First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
Em-dashes were in common use long before LLMs existed — anyone saying that’s a sign of LLM use should not be listened to. They’re used by LLMs because they were trained on good writing and we shouldn’t avoid using them any more than we should stop using correct punctuation for the same reason.
oss-security gets relatively little use?
You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
> Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
Thank you! I am so sick of these comments under EVERY POST.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a
museum - to restart the conversation. The mission is unchanged: full
disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
That "trope" is in almost every press release, every corporate announcement I have read in decades.
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
I agree - most of my notifications do come right to my primary email and the discussion on these lists is invaluable to me. There's some really good ones with some of the smartest people in the world concentrated on them. Never had infosec twitter and don't want anything to do with it.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
Bugtraq had ceased being relevant at least a decade before it was shut down; it's kind of hard to see what place it could hold now. When it started, vulnerability research was a tiny niche, and disclosure was still a live debate; the norms today are totally different.
Yet today, there's not many places to find open discussion and disclosures that otherwise would have seen the light of day in this age of "ethical hacking".
I'm amazed that this pattern has been so ubiquitous for uh. Has it been years already? But they haven't tweaked the services yet to avoid these patterns.
Especially when writing about projects the author cares about. Surely it should warrant a human writing about the thing they built and are sharing with the world.
First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work.
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.
It contains four emdashes, it overuses the Rule of Three (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...), it has the typical "not X, but Y" sentence, it unduly emphasizes the significance of Buqtrack (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...) ("preservation for the ages", really?).
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
I think it's just regular corporate speech. LLMs do this, because they've learned on this kind of posts.
Em-dashes were in common use long before LLMs existed — anyone saying that’s a sign of LLM use should not be listened to. They’re used by LLMs because they were trained on good writing and we shouldn’t avoid using them any more than we should stop using correct punctuation for the same reason.
oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.
I had to create an inbox filter for oss-security to go into a different label/folder to make my email usable.
Some hate mailing lists, not understanding how valuable the format and medium is. So they deride out of reflex, I suppose.
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
It gets little use in the sense that only a small fraction of vulnerabilities are reported there, and there are very few non-advisory discussions (often by the same 2-3 people).
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
So where's the residue of vulnerabilities that don't get sent there? You know of anything better?
> clearly 100% AI-generated
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
> Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
Thank you! I am so sick of these comments under EVERY POST.
> Today, we bring it back.
> I have acquired securityfocus.com and the Bugtraq name. Not to build a museum - to restart the conversation. The mission is unchanged: full disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
That "trope" is in almost every press release, every corporate announcement I have read in decades.
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
Pangram says 100% - "We believe that this entire text is AI."
I agree - most of my notifications do come right to my primary email and the discussion on these lists is invaluable to me. There's some really good ones with some of the smartest people in the world concentrated on them. Never had infosec twitter and don't want anything to do with it.
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
Bugtraq had ceased being relevant at least a decade before it was shut down; it's kind of hard to see what place it could hold now. When it started, vulnerability research was a tiny niche, and disclosure was still a live debate; the norms today are totally different.
Yet today, there's not many places to find open discussion and disclosures that otherwise would have seen the light of day in this age of "ethical hacking".
There's always Full Disclosure, I suppose. I would imagine that open discussion and disclosures have moved underground to closed groups.
If this is something an LLM accomplished by itself, then we have reached the singularity.
> Not to build a museum - to restart the conversation.
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.
I'm amazed that this pattern has been so ubiquitous for uh. Has it been years already? But they haven't tweaked the services yet to avoid these patterns.
They could avoid these patterns but there will always be some patterns so they probably judged that these aren't too bad.
Especially when writing about projects the author cares about. Surely it should warrant a human writing about the thing they built and are sharing with the world.
AI text just has such a noticeable rhythm... It makes it feel so non-genuine and I am so sick of it...
Interesting. But the styles chosen for hyperkitty displaying the archives is quite awful. Probably want either fixed width font or sensible reflow.
I might restart my old security blog then... anyway
I wonder what will happen. I think it might get flooded by automated AI submissions.
So... l0pht is next?
now bring back the original packetstorm :)
"Make Hackers Great Again"