Rendered at 17:17:08 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
matherial 2 days ago [-]
First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
michaelmior 1 days ago [-]
The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
IsTom 1 days ago [-]
I think it's just regular corporate speech. LLMs do this, because they've learned on this kind of posts.
acdha 1 days ago [-]
Em-dashes were in common use long before LLMs existed — anyone saying that’s a sign of LLM use should not be listened to. They’re used by LLMs because they were trained on good writing and we shouldn’t avoid using them any more than we should stop using correct punctuation for the same reason.
pajamasam 6 hours ago [-]
> anyone saying that’s a sign of LLM use should not be listened to
You don't need to believe me. You can read the studies about its statistically higher occurrence in LLM writing vs human writing (https://arxiv.org/pdf/2603.27006) or you can do the analysis yourself.
Also, no one said you should stop using them. But overusing them, along with emulating some of the other common traits of LLM generated writing, will give people the impression that you didn't bother to write something yourself.
acdha 2 hours ago [-]
You’re misunderstanding the problem: LLMs using emdashes more than the average human still doesn’t tell you that the poster you’re interacting with now is an LLM and not one of the many humans who used emdashes before LLMs existed and are the reason why LLM training picked that up as a good trait. Humans shouldn’t stop writing well just because bots were trained to mimic them.
One other problem with this as a heuristic is technical: they used to be hard to enter on Windows so mostly only professionally-edited text there had em-dashes while the ease of entry on Mac, iOS, Android, and to a lesser extent Linux meant that they were more common there. I suspect that this list disproportionately lists Mac users:
oss-security gets relatively little use?
You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
matherial 1 days ago [-]
It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
jamal-kumar 1 days ago [-]
So where's the residue of vulnerabilities that don't get sent there? You know of anything better?
b112 1 days ago [-]
Some hate mailing lists, not understanding how valuable the format and medium is. So they deride out of reflex, I suppose.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
some_furry 1 days ago [-]
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.
PaulRobinson 1 days ago [-]
> clearly 100% AI-generated
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
jamal-kumar 1 days ago [-]
I agree - most of my notifications do come right to my primary email and the discussion on these lists is invaluable to me. There's some really good ones with some of the smartest people in the world concentrated on them. Never had infosec twitter and don't want anything to do with it.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
BadBadJellyBean 1 days ago [-]
> Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
Thank you! I am so sick of these comments under EVERY POST.
zith 1 days ago [-]
Pangram says 100% - "We believe that this entire text is AI."
efficax 1 days ago [-]
> Today, we bring it back.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a
museum - to restart the conversation. The mission is unchanged: full
disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
PaulRobinson 23 hours ago [-]
That "trope" is in almost every press release, every corporate announcement I have read in decades.
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
tptacek 2 days ago [-]
Bugtraq had ceased being relevant at least a decade before it was shut down; it's kind of hard to see what place it could hold now. When it started, vulnerability research was a tiny niche, and disclosure was still a live debate; the norms today are totally different.
DaRealGraybeard 2 days ago [-]
Yet today, there's not many places to find open discussion and disclosures that otherwise would have seen the light of day in this age of "ethical hacking".
stackghost 2 days ago [-]
There's always Full Disclosure, I suppose. I would imagine that open discussion and disclosures have moved underground to closed groups.
survivalcrziest 2 days ago [-]
If this is something an LLM accomplished by itself, then we have reached the singularity.
jaapz 1 days ago [-]
> Not to build a
museum - to restart the conversation.
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.
Cthulhu_ 1 days ago [-]
I'm amazed that this pattern has been so ubiquitous for uh. Has it been years already? But they haven't tweaked the services yet to avoid these patterns.
Miraltar 1 days ago [-]
They could avoid these patterns but there will always be some patterns so they probably judged that these aren't too bad.
gfat 1 days ago [-]
Especially when writing about projects the author cares about. Surely it should warrant a human writing about the thing they built and are sharing with the world.
phoronixrly 1 days ago [-]
AI text just has such a noticeable rhythm... It makes it feel so non-genuine and I am so sick of it...
e12e 1 days ago [-]
Interesting. But the styles chosen for hyperkitty displaying the archives is quite awful. Probably want either fixed width font or sensible reflow.
_pdp_ 1 days ago [-]
I might restart my old security blog then... anyway
I wonder what will happen. I think it might get flooded by automated AI submissions.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
You don't need to believe me. You can read the studies about its statistically higher occurrence in LLM writing vs human writing (https://arxiv.org/pdf/2603.27006) or you can do the analysis yourself.
Also, no one said you should stop using them. But overusing them, along with emulating some of the other common traits of LLM generated writing, will give people the impression that you didn't bother to write something yourself.
One other problem with this as a heuristic is technical: they used to be hard to enter on Windows so mostly only professionally-edited text there had em-dashes while the ease of entry on Mac, iOS, Android, and to a lesser extent Linux meant that they were more common there. I suspect that this list disproportionately lists Mac users:
https://www.gally.net/miscellaneous/hn-em-dash-user-leaderbo...
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
Thank you! I am so sick of these comments under EVERY POST.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a museum - to restart the conversation. The mission is unchanged: full disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.
I wonder what will happen. I think it might get flooded by automated AI submissions.