|
|
Message-Id: <4F97B7BC-01F2-4FFE-92F8-CB06C0D0C29A@dwheeler.com> Date: Fri, 31 Jul 2026 11:39:46 -0400 From: "David A. Wheeler" <dwheeler@...eeler.com> To: oss-security@...ts.openwall.com Subject: Re: Some Changes to GNOME Security Tracking > On Jul 30, 2026, at 10:02 PM, Peter Gutmann <pgut001@...auckland.ac.nz> wrote: > > Alan Coopersmith <alan.coopersmith@...cle.com> writes: > >> 2) The GNOME security team will no longer forward vulnerability reports >> to projects that ban AI-generated content, since most reports they >> get these days have at least some AI-generated content. > > So you've got a bunch of projects where people are clamoring for them to > reject anything that might have been touched by AI, and another bunch of > projects where people have decided to refuse to take part in anything that > rejects things that have been touched by AI. To be fair: Michael Catanzaro is saying he's simply abiding by the request of those projects. They don't want to receive any AI-generated content, and since most vulnerability reports have AI-generated content, Michael won't send them any. Of course, that's absurd. It's appropriate to reject *bad* reports, but people should be open to truth wherever it comes from. Projects that reject truthful security reports are putting their users at risk. --- David A. Wheeler
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.