Email or username:

Password:

Forgot your password?
daniel:// stenberg://

"The issue was detected by our new AI-powered vulnerability scanner" ...

AAAAAAA

github.com/curl/curl/issues/12

55 comments
รngela Stella Matutina

@bagder

The thing will report so many false positives they'll take it offline within a week.

daniel:// stenberg://

@angelastella the user seems to have created the account to report this as their first issue. It does not bring hope.

Newk

@angelastella @bagder

Dunno. They externalize all the real work (make people like badger do it) so why not let the thing run?

Andreas Scherbaum

@angelastella @bagder Yes to the first part (the detection), but what makes you believe they take it offline?

Hugo Mills

@angelastella @bagder The thing will report so many false positives that everyone else will want it taken offline within a week.

FTFY.

(The perpetrator will think it's doing good things for the next couple of years, at least. :sadcat1:)

Gert van Dijk

@bagder "You really need to add some actual intelligence to the mix."

Yes, AI does not stand for Actual Intelligence. ๐Ÿ˜‚

github.com/curl/curl/issues/12

Matt Brown

@bagder And you just know this is going onto a pitch deck "detected X number of security flaws in its first week" without any validation whatsoever.

Konstantin Weddige

@bagder this reminds me of an interview enquiry, which I ignored, about how LLMs can improve the efficiency of penetration testing.

I should probably check if it's too late to reply, just to make sure they don't get any funny ideas from some "AI enthusiasts".

mhoye

@bagder The issue was detected by our new AI-powered vulnerability scanner. It found:

int x = 2 + 1;

Because we also detected addition in a different library, we are assigning this issue a severity of: high.

Noam

@bagder Not the most important part but โ€œsubtracting from from toโ€ is sending me

Andreas Scherbaum

@bagder

[ ] Please sign here if your bug report was NOT detected or written by an AI. Otherwise we will close it unseen.

Thomas Frans ๐Ÿ‡บ๐Ÿ‡ฆ

@bagder I have to wonder what they expected the response to be. It's like they want to be the public punching bag. Absolutely idiot behavior. Any person (or even fish) with a single braincell knows not to report security issues in public. Also their "issue" is so dumb. "Detected by AI", where AI stands for absolute idiots.

The Original Stripey Goodness

@bagder and holy mackerel, *they opened a GitHub account just to make this report rather than going to HackerOne*

The account has *zero* other activity

jesse

@bagder they have now linked this to an issue they logged on a wget mirror repo. Given that it's issue 25 I doubt it's even the right place ๐Ÿ™„.

Richard Levitte

@bagder
Gotta appreciate the huge amount of electrons they wasted on the description alone. But yeah, eh gods...

Caleb James DeLisle
Oh no... You're-relying-on-undefined-behavior-this-is-going-to-get-someone-killed-as-a-service ๐Ÿ˜ฑ
Kevin Karhan

@bagder I suggest you change the #CodeOfConduct and explicitly ban #AI-based or otherwise fully-automatic tools without proper checking by the submitting user, with banning said user for #spam if they violate that policy...

I doubt the situation would better otherwise!

Anthropy :verified_dragon:

@bagder lmao, oof, as much as I personally think LLMs can be powerful linter-like tools for added visibility on things when wielded by the right person, this is clearly a wrong usage by a person that isn't even capable of understanding the output it produces. You should be smarter than the tools you use, if you give a fool a hammer everything will look like a nail.

Magnus Ahltorp

@anthropy @bagder Itโ€™s almost as if work is more valuable when done by a person that knows what theyโ€™re doing.

Jorin, Subcontra Sorceress
@bagder this has the same vibe as that whole spam wave of people PRing "x is an awesome project" to READMEs to qualify for some giveaway a while back
skull

@bagder seeing people like this always pisses me off. why waste the time of maintainers and make their life more difficult? automation when pentesting is completely fine, but there still has to be the manual process of validating the vulnerability before reporting it.

gudenau

@bagder More like "AI-powered lie generator and time waster".

I don't envy popular projects right now, this spam sucks.

Kรฉvin โš

@gudenau @bagder I think we got it wrong here, it's not A-capital I, it's A-lowercase L

Artificial lies

Yusef Napora

@bagder itโ€™s a bit rich to have โ€œundefined behavior always means vulnerabilityโ€ come out of a model thatโ€™s essentially ten billion undefined behaviors in a trenchcoat

d0d63

@bagder I took a quick glance on my phone and it wasnโ€™t immediately obvious. Is this ssh as in secure shell embedded into curl somehow?

Edit: wow, lots more. Hrmf.

Cameron

@bagder I wonder if it will identify its creator as a vulnerability if they are posting the (potental) exploits publicly.

Yaksh Bariya

@bagder if from is zero and to is 2^63. size should turn out to be zero. Curl wont download anything, afaict. Isn't this more of a bug than a vulnerability?

daniel:// stenberg://

@CodingThunder correct. In the real word. Doom sayers will claim differently.

Stefan Eissing

@bagder ๐Ÿ™ˆ

Weโ€˜ll probably need reporters to use foul language prohibited to AI models or their issues will be auto closed.

SchwarzeLocke

@bagder wget received a similar report: lists.gnu.org/archive/html/bug

They are even referencing the issue they raised with curl.

Adam โ™ฟ

@bagder see I wouldn't have given that account a chance - that's just a permaban

argv minus one

@bagder

You laugh (and/or scream), but in a few centuries, when everyone's using 64-exabyte data crystals for storage, transferring data over 1Pbps network interfaces, and curl is still in regular use because of course it is, then your distant descendants will be sorry!

polprog68k
@bagder "Integer overflows in C are undefined behavior, and the behavior of the application is unknown when they arise."

truer words have never been spoken
vulp

@bagder oh boy I can't wait for LLM generated spam CVEs to waste developers time

Bart Janssens ๐Ÿ‡ง๐Ÿ‡ช

@bagder Heโ€™s doing the same thing at wgetโ€ฆ what a brave new world ๐Ÿ˜ญ

github.com/mirror/wget/issues/

Gerbrand van Dieyen

@bagder if you have 8192 petabyte sized files. Good last comment.

Fox

@bagder

"I believe it is about 8192 petabytes"

wow xD

That said, I would not be /against/ the use of AI for this purpose, but not like this person did. It might be handy to spot oversights or really deeply buried stuff. But then it still needs to be checked and (in)validated by a human.

github.com/curl/curl/issues/12

Claudio Zizza ๐Ÿฆœ

@bagder I know people who rather say "fix this" than listen to reason.

Bandie :nonbinary_flag:

@bagder Oh, you don't have 8192 PB lying around? :D

Moana Rijndael ๐Ÿ๐Ÿ•

@bagder LangcChain (framework to build complex llm pipelines) has chatgpt powered bot, which tries to help in open issues by generating walls of "helpful" text

It's smart enough to even quote some related code from repository, but...

...for me it results in not being able to read ANY FUCKING ISSUE. Because they're all are filled with walls of text. And knowing that, this text is very probably bullshit, my brain automatically infiltrates it :blobcatgooglyholdingitsheadinitshands:

Go Up