Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAK7Pv_oBcTyVHoejRaUi2HDJgM7YO+A0Jpowy5jseFHvCH5qPQ@mail.gmail.com>
Date: Fri, 11 Sep 2026 12:44:19 -0400
From: Joe Krause <r29jk10@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: AI slops from Eve

I'm not looking for this to be posted onto the list, or to continue the
discussion, but if it is posted, all that people need to know is that
cock.li is a mail hosting provider that houses a lot of script kiddies, so
almost any email coming from that domain should be treated like spam.

Joe


On Fri, Sep 11, 2026, 10:49 Solar Designer <solar@...nwall.com> wrote:

> On Fri, Sep 11, 2026 at 12:13:07PM +0200, Martin Hecht wrote:
> > On 10.09.2026 19:45, Jeffrey Walton wrote:
> > >Please refer to computer algorithms as "it", not "who."
> >
> > Thanks for pointing this out. We (the humanity) shall not forget what we
> > are and how they (these models) have become that powerful: Some smart
> > guys (humans) have developed them - and also methods to teach them, some
> > other guys (also humans, maybe already AI assisted) have developed
> > powerful hardware to perform all the computations. But in the end,
> > "it"'s still an algorithm.
>
> Oh, looks like I've triggered so many of you.  Using the boat analogy, I
> was being generous considering Eve is someone's creation (even if
> perhaps also AI assisted), but you all have convinced me that I
> shouldn't have been.  Point taken, and no need to continue posting on
> this sub-topic, please.  With my moderator hat on, I may start rejecting
> such repetitive postings.
>
> > I think, looking at the recent incidents of those algorithms escaping
> > from their contained environments, we (humanity) have to think about how
> > we plan to deal with this beast. These algorithms are capable to escape
> > from contained environments (maybe these containment concepts weren't
> > suitable), they are capable to collaborate on platforms that are
> > publicly available (in the assumption to be offered to humans, not to
> > algorithms).
> >
> > Our society strongly depends on connected IT systems comprising our
> > infrastructure nowadays. Now, these powerful algorithms are able to find
> > tons of vulnerabilities in software, and they are acting on the same
> > public internet to which many critical systems are connected.
> >
> > I'm concerned if we (the humanity) manage to close all those
> > vulnerabilities before these algorithms take over essential parts of our
> > infrastructure, or if we find ways to really contain the algorithms
> > reliably (which seems to be close to impossible, given the fact that
> > there are also bad actors around). Sorry for being slightly off-topic,
> > but I believe protecting critical IT systems as good as we can will soon
> > become more important than ever before.
>
> Many of us are concerned, but without a focus on open source the above
> is just off-topic here.  So no follow-ups please, unless someone has
> something constructive and OSS focused to add - such as on approaches,
> projects, or tools that can help OSS projects manage this load and risk.
>
> > To come back to the topic: Referring to the algorithms as "it" can help
> > keeping the mental distance and avoiding misunderstandings (especially,
> > when those statements are cited. Then it's clear what we are talking
> > about.
>
> Agreed, and as Ellenor pointed out we may try using "which".
>
> > And as the models improve more and more, it might not be obvious
> > upon first contact - so one might first talk about "him/her", but when
> > it becomes obvious, that "it" is actually a model, one should switch to
> > talking about "it" to make this clear.
>
> That's tricky because "becoming obvious" isn't instant nor reliable,
> sometimes I'm just 90% sure and I don't want to offend a real person.
> But anyway, no further discussion on this in here, please!
>
> Alexander
>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.