Live data from Hacker News

You did this with an AI and you do not understand what you're doing here

hackerone.com

501–510 of 571 posts

Re: You did this with an AI and you do not understand what you're doing here

#501
post #183

Earlier quoted context omitted.

On Linux I just type (in sequence): compose - - and it makes an em dash, it takes a quarter of a second longer to produce this. I don't know why the compose key isn't used more often.

[As an English typer] Where is this compose key on my keyboard? (This is a vaguely Socratic answer to the question of why the compose key is not more often used.)

As per the wiki article someone else listed — the compose key was available on keyboards back in the 1980s (notably it was invented only 5 years after the Space Cadet keyboard was invented!).

Some DOS applications did have support for it. The reason it wasn't included is baffling, and it's especially baffling to me that other operating systems never adopted it, simply because

    compose a '
is VASTLY more user friendly to type than:

    alt-+
    1F600
which I have met some windows users who memorize that combo for things like the copyright symbol (which is simply:)

    compose o c

Re: You did this with an AI and you do not understand what you're doing here

#502
post #70

Is there something about cUrl that attracts these AI bots, or is it just better documented by them - because I was going to say that this is old, but then I checked the date and realized that this is a new problem. Going down the rabbit-hole, @badger has made multiple posts [0][1] about AI slop. [0] https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-s... [1] https://gist.github.com/bagder/07f7581f6e3d78ef37df…

Curl is one of the most widely used/deployed libraries on the planet.

Re: You did this with an AI and you do not understand what you're doing here

#503
post #309
post #281

Earlier quoted context omitted.

Seems to me like people have to push back more directly with a collective effort; otherwise the incentives are all wrong.

What I don't get, is why people think this action has value. The maintainer of the project could ask an LLM to do that. A senior dev. I can't imagine Googling for something, seeing someone on (for example) stackoverflow commenting on code, and then filing a bug to the maintainer. And just copy and pasting what someone else said, into the bug report. All without even comprehending the code, the project, or even runnin…

Now just imagine some malicious party overwhelming software teams with shitloads of AI bug reports like this. I bet this will be weaponized eventually, if not already is.

Re: You did this with an AI and you do not understand what you're doing here

#504
post #463

Earlier quoted context omitted.

That or the dark vuln market will find a way to vet bugs and pay out faster and easier than the actual project.

I think people who find real bugs have lots of incentives to not sell them to criminals (in and of itself a crime!!)

I mean it depends where you are. In the US my salary is pretty damned high so it's not worth it. Once you start getting in other places, especially those embargod with the US/EU then it's a different story.

Re: You did this with an AI and you do not understand what you're doing here

#505

Earlier quoted context omitted.

Each punch card was it's own line of text. By putting the final curly brace on it's own card, and hence line, it meant you could add lines to blocks without having to change the old last line. E.g. the following code meant you only had to type a new card and insert it. for(i=0;i But for following had to edit and replace an old card as well. for(i=0;i This saved a bit of typing and made errors less likely.

I'm dubious of this explanation because C itself largely postdates punched cards as a major medium of data storage, and some quick searches doesn't produce any evidence of people using punch cards with C or Unix.

Ed was also line oriented.

Using regex to edit lines instead of typing them out was a step up, but not much of one.

Also my father definitely had C punch cards in the 80s.

Re: You did this with an AI and you do not understand what you're doing here

#506
When I view this page without JavaScript (on my current small monitor), there is a micro-scroll vertically down to a banner which reads

> It looks like your JavaScript is disabled. To use HackerOne, enable JavaScript in your browser and refresh this page.

on a rgba(206, 0, 0, 0.3) background (this apparently interpolates onto pure white, so it's actually something like (240, 178, 178) ), and otherwise nothing but blank white.

I know I've complained about lack of "graceful degradation" before, but this seems like a new level.

Re: You did this with an AI and you do not understand what you're doing here

#508
post #45

Earlier quoted context omitted.

AI's other acronym...

You do realize English is one of India's two official languages, I hope?

I've been keeping a file of samples of unusually poor English I encounter in technical programming forums etc. It's almost entirely from people with Indian names. Over decades of experience I've come to notice patterns in how certain native languages inform specific common errors (for a trivial example, native German speakers typo "und" for "and" all the time, even if they have many years of experience with English and are otherwise fluent).

But many of the samples I've seen from Indians (I don't know what their native languages are exactly, and fully admit I wouldn't be able to tell them apart) in the last few years are quite frankly on a whole other level. They're barely intelligible at all. I'm not talking about the use of dialectic idioms like "do the needful" or using "doubt" where UK or US English speakers would use "question". All of that is fine, and frankly not difficult to get used to.

I'm talking about more or less complete word salad, where the only meaning I can extract at all is that something is believed to have gone wrong and the OP is desperate for help. It comes across that they would like to ask a question, but have no concept of QUASM (see e.g. https://www.espressoenglish.net/an-easy-way-to-form-almost-a...) whatsoever.

I have also seen countless cases where someone posted obvious AI output in English, while having established history in the same community of demonstrating barely any understanding of the language; been told that this is unacceptable; and then appeared entirely unable to understand how anyone else could tell that this was happening. But I struggle to recall any instance where the username suggested any culture other than an Indian one (and in those cases it was an Arabic name).

To be clear, I am not saying that this is anything about the people or the culture. It's simple availability bias. Although China has a comparable population, there's a pretty high bar to entry for any Chinese nationals who want to participate in English-speaking technical forums, for hopefully obvious reasons. But thanks to the status of an English dialect as an official language, H1B programs etc., and now the ability to "polish" (heavy irony) one's writing with an LLM, and of course the raw numbers, the demographics have shifted dramatically in the last several years.

Re: You did this with an AI and you do not understand what you're doing here

#509
post #504

Earlier quoted context omitted.

I think people who find real bugs have lots of incentives to not sell them to criminals (in and of itself a crime!!)

I mean it depends where you are. In the US my salary is pretty damned high so it's not worth it. Once you start getting in other places, especially those embargod with the US/EU then it's a different story.

Presumably Hackerone isn't paying to people under US embargo!

Re: You did this with an AI and you do not understand what you're doing here

#510

Earlier quoted context omitted.

Unfortunately that seems to be the norm now – people literally reduce themselves to a copy-paste mechanism.

To be honest, I do not understand this new norm. A few months ago I applied to an internal position. I was a NGO IT worker, deployed twice to emergency response operations, knew the policies & operations and had good relations with users and coworkers. The interview went well. I was honest. When asked what my weakness regarding this position I told that I am a good analyst but when it comes to writing new exploits, t…

Same thing where I work. It's a startup, and they value large volumes of code over anything else. They call it "productivity".

Management refuses to see the error of their ways even though we have thrown away 4 new projects in 6 months because they all quickly become an unmaintainable mess. They call it "pivoting" and pat themselves on the back for being clever and understanding the market.

Post reply on HN