Bugtraq is back

52 pointsposted 11 hours ago
by bashtoni

18 Comments

matherial

9 hours ago

First - and I know this is immaterial - there's something sad about the announcement being clearly 100% AI-generated and then bemoaning AI and calling for a renewed human connection. Like, we want to have a community, but no one is willing to do the work.

Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.

michaelmior

an hour ago

The announcement didn't read as AI-generated to me at all. Of course this is far from foolproof, but ZeroGPT says 0% AI.

pajamasam

10 minutes ago

It contains four emdashes, it overuses the Rule of Three (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...), it has the typical "not X, but Y" sentence, it unduly emphasizes the significance of Buqtrack (https://en.wikipedia.org/wiki/Wikipedia:Signs_of_AI_writing#...) ("preservation for the ages", really?).

Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.

PaulRobinson

an hour ago

> clearly 100% AI-generated

First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.

Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.

> Today, what's the incentive to use a mailing list?

Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.

I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.

Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.

Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.

Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.

BadBadJellyBean

23 minutes ago

> Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.

Thank you! I am so sick of these comments under EVERY POST.

hannob

an hour ago

oss-security gets relatively little use? You must know another oss-security. The one I'm subscribed to is very much alive and an important source of information for me.

tptacek

11 hours ago

Bugtraq had ceased being relevant at least a decade before it was shut down; it's kind of hard to see what place it could hold now. When it started, vulnerability research was a tiny niche, and disclosure was still a live debate; the norms today are totally different.

DaRealGraybeard

9 hours ago

Yet today, there's not many places to find open discussion and disclosures that otherwise would have seen the light of day in this age of "ethical hacking".

stackghost

8 hours ago

There's always Full Disclosure, I suppose. I would imagine that open discussion and disclosures have moved underground to closed groups.

survivalcrziest

8 hours ago

If this is something an LLM accomplished by itself, then we have reached the singularity.

jaapz

4 hours ago

> Not to build a museum - to restart the conversation.

> This list is [...]. Same address. Same purpose. New era.

Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.

gfat

an hour ago

Especially when writing about projects the author cares about. Surely it should warrant a human writing about the thing they built and are sharing with the world.

Cthulhu_

4 hours ago

I'm amazed that this pattern has been so ubiquitous for uh. Has it been years already? But they haven't tweaked the services yet to avoid these patterns.

Miraltar

2 hours ago

They could avoid these patterns but there will always be some patterns so they probably judged that these aren't too bad.

phoronixrly

35 minutes ago

AI text just has such a noticeable rhythm... It makes it feel so non-genuine and I am so sick of it...

_pdp_

2 hours ago

I might restart my old security blog then... anyway

I wonder what will happen. I think it might get flooded by automated AI submissions.

snorbleck

10 hours ago

now bring back the original packetstorm :)