hhmx.de

Föderation EN Mo 05.05.2025 10:27:57

AI vulnerability/bug founds and reports is a huge problem. Curl has banned the use of AI-generated submissions via HackerOne because none of it made any sense, and is a waste of resources and time. "We are effectively being DDoSed. If we could, we would charge them for this waste of our time" hackerone.com/reports/3125832

Medien: 1

Föderation EN Mo 05.05.2025 12:03:03

@LukaszOlejnik it’s amazing what they are getting- takes hours of trying and failing to reproduce before concluding it’s complete bs. @GossiTheDog

Föderation EN Mo 05.05.2025 12:55:56

@LukaszOlejnik AI is today's Soylent Green

Föderation EN Mo 05.05.2025 16:31:17

@humourmetom @LukaszOlejnik No, Soylent Green was *people*. This isn't even that, it's a fat free, protein free, thought free version.

Föderation EN Mo 05.05.2025 19:44:13

@humourmetom @LukaszOlejnik at least Soylent green ostensibly had nutritional value, lol

Föderation EN Mo 05.05.2025 13:03:34

@LukaszOlejnik Completely understandable. I believe this has to do with the mythologization of AI. People seem to believe AI is the Magic Tool That Solves All Problems. 🙄

On , we recently got spammed with obvious fake bug reports that appear to be written by LLMs. Thankfully, moderation deleted all of it at lightning speed. 👍

Conspiracy theory: Maybe this is what happend to curl as well. I.e. it's actually a *deliberate* spam attack to troll the devs and waste time.

Föderation EN Mo 05.05.2025 14:21:19

@LukaszOlejnik It's funny because this is what I hear is one of the valid uses of AI in coding. But If it is this bad, then it seems like it adheres to the general impression I have of people coding with AI: They are trying to plow through without the normal work to gain the skills to do their work, and without due dilligence, and it works out poorly.

Föderation EN Mo 05.05.2025 15:19:16

@LukaszOlejnik If I click on the reporter's username, there is a list of "closed bugs" together with dollar amounts. Is this money paid out?

If so, the slop is profitable, so it won't go away.

Föderation EN Mo 05.05.2025 17:06:45

@loke @LukaszOlejnik You've heard of beg bounty, maybe the next thing is microbegging. As long as it's cheap to submit plausible-sounding bugs, people will do so in the hope that one in a hundred will pay a hundred bucks to make the reporter just quietly piss off.
I say report them as spam, and block them, if the program has that option.

Föderation EN Mo 05.05.2025 17:55:28

@ftp_alun @LukaszOlejnik Seems like it. Since it's basically free to send out an uncountable number of reports, there is no limit to the number of reports you can send. On the receiving end, there's a lot of work though, but that's not their problem.

Föderation EN Mo 05.05.2025 18:06:23

@loke @ftp_alun @LukaszOlejnik There should be a cost to have more than a small number of outstanding reports, non refundable if any of them are found to be fraudulent.

Föderation EN Mo 05.05.2025 18:12:36

@dalias @ftp_alun @LukaszOlejnik That's a pretty good idea. How many actual issues would a decent analyst find in a month? 10? I think something as low as 1€ per submission would likely fix the problem.

Hopefully when someone with as much clout as @bagder raises this as an issue, someone might notice? Surely the companies paying out the bounties to the fraudsters would like to, you know, not do that.

Föderation EN Mo 05.05.2025 18:20:26

@ftp_alun @loke @LukaszOlejnik Maybe "prompt to earn" is the new "play to earn" since the latter turned out to be a lie.

Föderation EN Mo 05.05.2025 15:39:20

@LukaszOlejnik not done wondering why I got blocked for this, still seems quite accurate...

hespere.de/@hllizi/11442718608

Föderation EN Mo 05.05.2025 16:00:36

@LukaszOlejnik Why do you accept reports via this service at all? Or is direct e-mail also filled with such broken reports?

Föderation EN Mo 05.05.2025 16:19:06

@LukaszOlejnik awesome. Everyone should follow.

Föderation EN Mo 05.05.2025 16:19:24

@LukaszOlejnik
"If we could, we would charge them for this waste of our time"

OK, why NOT charge a nominal fee? I'd be perfectly happy to pay $0.50 per instance to report bugs or vulnerabilities to an organization I trusted to pay attention to them. (Especially if they refund the toll less processing fees if the report was worthwhile.)

No responsible bug-finder is going to run up a significant bill in this way, but the AI idiots certainly will. Especially if you increase the reporting fee for each successive report from the same source (or the same credit card number) in a given time period. Waive the fees for known-reliable researchers who can be relied on to provide only meaningful submissions.

This is obviously not a wonderful solution, but it is A solution to an otherwise intractable problem, and, crucially, it turns the economy of scale back on the report-spammers.

Föderation EN Mo 05.05.2025 18:12:54

@n1xnx @LukaszOlejnik

I think you could probably get away with charging $20 or more. Make them actually think about hitting that submit button. Anyone who's spent hours of their valuable time researching a real security issue won't be deterred by $20, but someone who's just thrown something together will definitely think twice, and you can always refund people if their reports are actually worthwhile.

Föderation · Mo 05.05.2025 21:04:29

@n1xnx @LukaszOlejnik Yeah, only problem I could see with it is effectively gatekeeping to a credit card that works for said website (online payments compatibility is such a mess sometimes).
And some reporters might want to stay pseudonymous.

Föderation · Mo 05.05.2025 21:21:07

@n1xnx @LukaszOlejnik It's very amusing to see people finally accepting that Proof of Work or a native internet currency is required to handle scale and abuse

This will never work with credit cards as refunds are not "free"; at a minimum they still cost the transaction fee and if this became popular the card processors will just increase the cost to refund even higher.

But yes we should probably gate more things on the internet with some kind of payment to punish the bad actors.

Föderation EN Mo 05.05.2025 16:21:04

@LukaszOlejnik Can't hackerone make submitter pay a submission fee?

Föderation EN Mo 05.05.2025 16:32:54

@dragnucs @LukaszOlejnik Maybe you could, if they want to be part of the paid bug bounty system, command £10 per submission.

Föderation EN Mo 05.05.2025 16:49:44

@bagder Have you checked this suggestion? It would allow you make submitters pay. @Dss @LukaszOlejnik

Föderation EN Mo 05.05.2025 17:25:18

@dragnucs @bagder @LukaszOlejnik If the bug bounties are paying out lots of money, then the £10 wouldn't be a concern to good faith submissions. Or submit for free, but you get half the bounty, and things get checked more slowly. See how it goes, perhaps?

Föderation EN Mo 05.05.2025 16:40:43

@LukaszOlejnik …and I thought beg-bounties were annoying

Föderation EN Mo 05.05.2025 17:02:42

@LukaszOlejnik

Folk may be interested in following @bagder , author of the post in the screenshot.

Föderation EN Mo 05.05.2025 17:55:11

@LukaszOlejnik They spam them everywhere too. I have a fairly small website and never got a bug report before, but I did set up security.txt. Got submitted a generic clearly AI generated, and of course, inaccurate report. Made me want to pull the security.txt but fortunately it's just one so far

Föderation EN Mo 05.05.2025 18:53:01

@LukaszOlejnik This will keep getting worse, as bug reports are perfect an attack surface to try and inject backdoors into apps.
Unfortunately, also the models themselves will keep increasingly attacked as people find ways of injecting backdoors into their training data.

Föderation EN Mo 05.05.2025 19:28:47

@LukaszOlejnik The only thing that concerns me there is the "that we deem" part.

I absolutely want to see this situation resolved for them, but if they start straight up banning anyone who doesn't write "well enough" that's a problem too. It's not just a rejection of the report, but a full on ban they're talking about.

Föderation EN Mo 05.05.2025 21:36:05

Sorry you have deal with this.. AI is already destroying so much without any robot needed @bagder

@LukaszOlejnik