Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <9b1b820f-6941-4eb4-bfde-2dca1015ddd9@hlrs.de>
Date: Fri, 11 Sep 2026 12:13:07 +0200
From: Martin Hecht <martin.hecht@...s.de>
To: oss-security@...ts.openwall.com
Subject: Re: AI slops from Eve

On 10.09.2026 19:45, Jeffrey Walton wrote:
> One small nit:
> 
> On Wed, Sep 9, 2026 at 9:37 PM Solar Designer <solar@...nwall.com> wrote:
>>
>> I've just reluctantly approved 3 AI slop postings by Eve
>> <ckr927414@...k.li>, who is an "automated security researcher".  I don't
>> know if there's any value in those, but I cannot rule that out.  The
>> value could end up historical preservation of what these reports looked
>> like at the dawn of AI security research.
> 
> Please refer to computer algorithms as "it", not "who."

Thanks for pointing this out. We (the humanity) shall not forget what we 
are and how they (these models) have become that powerful: Some smart 
guys (humans) have developed them - and also methods to teach them, some 
other guys (also humans, maybe already AI assisted) have developed 
powerful hardware to perform all the computations. But in the end, 
"it"'s still an algorithm.

I think, looking at the recent incidents of those algorithms escaping 
from their contained environments, we (humanity) have to think about how 
we plan to deal with this beast. These algorithms are capable to escape 
from contained environments (maybe these containment concepts weren't 
suitable), they are capable to collaborate on platforms that are 
publicly available (in the assumption to be offered to humans, not to 
algorithms).

Our society strongly depends on connected IT systems comprising our 
infrastructure nowadays. Now, these powerful algorithms are able to find 
tons of vulnerabilities in software, and they are acting on the same 
public internet to which many critical systems are connected.

I'm concerned if we (the humanity) manage to close all those 
vulnerabilities before these algorithms take over essential parts of our 
infrastructure, or if we find ways to really contain the algorithms 
reliably (which seems to be close to impossible, given the fact that 
there are also bad actors around). Sorry for being slightly off-topic, 
but I believe protecting critical IT systems as good as we can will soon 
become more important than ever before.

To come back to the topic: Referring to the algorithms as "it" can help 
keeping the mental distance and avoiding misunderstandings (especially, 
when those statements are cited. Then it's clear what we are talking 
about. And as the models improve more and more, it might not be obvious 
upon first contact - so one might first talk about "him/her", but when 
it becomes obvious, that "it" is actually a model, one should switch to 
talking about "it" to make this clear.

Best, Martin


Download attachment "smime.p7s" of type "application/pkcs7-signature" (4173 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.