if plumbers or electricians were this cavalier? Houses would burn down. People in hospitals would die because the back-up power generators gas lines would fail. The security of curl is pretty high stakes. If the obnoxious behavior is simply just for kicks, we're putting a LOT on the line.

Re: Curl: We still have not seen a valid security report done with AI help

#258
post #140

Earlier quoted context omitted.

You wouldn't say "the Google search engine contributed to an open source project". Similarly, many millions of developers are using AI. Sometimes in a good way. When that results in a good MR, they likely don't even mention they used Google, or stackoverflow, or AI, they just submit.

Yes and surely someone somewhere though can be explicit and show they used AI in these cases? It would be nice to curate a list where it has been successful.

[deleted]
Post reply on HN