Email or username:

Password:

Forgot your password?
11 comments
Kevin Beaumont

@timhaines @bagder it’s happening, I’ve got one reported on a paid bug bounty programme where they asked Bing AI (lol) to find a vulnerability and then just copypasta the outputs. Unsurprisingly it just made up the issue.

daniel:// stenberg://

@GossiTheDog @timhaines it is fine as long as that they mention "AI", "Bard" or similar early on in the report so that we can discard it quicker. =)

Gabriel Viso ☕️👾

@bagder @GossiTheDog @timhaines I would tell them next time to ask the Bard to write about the issue talking like a pirate, so that at least you can laugh before blocking them to death.

Peter Bindels

@GossiTheDog @timhaines @bagder There should almost be a fine for people knowingly submitting false or AI generated reports.

Kevin Beaumont

@dascandy42 @timhaines @bagder put it this way, a lawyer submitted court documents using ChatGPT and when called out about it - because the citations it used was made up - said they didn’t know AI could be wrong.

Bard told me I died of cancer in 2021, so hello from a ghost. 👻

daniel:// stenberg://

@dascandy42 @GossiTheDog @timhaines fortunately, at least on hackerone, there's a "reputation" for the hacker that gets a dent when they do this.

Peter Bindels

@bagder @GossiTheDog @timhaines I typed "almost", because this is going to create a situation similar to StackOverflow, where new users are almost unable to report anything.

Andreas Scherbaum

@GossiTheDog @timhaines @bagder Can you charge these people instead, if the claim turns out to be bogus? After all, they wasted your time and did not do any research on their own.

Go Up