11 comments
@GossiTheDog @timhaines it is fine as long as that they mention "AI", "Bard" or similar early on in the report so that we can discard it quicker. =) @bagder @GossiTheDog @timhaines I would tell them next time to ask the Bard to write about the issue talking like a pirate, so that at least you can laugh before blocking them to death. @GossiTheDog @timhaines @bagder There should almost be a fine for people knowingly submitting false or AI generated reports. @dascandy42 @timhaines @bagder put it this way, a lawyer submitted court documents using ChatGPT and when called out about it - because the citations it used was made up - said they didn’t know AI could be wrong. Bard told me I died of cancer in 2021, so hello from a ghost. 👻 @dascandy42 @GossiTheDog @timhaines fortunately, at least on hackerone, there's a "reputation" for the hacker that gets a dent when they do this. @bagder @GossiTheDog @timhaines I typed "almost", because this is going to create a situation similar to StackOverflow, where new users are almost unable to report anything. @GossiTheDog @timhaines @bagder Can you charge these people instead, if the claim turns out to be bogus? After all, they wasted your time and did not do any research on their own. |
@timhaines @bagder it’s happening, I’ve got one reported on a paid bug bounty programme where they asked Bing AI (lol) to find a vulnerability and then just copypasta the outputs. Unsurprisingly it just made up the issue.