Rendered at 22:29:17 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
matherial 20 hours ago [-]
First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
michaelmior 12 hours ago [-]
The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
IsTom 9 hours ago [-]
I think it's just regular corporate speech. LLMs do this, because they've learned on this kind of posts.
acdha 6 hours ago [-]
Em-dashes were in common use long before LLMs existed — anyone saying that’s a sign of LLM use should not be listened to. They’re used by LLMs because they were trained on good writing and we shouldn’t avoid using them any more than we should stop using correct punctuation for the same reason.
hannob 12 hours ago [-]
oss-security gets relatively little use?
You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
matherial 8 hours ago [-]
It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
jamal-kumar 6 hours ago [-]
So where's the residue of vulnerabilities that don't get sent there? You know of anything better?
b112 10 hours ago [-]
Some hate mailing lists, not understanding how valuable the format and medium is. So they deride out of reflex, I suppose.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
some_furry 10 hours ago [-]
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.
PaulRobinson 12 hours ago [-]
> clearly 100% AI-generated
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
jamal-kumar 6 hours ago [-]
I agree - most of my notifications do come right to my primary email and the discussion on these lists is invaluable to me. There's some really good ones with some of the smartest people in the world concentrated on them. Never had infosec twitter and don't want anything to do with it.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
zith 10 hours ago [-]
Pangram says 100% - "We believe that this entire text is AI."
BadBadJellyBean 11 hours ago [-]
> Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
Thank you! I am so sick of these comments under EVERY POST.
efficax 11 hours ago [-]
> Today, we bring it back.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a
museum - to restart the conversation. The mission is unchanged: full
disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
PaulRobinson 4 hours ago [-]
That "trope" is in almost every press release, every corporate announcement I have read in decades.
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
tptacek 22 hours ago [-]
Bugtraq had ceased being relevant at least a decade before it was shut down; it's kind of hard to see what place it could hold now. When it started, vulnerability research was a tiny niche, and disclosure was still a live debate; the norms today are totally different.
DaRealGraybeard 20 hours ago [-]
Yet today, there's not many places to find open discussion and disclosures that otherwise would have seen the light of day in this age of "ethical hacking".
stackghost 19 hours ago [-]
There's always Full Disclosure, I suppose. I would imagine that open discussion and disclosures have moved underground to closed groups.
survivalcrziest 19 hours ago [-]
If this is something an LLM accomplished by itself, then we have reached the singularity.
jaapz 15 hours ago [-]
> Not to build a
museum - to restart the conversation.
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.
Cthulhu_ 15 hours ago [-]
I'm amazed that this pattern has been so ubiquitous for uh. Has it been years already? But they haven't tweaked the services yet to avoid these patterns.
Miraltar 13 hours ago [-]
They could avoid these patterns but there will always be some patterns so they probably judged that these aren't too bad.
gfat 12 hours ago [-]
Especially when writing about projects the author cares about. Surely it should warrant a human writing about the thing they built and are sharing with the world.
phoronixrly 12 hours ago [-]
AI text just has such a noticeable rhythm... It makes it feel so non-genuine and I am so sick of it...
e12e 10 hours ago [-]
Interesting. But the styles chosen for hyperkitty displaying the archives is quite awful. Probably want either fixed width font or sensible reflow.
_pdp_ 13 hours ago [-]
I might restart my old security blog then... anyway
I wonder what will happen. I think it might get flooded by automated AI submissions.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
Thank you! I am so sick of these comments under EVERY POST.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a museum - to restart the conversation. The mission is unchanged: full disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.
I wonder what will happen. I think it might get flooded by automated AI submissions.