Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-ID: <2b91a47f-3223-4db8-82e0-50801d656908@gmail.com>
Date: Mon, 25 May 2026 00:40:54 -0500
From: Jacob Bachmeyer <jcb62281@...il.com>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Re: Coordinated Disclosure in the LLM Age

On 5/24/26 06:58, ROI AI wrote:
>
> > In case you have forgotten, this discussion *started* with a maintainer
> suspecting that LLM-detected vulnerabilities
>
> I replied to this thread because I reported a dozen issues to 
> OpenStack, which the OP is a VMT lead for.  He has yet to claim any of 
> the issues I've reported are invalid or duplicate. I believe people 
> are overclaiming this.  I also believe duplicates, when found, are a 
> good sign for prioritization.
>
> I was also disappointed to see a serious security bug I reported on 
> OpenStack pushed to public.  If I had know that would happen, I 
> wouldn't have reported it.  I don't want to be a part of what I feel 
> to be negligent and unprofessional activities.  My goal was not 
> credit, but rather to improve the security of OpenStack as I wanted to 
> see it as a solution to sovereign cloud.  Pushing it to public 
> undermined that.
>
> Using LLMs, I am farming careless engineers who reveal security 
> sensitive info in bug reports, commit comments, and code reviews.  
> This 'public' attitude is just making it much easier for me to do so.
>
> Security sensitive communication should remain in a restricted 
> discussion area and teams should be using LLMs to analyze it for 
> further issues to close.
>
>
> -- Jacob


I want to make clear that the message quoted above bungled quoting in a 
way that left my signature line after what I now presume to be a 
generated response that completely ignored the point I was trying to 
make.  I am sorry but I have just run out of credible assumptions of 
good faith from ROI AI.

I also note that the list moderator is asking to curtail this thread and 
I agree that any further "debate" with the ROI AI slop machine is likely 
to be useless.  I want the record to clearly show that the *only* piece 
of that I wrote was the sentence fragment quoted in its first line: "In 
case you have forgotten, this discussion *started* with a maintainer
suspecting that LLM-detected vulnerabilities"


-- Jacob


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.