Live data from Hacker News

I almost got hacked by a 'job interview'

blog.daviddodda.com

301–310 of 534 posts

Re: I almost got hacked by a 'job interview'

#301

Earlier quoted context omitted.

It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?” “Not fancy security tools. Not expensive antivirus software. Just asking my coding assistant…” I actually feel like AI articles are becoming easier to spot. Maybe we’re all just collectively noticing the patterns.

I'm regularly asked by coworkers why I don't run my writing through AI tools to clean it up and instead spend a time iterating over it, re-reading, perhaps with a basic spell checker and maybe grammar check. That's because, from what I've seen to date, it'd take away my voice. And my voice -- the style in which I write -- is my value. It's the same as with art... Yes, AI tools can produce passable art, but it feels s…

[deleted]

Re: I almost got hacked by a 'job interview'

#302

Earlier quoted context omitted.

It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?” “Not fancy security tools. Not expensive antivirus software. Just asking my coding assistant…” I actually feel like AI articles are becoming easier to spot. Maybe we’re all just collectively noticing the patterns.

I'm regularly asked by coworkers why I don't run my writing through AI tools to clean it up and instead spend a time iterating over it, re-reading, perhaps with a basic spell checker and maybe grammar check. That's because, from what I've seen to date, it'd take away my voice. And my voice -- the style in which I write -- is my value. It's the same as with art... Yes, AI tools can produce passable art, but it feels s…

The thing is, ask it something right away and it'll use its own voice. Give it lots of data from your own writing through examples and extrapolations on your speech patterns and it will impersonate your voice more. It's like how it can impersonate Trump, it has lots of examples to pull from, you? it doesn't know you. LLMs needs large amount of input to give it a really good output.

Re: I almost got hacked by a 'job interview'

#303
post #9

This article was written by an LLM. I get that the author might be self-conscious about his English writing skills, but I would still much rather read the original prompt that the author put into ChatGPT, instead of the slop that came out. The story - if true - is very interesting of course. Big bummer therefore that the author decided to sloppify it. David, could you share as a response to this comment the original…

thanks for the feedback. just fyi - this went though 11 different versions before reaching this point. so I am not able to share the full chat because i used Claude with google docs integration. but hears the google doc i started with https://docs.google.com/document/d/1of_uWXw-CppnFtWoehIrr1ir... this and the following prompt ``` 'help me turn this into a blog post. keep things interesting, also make sure you take a…

The Google Doc was a better and easier read than the LLM output. If you don't have the time, unpolished stuff in your own voice is just fine.

(The LLM output was more or less unreadable for me, but your original was very easy to follow and was to-the-point.)

Re: I almost got hacked by a 'job interview'

#304

I'm seeing red flags all over the story. "Blockchain" being the first one. The use cases for that are so small, it is a red flag in and of itself. Then asking you to run code before a meeting? No, that doesn't "save time", that is driving you to take actions when you don't yet know who is asking. Still, I appreciate the write-up. It is a great example of a clever attack, and I'm going to watch out more for such thing…

For better or worse, there are still many people working on crypto and in the blockchain space. They are probably much more likely than the average developer to have crypto wallets to steal. It sounds like the author is one of those people. The attacker picked the victim carefully.

That said, this attack could be retargeted to other kinds of engineers just by changing the linkedin and website text. I will be more paranoid in the future just knowing about it.

Re: I almost got hacked by a 'job interview'

#305

Earlier quoted context omitted.

I'm regularly asked by coworkers why I don't run my writing through AI tools to clean it up and instead spend a time iterating over it, re-reading, perhaps with a basic spell checker and maybe grammar check. That's because, from what I've seen to date, it'd take away my voice. And my voice -- the style in which I write -- is my value. It's the same as with art... Yes, AI tools can produce passable art, but it feels s…

I often ask for ai to give only grammar and spelling corrections, and then only a change set I apply manually. In other words the same functionality as every word processor since…y2k?

Why not just use one of those word processors, then? It seems like you'd expend less effort (unless there's an advantage of your approach that I'm missing), since the proof-reading systems built into a Word processor have a built-in queue UI with integrated accept / reject functionality that won't randomly tweak other parts of the paragraph behind your back.

Re: I almost got hacked by a 'job interview'

#306
post #292

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

I’d personally like to see these posts banned / flagged out of existence (AI posts, not the parent post). It’s sort of the personal equivalent of tacky content marketing. Usually you’d never see an empty marketing post on the front page, even before AI when a marketer wrote them. Now the same sort of spammy language is accessible to everyone, it shouldn’t be a reason for such posts to be better tolerated

I would agree, but the truth is that I've seen a few technical articles that benefited greatly from both organization and content that was clearly LLM-based. Yes, such articles feel dishonest and yucky to read, but the uncomfortable truth is that they aren't all stereotypical "slop."

Re: I almost got hacked by a 'job interview'

#307

This article is so interesting, but I can’t shake the feeling it was written by AI. The writing style has that feel for me. Maybe that shouldn’t bother me? Like, maybe the author would never have had time to write this otherwise, and I would never have learned about his experience. But I can't help wishing he'd just written about it himself. Maybe that's unreasonable--I shouldn't expect people to do extra work for fr…

that was the case. you can find the base write up and the prompt used in one of my comments on this post. i did not have much time to work on this at all, being in the middle of a product launch at my work, and a bunch of other 'life' stuff. thanks for understanding.

Yeah, people hate that. It just instantly destroyed the immersion and believability of any story. The moment i smell AI every single shred of credibility is completely trashed. Why should i believe a single thing you say? How am i to know in any way how much you altered the story? I understand you must be very busy but straight up the original sketch is better to post than the generic and sickly ai'ified mushmash

Re: I almost got hacked by a 'job interview'

#308
post #279

Earlier quoted context omitted.

that was the case. you can find the base write up and the prompt used in one of my comments on this post. i did not have much time to work on this at all, being in the middle of a product launch at my work, and a bunch of other 'life' stuff. thanks for understanding.

Next time maybe just post the base write up and the prompt? What value does the llm transformation add, other than wasting every reader's time (while saving yours)?

People are often unconfident about their own writing. But if you can feed it to a LLM and have the LLM output something that looks coherent, your writing is good enough to publish.

Re: I almost got hacked by a 'job interview'

#309
post #289
post #153

Earlier quoted context omitted.

My 10+ year old only Reddit account where everything was retroactively removed but "this was in error, appeal granted" also salutes. I worry about Kafkaesque black-mirror trust/reputation issues in the coming decades.

Some of the bureaucratic battles that a functional government would be fighting right now include establishing manual identity management as an essential state function, NSA red teams to enable defensive improvements to widely used software and networks, widespread antitrust action if not progressive corporate taxes to limit the extent of a single vulnerability, postal banking, automatic tax filing, and a whole host…

> identity management as an essential state function

I dimly remember some sci-fi book, the kind where everything was Very Crypto-Quantum, and a character was reminiscing about how human spacefaring civilization kinda-collapsed, since the prior regime had been providing irreplaceable functions of authoritative (1) Identity and (2) Timekeeping.

Anyway, yes, basic identity management is an essential state function nowadays, regardless of whether one thinks it should be federal or state within the US.

That said, I would prefer a tech-ecology where we strongly avoid "true identity" except when it is strictly necessary. For example, the average webforum's legitimate needs are more like "not a bot" and "over 18" and "is invested in this account and doesn't consider it a throwaway."

Re: I almost got hacked by a 'job interview'

#310

Here's a tool that protects you from these kind of things without the necessity to set up an environment per project, just simple one-time install. https://github.com/lavamoat/kipuka It's an upcoming part of the LavaMoat toolkit (that got on main page here recently for blocking the qix malware)

Oh, just download and run your software?

Nice try ;-)

Post reply on HN