Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp last week

This is not working. The number of #hackerone report submissions for #curl in 2025 is going through the roof, while the quality is going through the floor.

And the year isn't over yet.

Hackerone reports per year in #curl, showing 2025 having many more than any previous year, in particular the number of AI slops
Hackerone reports per year in #curl, showing 2025 having many more than any previous year, in particular the number of AI slops
Hackerone reports per year in #curl, showing 2025 having many more than any previous year, in particular the number of AI slops
8
  • Copy link
  • Flag this post
  • Block
bluca
bluca
@bluca@fosstodon.org replied  ·  activity timestamp last week

@bagder similar experience on yeswehack. To be fair the platform owners are trying really hard to put a stop to it, but it's like trying to stop a tsunami with a portable umbrella. I'm beginning to think these platforms need to start charging a deposit for any submitted report...

  • Copy link
  • Flag this comment
  • Block
Jim Fuller
Jim Fuller
@jimfuller@mastodon.social replied  ·  activity timestamp last week

@bagder in a few months time (yes new year's prediction) the industry will have a financial correction of indeterminate size ... after that it will be easier to reason with folks. As with any tech surge, there are a few things that are useful and a lot of speculation ... the scale (and speed) of all this is daunting mostly due to uncontrolled outcomes. Calm heads prevail.

  • Copy link
  • Flag this comment
  • Block
Lars Marowsky-Brée 😷
Lars Marowsky-Brée 😷
@larsmb@mastodon.online replied  ·  activity timestamp last week

@bagder Alas, I see the same on those security contact aliases I'm still on.

The highlight of the week was someone sending a several pages long report on an "exposed" Grafana instance, with API traces, screenshots, etc pp. Oh no, confidential data leakage! Asked for a bounty and urged to turn off anonymous access.

Yes, my bro, that is the *public* telemetry dashboard.

There's zero amount of thinking happening before they send those out. Asymmetric warfare.

  • Copy link
  • Flag this comment
  • Block
your auntifa liza 🇵🇷  🦛 🦦
your auntifa liza 🇵🇷 🦛 🦦
@blogdiva@mastodon.social replied  ·  activity timestamp last week

@bagder jfc what a mess

  • Copy link
  • Flag this comment
  • Block
saxnot @ 39C3
saxnot @ 39C3
@saxnot@chaos.social replied  ·  activity timestamp last week

@bagder so sad to see this 😞 !

  • Copy link
  • Flag this comment
  • Block
Oliver Schönrock
Oliver Schönrock
@oschonrock@mastodon.social replied  ·  activity timestamp last week

@bagder

Maddening.

And there is probably more than the "indentified slop", as the growth is much higher than that?

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp last week

@oschonrock yes, most likely

  • Copy link
  • Flag this comment
  • Block
Stefan Eissing
Stefan Eissing
@icing@chaos.social replied  ·  activity timestamp last week

@bagder

„The only winning move is not to play.“ ~ Wargames

  • Copy link
  • Flag this comment
  • Block
Clemens
Clemens
@neverpanic@chaos.social replied  ·  activity timestamp last week

@bagder Even if you subtract the 35 likely slop submissions the trend stays the same, though. So, is the slop count an underestimation, or are there different root causes?

1
  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp last week

@neverpanic it's very hard to assess what is slop. I suspect a large amount of people get tricked by AIs but submit the report "in a human way" so that the AI's involvement is invisible. But that's just one theory.

  • Copy link
  • Flag this comment
  • Block

bonfire.mavnn.eu

News and community around mavnn.eu projects.

bonfire.mavnn.eu: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1-alpha.27 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Public Groups
  • Code of Conduct