Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
12 Indlæg 9 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • evacide@hachyderm.ioE evacide@hachyderm.io

    I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

    https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

    f4grx@chaos.socialF This user is from outside of this forum
    f4grx@chaos.socialF This user is from outside of this forum
    f4grx@chaos.social
    wrote sidst redigeret af
    #2

    @evacide techbros have no fucking clue. For them open source projects are just lines in the sbom.

    1 Reply Last reply
    0
    • evacide@hachyderm.ioE evacide@hachyderm.io

      I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

      https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

      jens@social.finkhaeuser.deJ This user is from outside of this forum
      jens@social.finkhaeuser.deJ This user is from outside of this forum
      jens@social.finkhaeuser.de
      wrote sidst redigeret af
      #3

      @evacide I don't think they think that. So much cluelessness seems highly unlikely, after all.

      1 Reply Last reply
      0
      • evacide@hachyderm.ioE evacide@hachyderm.io

        I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

        https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

        nuintari@mastodon.bsd.cafeN This user is from outside of this forum
        nuintari@mastodon.bsd.cafeN This user is from outside of this forum
        nuintari@mastodon.bsd.cafe
        wrote sidst redigeret af
        #4

        @evacide I'm having one of those things.... a headache with pictures! An idea!

        Generate a metric shitton of slop code, upload it all to Github, and opt it all into this nonsense.

        I am all about driving up costs to these digital laudanum peddling con artists.

        1 Reply Last reply
        0
        • evacide@hachyderm.ioE evacide@hachyderm.io

          I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

          https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.socialB This user is from outside of this forum
          bagder@mastodon.social
          wrote sidst redigeret af
          #5

          @evacide but if a project doesn't want the reports, why would they opt in for them?

          evacide@hachyderm.ioE 1 Reply Last reply
          0
          • bagder@mastodon.socialB bagder@mastodon.social

            @evacide but if a project doesn't want the reports, why would they opt in for them?

            evacide@hachyderm.ioE This user is from outside of this forum
            evacide@hachyderm.ioE This user is from outside of this forum
            evacide@hachyderm.io
            wrote sidst redigeret af
            #6

            @bagder Because your options are "more reports than you can possibly triage" or "someone finds a.vuln and either exploits it or sells it to bad people."

            benjamingeer@piaille.frB 1 Reply Last reply
            0
            • evacide@hachyderm.ioE evacide@hachyderm.io

              @bagder Because your options are "more reports than you can possibly triage" or "someone finds a.vuln and either exploits it or sells it to bad people."

              benjamingeer@piaille.frB This user is from outside of this forum
              benjamingeer@piaille.frB This user is from outside of this forum
              benjamingeer@piaille.fr
              wrote sidst redigeret af
              #7

              @evacide @bagder Are we sure that you can’t sign up somebody else’s project?

              1 Reply Last reply
              0
              • evacide@hachyderm.ioE evacide@hachyderm.io

                I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

                https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

                kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                kevingranade@mastodon.gamedev.place
                wrote sidst redigeret af
                #8

                @evacide a quick glance over the information they publish shows NO checks that the submitter is actually a "core contributor". It very much looks like the only filtering they care about is prestige.

                evacide@hachyderm.ioE 1 Reply Last reply
                0
                • evacide@hachyderm.ioE evacide@hachyderm.io

                  I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

                  https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

                  dataknightmare@mastodon.xyzD This user is from outside of this forum
                  dataknightmare@mastodon.xyzD This user is from outside of this forum
                  dataknightmare@mastodon.xyz
                  wrote sidst redigeret af
                  #9

                  @evacide
                  You seriously believe they are not doing in on purpose?

                  1 Reply Last reply
                  0
                  • kevingranade@mastodon.gamedev.placeK kevingranade@mastodon.gamedev.place

                    @evacide a quick glance over the information they publish shows NO checks that the submitter is actually a "core contributor". It very much looks like the only filtering they care about is prestige.

                    evacide@hachyderm.ioE This user is from outside of this forum
                    evacide@hachyderm.ioE This user is from outside of this forum
                    evacide@hachyderm.io
                    wrote sidst redigeret af
                    #10

                    @kevingranade The "case by case basis" language suggests that they think human review is going to prevent them from sending the vuln report to a bad actor. I am much less confident in their abilities.

                    kevingranade@mastodon.gamedev.placeK 1 Reply Last reply
                    0
                    • evacide@hachyderm.ioE evacide@hachyderm.io

                      @kevingranade The "case by case basis" language suggests that they think human review is going to prevent them from sending the vuln report to a bad actor. I am much less confident in their abilities.

                      kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                      kevingranade@mastodon.gamedev.placeK This user is from outside of this forum
                      kevingranade@mastodon.gamedev.place
                      wrote sidst redigeret af
                      #11

                      @evacide given the source I can only assume the process is, "ask a LLM".

                      1 Reply Last reply
                      0
                      • evacide@hachyderm.ioE evacide@hachyderm.io

                        I understand that Anthropic thinks they're doing open source projects a favor here, but what they're actually doing is creating an enormous amount of work for people that they are not paying.

                        https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source

                        dacmot@sunny.gardenD This user is from outside of this forum
                        dacmot@sunny.gardenD This user is from outside of this forum
                        dacmot@sunny.garden
                        wrote sidst redigeret af
                        #12

                        @evacide wow. That's truly awful.

                        Thank you for bringing this up and sharing it.

                        1 Reply Last reply
                        0
                        • jwcph@helvede.netJ jwcph@helvede.net shared this topic
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper