Hacker Newsnew | past | comments | ask | show | jobs | submit | bsamuels's commentslogin

and how do you propose fixing the hundreds, if not thousands, of valid, impactful security bugs that frontier models will find?


That seems like an unfounded assumption. Why should one assume that Git Annex has hundreds or thousands of critical, exploitable security vulnerabilities?


This isn't a problem that is isolated to Git Annex. There are many maintainers out there taking anti-LLM stances, and you don't have to look very far to find OSS projects drowning from the wave of bugs.

https://daniel.haxx.se/blog/2026/05/26/the-pressure/


Wave of bug reports which is quite a different thing.

If you aren’t happy with their stance towards LLMs you can fork and fix yourself if you feel it’s necessary.


If you can't fix them without LLMs, then you can't fix them. You probably shouldn't be trusted with maintaining the codebase in the first place.


How about if you don't have time to fix them without LLMs?


Then you don't have time to maintain the codebase. Sad, but sometimes true.


When given the choice between putting food on the table, and being a purist, I'd take some bread. It is hard out there.


Sure. I did not mean to throw shade at people whose professional survival depends on doing this.

I'm merely trying to establish that it's bad. A lot of HN seems to be cheering for the badness. That is, to me, unfathomable.


You are trying to establish that it is bad based on your beliefs.

I've pointed out to you that LLMs are forced onto people. I fear you are out of touch with the job market requirements of 2026.


Huh? You can accept things that are forced onto you, due to needing to earn a living, while still acknowledging that the things that are forced onto you are bad.

All I'm trying to say here is that slopcode is generally a bad idea. If you are forced to slopcode to earn a living, I am not saying you shouldn't do that ("be a purist", as you'd put it). I'm just trying to point out that HN doesn't seem to generally acknowledge that concept as being bad.


I think it is much too early to outright say it is bad. Very few things are trivial enough to classify in a binary way as in bad or good.

Slop is not okay, this isn't disputed.

When you say "If you are forced to slopcode" you are implying that LLMs (or humans who operate the tools) can only produce slop with it.


> When you say "If you are forced to slopcode" you are implying that LLMs (or humans who operate the tools) can only produce slop with it.

No.


Fair enough. Honestly, nobody is "forced" to slopcode, this is the human's decision, no?



!Purist != Slopper

Just because you are forced to use an LLM, does not mean you can only produce slop.


Of course. What's your point?


Welcome to volunteer-driven open source.

(Update: you're a Debian developer so you're even more familiar with how that world works than I am.)


they buy it from research peptide vendors


thinking tokens, output tokens, etc. Being more clever about file reads/tool calling.


dont unzip an untrusted payload


Unless you are worried about something like a gzip bomb, I don't see why this is an issue. A lot of formats are effectively just zips. The xlsx, odf, etc for example. It's a pretty common format style.

It helps to have a well defined expected structure in the archive.



Right, so long as step 1 in reading your file isn't "extract everything" you're pretty safe.

This specific exploit is one that only exists when you are extracting a zip on windows.


this is just one instance of a vulnerability associated with unzipping; a curious search would yield more.


A curious search reveals that vulnerabilities that do exist are of 2 flavors.

1. Standard C memory vulnerabilities

2. Unsafe file traversal while unzipping

The entire second class is avoided in a fixed file format. The first class of vulnerabilities plague everything. A quick look at libxml2 CVEs shows that.


and the zip bombs you mentioned! i keep a dummy SD card with one hehe.

but yeah the first class of vulns is why we have advice like don’t run untrusted input, which is not dissimilar to “don’t unzip untrusted payloads”.


welcome, you're well along the path of realizing that most of the people on this site don't know what they're talking about


IP rate limiting hasn't been a serious misuse prevention tool for 15-20 years


Can you elaborate? As one tool among many it seems to me to be a perfectly serviceable tool in the toolbox, with a sufficiently high rate limit to account for shared IPs.


as soon as you publish a benchmark like this, it becomes worthless because it can be included in the training corpus


While I agree with you in principle give Claude 4 a try on something like: https://open.kattis.com/problems/low . I would expect this to have been included in the training material as well as solutions found on Github. I've tried providing the problem description and asking Claude Sonnet 4 to solve it and so far it hasn't been successful.


In addition to what Will posted, published reports for blockchain projects tend to be skewed compared to our other groups.

Blockchain clients tend to want to publish the report, but that isn't true for our business lines/projects/clients that are more interesting to HN's audience.


the exact details of the attack were still evolving when we pushed the blog post out, so we kept it to what we did know and what could be extrapolated from it


had the same thing coincide with covid, but much harder to fall asleep once disrupted. Melatonin only seems to last for an hour or so, so I would take one to go back to sleep after a disruption


Thank you very much for the tip. I will try it out for a month, and let you know how it works.


The one I like to take at night is Life Extension 300mcg (.3mg) 6 hour timed release (they make a bunch of different ones), which is the closest to natural melatonin release of any supplemental melatonin I've seen, although it sounds like there is massive variation between people in how much makes it to the blood from a given dose. There are a couple of ways to use melatonin and for circadian use a small non-delayed dose earlier may be better (or use both):

https://circadiansleepdisorders.org/treatments.php#melatonin

I have had issues waking up more frequently when taking melatonin. It sounds like while not common this side effect is not that rare either. Based on my severe sleep issues (primarly circadian) I suspect that one part of "sleep issues" for many people is actualy waking up issues and that the detailed process around waking up has a bigger influence than is currently appreciated. I suspect one reason that melatonin is helpful is that it sets the stage for a better wake up, however if something causes this wake up procedure to start after not enough sleep it can be more difficult to get back to sleep. The delayed release seems to help quite a bit to limit the chance of this happening for me, although it does still happen at times. I'm not sure if melatonin is a particularly good option for staying asleep.

Unfortunately, there aren't particulary good options. Magnesium is the easiest and as effective as anything for me but unfortunately a high enough dose to be effective will also make me tired the next day. However, if your diet is low on magnesium then just increasing that some might help or possibly you won't have the issue with tiredness the next day. baclofen helps me but has issues and I certainly would not recommend it for your case.

A short (few minutes) nap mid day helps the circadian rhythm but longer naps can make it harder to stay asleep at night. If you nap for longer periods, multiple times, or later in the day that is the first thing I would suggest changing. I'm not sure what length causes more trouble but I think getting to sleep but staying asleep as briefly as you easily can is the ideal (though if you will naturally wake up after a bit longer that might be better than an alarm).

I also noticed covid made my already bad sleep worse when I had it (most likely covid, not confirmed by test; cold or flu usually give me better sleep for a day or two). However, I didn't notice any lasting issues (I still have severe sleep issues but it was just that first week of covid that they seemed to be different from usual). I wonder if it could be just your memory of how you sleep that changed after you noticed it due to the disruption. As long as you can easily get back to sleep and aren't staying awake for long it should not cause trouble and is not uncommon. If you feel rested there is nothing to fix while worrying about it or trying to change it could case worse trouble.

These are my thoughts anyway, hopefully something in there is helpful :).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: