Live data from Hacker News

I found a vulnerability. they found a lawyer

dixken.de

61–70 of 466 posts

Re: I found a vulnerability. they found a lawyer

#62

This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance.

HN's comment section new favourite sport, trying to guess if an article was generated by LLM. It's completely pointless. Why not focus on what's being said instead?

I thought the same thing. With the rate LLMs are improving, it's not going to be too much longer before no one can tell.

I also enjoy all the "vibes" people list out for why they can tell, as though there was any rhyme or reason to what they're saying. Models change and adapt daily so the "heading structure" or "numbered list" ideas become outdated as you're typing them.

Re: I found a vulnerability. they found a lawyer

#63

Why does someone with a .de website insure their diving using some company based in Malta? Based on this interaction, you have wonder what it's like to file a claim with them.

Divers Alert Network, which is probably the most well known dive membership (and insurance) org out there is registered in Malta in Europe.

Re: I found a vulnerability. they found a lawyer

#64
I find these tales of lawyerly threats completley validate the hackers actions. They reported the bug to spur the company to resolve it. Their reaction all but confirms that reporting it to them directly would not have been productive. Their management lacks good stewardship. They are not thinking about their responsibility to their customers and employees.

Re: I found a vulnerability. they found a lawyer

#65

[flagged]

Not sure what the name of your complex is, maybe groveling deference to legalese? Whatever it is, I'm sure I would have applied it to your entire country of origin if I knew where you're from, and if I were developmentally around the age of twelve.

He did everything exactly by the book and in the end was even nice enough to not publish the company's name, despite the legal threat being bullshit and him being entirely in the right.

Re: I found a vulnerability. they found a lawyer

#66

Why does someone with a .de website insure their diving using some company based in Malta? Based on this interaction, you have wonder what it's like to file a claim with them.

It is probably among the standard forms required to participate in a diving class/excursion for travelers from other countries; and, Malta was probably chosen as the official HQ for legal or liability shelter reasons.

Re: I found a vulnerability. they found a lawyer

#67
post #18

This is somewhat related, but I know of a fairly popular iOS application for iPads that stores passwords either in plaintext or encrypted (not as digests) because they will email it to you if you click Forgot Password. You also cannot change it. I have no experience with Apple development standards, so I thought I'd ask here if anyone knows whether this is something that should be reported to Apple, if Apple will do…

>whether this is something that should be reported to Apple, if Apple will do anything Lmao Apple will not do anything for actual malware when reported with receipts, besides sending you a form letter assuring you "experts will look into it, now fuck off" then never contact you again. Ask me how I know. To their credit, I suspected they ran it through useless rudimentary automated checks which passed and they were ba…

> Apple will not do anything for actual malware when reported with receipts, besides sending you a form letter assuring you "experts will look into it, now fuck off"

Ask while you are in an EU country, request appeal and initiate Out-of-court dispute resolution.

Or better yet: let the platform suck, and let this be the year of the linux desktop on iPhone :)

Re: I found a vulnerability. they found a lawyer

#68

Earlier quoted context omitted.

> This is an LLM-generated article, for anyone who might wish to save the "15 min read" labelled at the top. Recounts an entirely plausible but possibly completely made up narrative of incompetent IT, and contains no real substance. Nothing in the original message refers to it being clickbait, the core complaint is the LLM-like tone and the lack of substance, which you also just threw it there without references iron…

It is not based on guesswork. For whatever it's worth, I have gotten 7 LLM accounts banned from HN in the past week based on accurately detecting and reporting them to moderation[1]. Many of these accounts had between dozens and 100 upvotes, some with posts rated to the top of their threads that escaped detection by others. I have not once misidentified and reported an account that was genuinely human. I am aware tha…

Congrats, and thanks for your work, but you should be aware that HN comments are completely different from articles. What makes you think the skills/automations required to identify LLM generated HN comments will work seamlessly with submitted articles? You have to do a statistical analysis of this, otherwise it's just guesswork.

You also have to take into account that the medium is the message[1]. In a nutshell, the more people read LLM generated posts and interact with chatbots, the higher the influence of LLM style in their writing -- the whole "delve" comes to mind, and double dashes. So even if you have a machine that correctly identified LLM generated posts, you can't be sure it'll keep working.

[1] https://web.mit.edu/allanmc/www/mcluhan.mediummessage.pdf

Re: I found a vulnerability. they found a lawyer

#69
When you are acting in good faith and the person/organization on the other end isn't, you aren't having a productive discussion or negotiation, just wasting your own time.

The only sensible approach here would have been to cease all correspondence after their very first email/threat. The nation of Malta would survive just fine without you looking out for them and their online security.

Re: I found a vulnerability. they found a lawyer

#70
post #42

Since the author is apparently afraid to name the organisation in question, it seems the legal threats have worked perfectly.

Or maybe in the diving community, "Maltese insurance company for divers" is about as subtle as "Bird-themed social network with blue checkmarks".

There's pretty much only one global insurer affiliated with dive schools, so this is spot on
Post reply on HN