Live data from Hacker News

Half a Second – a book about the XZ backdoor

half-second.com

41–50 of 54 posts

Re: Half a Second – a book about the XZ backdoor

#41

It’s great to have the entire topic brought together into a cohesive book - but wow, I find it very annoying to read.

Probably because LLM output only gives the appearance of cohesive writing, but the more you try to understand the author's intent and meaning, the more confusing and annoying it gets, as there is no author, no intent and no meaning there to understand.

Re: Half a Second – a book about the XZ backdoor

#42
post #13

Earlier quoted context omitted.

"free book" "no paywall and nothing to buy." Might this not actually be a reasonable purpose for AI? I can tolerate the quirky style and AI signatures for something honest and free.

Why not just post the prompt you used? I have access to LLMs too.

You think if he gave you the "prompt" you'd be able to produce that book?

Heck, I should put money on this. Start a competition: I give folks a prompt, and tell them to write a book about a subject with AI. I'm the sole judge of quality. Winner gets $2000. Then let's examine the variance in the entries.

In short: using AI is a skill. It's silly to pretend otherwise.

Re: Half a Second – a book about the XZ backdoor

#43

Here's the tool developed by the author that was almost certainly used to generate this book in its entirety - "A structured pipeline for writing long-form nonfiction, packaged as a Claude Code skill": https://github.com/AdrianMastronardi/bookwright There's nowhere near enough public information about the xz vuln to be worth turning into a book, so the merits of AI-generated text aside, this is just a very inefficien…

"There's nowhere near enough public information about the xz vuln to be worth turning into a book," As an actual person, who reads, and having glanced at this book, I do not agree. I can already see part of the purpose is to put perspective on the crazy reality of backdoors/exploits and the undermined implications thereof. Jia Tan alone could warrant a book or film. It also says "for the general reader" and non-technical, which is where I myself think the importance really is. Maybe the AI is catching blindspots.

I downloaded the book. It's not fake. Perhaps no masterpiece, but far from worthless. Also, not "enough public information" really sells inference and imagination short. There is a rich amount of material to work with here. More than enough.

I am going to go ahead and say that flagging this was more information suppression than crankiness about AI. A lot of folks get strange when Jia Tan or similar subjects come up. I guess it's wiser to just wait until the grid goes down, or the water supply gets a bit more chlorinated....

Re: Half a Second – a book about the XZ backdoor

#44
post #14

Earlier quoted context omitted.

In last month or two I noticed semicolons getting used where previously it would be em-dash, in both cases excessively and often incorrectly. I assumed some of my coworkers added "replace all em-dashes with semicolons" into their CLAUDE.md as a really crappy attempt at hiding their inability to write a single sentence without assistance.

Come on now, you can't also take away my semicolons. What am I supposed to do now; I barely have any punctuation left.

Not taking it away.

I hate those arguments "it has emdash therefore AI", of course humans also write that way.

But poor and excessive usage of them is a pretty strong red flag, also together with other tells.

Re: Half a Second – a book about the XZ backdoor

#45

Earlier quoted context omitted.

Why not just post the prompt you used? I have access to LLMs too.

You think if he gave you the "prompt" you'd be able to produce that book? Heck, I should put money on this. Start a competition: I give folks a prompt, and tell them to write a book about a subject with AI. I'm the sole judge of quality. Winner gets $2000. Then let's examine the variance in the entries. In short: using AI is a skill. It's silly to pretend otherwise.

Are you the only reasonable person on HN today? Others are framing this author as some official journalist who must be held to rigorous standards and has violated every rule of the trade, with wanton contempt. The author has failed to produce new data. The author is bad. This seems deranged and extraordinarily unfair. The front page explicitly states the book is for general readers and is non-technical. I do not see anything claiming official original research or boasting academic credentials. No ads. Free. No download registration. Just there. The result of work, tokens, time -- didn't 'just happen'.

The Gladwell-style of conceptual-synthesis is the foundation for half the popular-science books in the world, and the bedrock for the majority of general-reader material out there. And this book happens to have a truly fascinating and extremely relevant and rich theme at its core, sufficiently rich that any motivated idiot could churn out half-decent content with. Yet it gets flagged, insulted and framed as abuse of AI, a tool specifically designed as a force multiplier and tool. Damned if you do, damned if you don't, and how dare anyone generate something of value with it.

I sincerely find this all highly suspicious. The only explanation is hypersensitive AI allergy in a highly unstable immune system, or the topic itself is making some nervous and, ironically, insecure...

I could totally understand disagreement, and complaining. But a comment that simply states acceptance of the book as possibly of value, being flagged? Who not hiding something trounces on a friendly comment to flag it? It's gray already, but that's not dead enough? Kill it til it's dead!? I say this because on a completely different post, I mentioned Jia Tan and several of the very concepts highlighted in this book, and I was flagged for it. I have said some stupid shit around here and not been flagged. But this subject really seems to bring out seriously inspired opponents. One would think, gee wiz, security, potentially many lives or billions of dollars or FOSS at stake -- there's no such thing as too much security, by all means, obsess on it, stay focused and talk about it, there are real world dangers here. But no.

Something seems fishy.

Anyway, glad someone had the courage to question the outrage. And I will promptly warn my author friends of the coming witch-hunt and to be very quiet about the tools they're using.

Re: Half a Second – a book about the XZ backdoor

#46
post #45

Earlier quoted context omitted.

You think if he gave you the "prompt" you'd be able to produce that book? Heck, I should put money on this. Start a competition: I give folks a prompt, and tell them to write a book about a subject with AI. I'm the sole judge of quality. Winner gets $2000. Then let's examine the variance in the entries. In short: using AI is a skill. It's silly to pretend otherwise.

Are you the only reasonable person on HN today? Others are framing this author as some official journalist who must be held to rigorous standards and has violated every rule of the trade, with wanton contempt. The author has failed to produce new data. The author is bad. This seems deranged and extraordinarily unfair. The front page explicitly states the book is for general readers and is non-technical. I do not see…

The HN crowd is generally skeptical, but "shallow dismissals", which are specifically called out in the guidelines, are still extremely common. These dismissals are not as clever as they tend to seem to those skimming the comments, but folks have developed a bunch of thought-terminating cliches to empower this: calling anything involving AI "slop" is the most common, but more catchy (but fundamentally incoherent) phrases have also emerged:

> If you didn't take the time to write it, why should I read it?

I mean, fundamentally you read things if they bring value. It doesn't actually matter if a human wrote it. It matters if it is correct and useful. One implementation is to have a human review, but you can imagine others. Fundamentally anyone who reads and leverages the output of AI knows this. The phrase seems reasonable because it is a good refutation of folks literally copying and pasting AI output from their ChatGPT session in the comments, which I think everyone agrees isn't good hygiene for online discussion. Because the guideline is "right" in that case, it seems easy to apply everywhere, but I think that's overly broad.

> I have tokens, too. Just give me the prompt.

As if everything generated with AI is created as a one-shot with ChatGPT. I feel like half the people writing this stuff have no clue how professionals are using AI. The model, reasoning level, skills, tools, harness all matter, and that's even if the whole thing is a one-shot and we ignore all the server-side variables (inference engine, temperature, top_k, quantization level, etc.). If not, it's the product of a (probably extensive) back-and-forth with an AI, possibly changing models for various subagent calls (Kimi K2.7 Code for the plan, MiniMax M2.7 for implementation, Deepseek v4 Flash as advisor, etc.), etc. Orchestration is as important as prompt and context, but the space has a lot of dimensions. This is why you get radically opposed takes on models, harnesses, and the even the utility of AI: everybody is doing different stuff, solving different problems, and reporting results all over the spectrum. There was a guy just today on HN claiming Opus 4.8 was terrible at agentic development, for example, with half a dozen responses asking how s/he could possibly say that.

Anyway, my post was controversial, but overall negative on points. I just don't understand how anyone can actually use these tools and then post in such a black-and-white way about AI use. I spend a ton of time refining my use of AI and I'm getting better over time, but it's a lot of trial-and-error trying various combinations of tools and trying to match them to tasks. Appreciate your response and the discussion.

Re: Half a Second – a book about the XZ backdoor

#47
post #41

It’s great to have the entire topic brought together into a cohesive book - but wow, I find it very annoying to read.

Probably because LLM output only gives the appearance of cohesive writing, but the more you try to understand the author's intent and meaning, the more confusing and annoying it gets, as there is no author, no intent and no meaning there to understand.

That’s not it in this case, because the book is mostly a recounting of what happened. I narrowed it down to two things: One is that every aspect of the story is treated equally - unimportant facets get an equally profound sounding prose like the really important bits.

And the other one is the repetition of phrases. Everything is worth slowing down on.everything is load bearing. That’s so annoying.

Re: Half a Second – a book about the XZ backdoor

#48
post #41

Earlier quoted context omitted.

Probably because LLM output only gives the appearance of cohesive writing, but the more you try to understand the author's intent and meaning, the more confusing and annoying it gets, as there is no author, no intent and no meaning there to understand.

That’s not it in this case, because the book is mostly a recounting of what happened. I narrowed it down to two things: One is that every aspect of the story is treated equally - unimportant facets get an equally profound sounding prose like the really important bits. And the other one is the repetition of phrases. Everything is worth slowing down on.everything is load bearing. That’s so annoying.

Right, that's the sort of thing I meant.

As you read it, you would naturally try to understand why the author used such profound-sounding prose in that particular part of the text. You would expect that the author's intent was to emphasize the important bits. When the author talks about slowing down or something being load-bearing, you would expect that they're going somewhere with this, that this particular bit is especially important in some way.

But with an LLM-generated text, these attempts at understanding will get you nowhere and only produce frustration. The reader is left trying to interpret a signal that isn't really there.

Re: Half a Second – a book about the XZ backdoor

#50
post #7

Earlier quoted context omitted.

Fun fact: the guy who reported it (Andres Freund) works for Microsoft. Another fun fact: Moscow is in the same time zone as the Middle East.

The middle east is not one time zone https://whichtimezone.com/me/middle-east-map/

I know.
Post reply on HN