Nextcloud has joined a growing list of projects, including Curl, that have ended their bug‑bounty partnerships with HackerOne due to an unmanageable surge of low‑effort, AI‑generated security reports. I received the fol…
Nextcloud has joined a growing list of projects, including Curl, that have ended their bug‑bounty partnerships with HackerOne due to an unmanageable surge of low‑effort, AI‑generated security reports. I received the fol…
Anecdote: there is this annual event called Hacktoberfest for promoting OSS contribution. It offers various merchandise as reward for PRs that get merged as part of the event. A few years back, someone posted a YouTube video trying to promote the event, and demonstrated how to to create a PR by going to some repository and adding some arbitrary text to the README.
What he wanted to convey: “this is the procedure for sending contributions”
What people understood: “you can win a free t-shirt by making small changes to non-code text”
The result: https://joel.net/how-one-guy-ruined-hacktoberfest2020-drama
LLMs did not create this problem. The desire to make bullshit contributions in order to be seen as contributing seems to a basic human need. At least - for some humans. Generative AI did make it so much worse, though, because it’s so good at bullshitting that you have to waste time and spend mental resources in order to recognize the bullshit.