▲ | angst 3 days ago | |||||||||||||||||||
> There is an increasing crowd of people who ask a large language model to "find a problem in curl, make it sound terrible", then send the result, which is never correct, to the project, thinking that they are somehow helping. Our worst nightmares are becoming true indeed.. | ||||||||||||||||||||
▲ | slacktivism123 3 days ago | parent | next [-] | |||||||||||||||||||
>thinking that they are somehow helping >Our worst nightmares are becoming true indeed Agree completely with you, but most of the time this isn't people being altruistic. It's people spraying bullshit at maintainers to try and score "CVE IDs as trophies" for their résumé or payouts from the vendor-backed Internet Bug Bounty (IBB) program on HackerOne. https://daniel.haxx.se/blog/2021/09/23/curl-joins-the-reborn... | ||||||||||||||||||||
▲ | bgwalter 3 days ago | parent | prev | next [-] | |||||||||||||||||||
The problem is that open source maintainers rarely react, because most projects are captured by some big tech employees. Independent authors like Stenberg are the exception. If the rebellious spirit of the 1990s and early 2000s still existed, open source could sink "AI" code laundromats within a month. But since 2010 everyone is falling over themselves to please big tech. Big Tech now rewards the cowards with layoffs and intimidation. Most developers do not understand that power balances in corporations work on a primal level. If you show fear/submission, managers will treat you like a beta dog. That is all they understand. | ||||||||||||||||||||
▲ | timeon 3 days ago | parent | prev | next [-] | |||||||||||||||||||
This is getting more common. I've seen CVEs posted to several opensource projects that included made-up APIs. | ||||||||||||||||||||
▲ | blahgeek 3 days ago | parent | prev [-] | |||||||||||||||||||
The worst nightmare would be the maintainers in turn use large language model to review or apply these patches | ||||||||||||||||||||
|