cross-posted from: https://lemmy.zip/post/64538696
Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’
cross-posted from: https://lemmy.zip/post/64538696
Multiple researchers using the same tools to find the same bugs are creating ‘unnecessary pain and pointless work’
deleted by creator
What you’re forgetting is that many – if not most – of these vulnerabilities/exploits are bullshit in the first place. Either very niche situations that are extremely unlikely to happen in real life or outright hallucinations.
A few of them are legitimate security concerns, sure, but the vast majority are either low priority or a complete waste of time. And the same goes for the hackers trying to find ways in – the vast majority of the exploits they discover this way won’t actually work, or will only affect a tiny minority of Linux systems that are using obscure and/or obsolete protocols. So it’s not quite the ‘nukes’ from your hyperbole.
deleted by creator
You want a real solution?
It costs $10 for an un-vetted reporter to submit a bug report. If the developers review the bug report and find it to be valid and helpful, you get your $10 refunded and you’re added to the list of vetted reporters who can submit bug reports for free. If not, the foundation keeps the $10 and uses it to help pay the salaries of people who have to review these bug reports.
deleted by creator
Not ethics, practicality. There are only so many people contributing so many hours to open source projects. It’s impossible to handle the entire incoming stream of reports without some filtering.
And your analogy isn’t really capturing the problem. If you want to stick with the (slightly hyperbolic) nuke analogy, it’s more like getting 9 reports that nukes are going to be launched but 6 of them name different source countries, 4 of them say it’ll actually be tomorrow night, 2 of them say the nukes will be unarmed for some reason, and one says it’s actually bottle rockets being launched. I hope you can find them in time because they’re buried among 362 other intelligence reports about god knows what, many of which are duplicates of things you already knew about. Also, you don’t know any of the sources or what their motives and competency levels are.
@OwOarchist@pawb.social didn’t say anything about banning AI usage at all, just that we need a better system to restrict contributions to people who can demonstrate that they can filter the noise out of their own contributions instead of just spamming mailing lists with everything their chosen tool spits out. No one is going to dump a valid bug report just because a contributor used AI to find it. They want to dump the endless stream of duplicate and invalid reports being submitted by people that don’t bother confirming that the reports they’re submitting are new and valid.
deleted by creator
No. That’s what this whole post is about. The current state is unsustainable and a better system is needed.
I don’t think anybody has the answers to your other questions yet - that’s the whole point of the discussion. Open source projects are facing a new challenge and the community as a whole needs to do some brainstorming and experimentation to figure out how to solve it. Video interviews may not be the right solution at all, it’s just one idea among others.