Hacker News
Bugtraq is back
matherial
|next
[-]
Second, BUGTRAQ existed because it had no alternatives. There was no social media, vulnerability research orgs had no marketing teams, there were no commercial clearinghouses, etc. Today, what's the incentive to use a mailing list? Case in point: two other security mailing lists, fulldisclosure@seclists.org and oss-security@lists.openwall.com, still exist but get relatively little use.
michaelmior
|root
|parent
|next
[-]
pajamasam
|root
|parent
[-]
Also, in my experience, LLMs seem to love to say something went "dark" or "silent", to mention a "generation" of people, and to say something "matters". "no corporate filter" also seems like a strange thing to say.
IsTom
|root
|parent
|next
[-]
acdha
|root
|parent
|previous
[-]
pajamasam
|root
|parent
[-]
You don't need to believe me. You can read the studies about its statistically higher occurrence in LLM writing vs human writing (https://arxiv.org/pdf/2603.27006) or you can do the analysis yourself.
Also, no one said you should stop using them. But overusing them, along with emulating some of the other common traits of LLM generated writing, will give people the impression that you didn't bother to write something yourself.
acdha
|root
|parent
[-]
One other problem with this as a heuristic is technical: they used to be hard to enter on Windows so mostly only professionally-edited text there had em-dashes while the ease of entry on Mac, iOS, Android, and to a lesser extent Linux meant that they were more common there. I suspect that this list disproportionately lists Mac users:
https://www.gally.net/miscellaneous/hn-em-dash-user-leaderbo...
hannob
|root
|parent
|next
|previous
[-]
b112
|root
|parent
|next
[-]
Mailing lists are a lot like democracy. Imperfect, but nothing else is less-Imperfect.
matherial
|root
|parent
|next
|previous
[-]
It does get use in the sense that every now and then, some vendor sends 50 emails that could've been one (most recently, some Apache Qpid thing). But I wouldn't call that part valuable.
PaulRobinson
|root
|parent
|previous
[-]
First, show your working - just reads like generic announcement/PR speak from the last 30 years to me.
Secondly, could everyone who wants to make comments about AI text in submissions please consider re-reading the comments section of the Guidelines: https://news.ycombinator.com/newsguidelines.html - I'm not sure these comments are in the spirit of the HN community. We should stop this in the same way we try and stop "HN is just turning into Reddit" noise.
> Today, what's the incentive to use a mailing list?
Social media is trash that makes your life worse. Deleting the apps demonstrably improves mental health. I'm a case in point, but everyone I know or read about who gets rid of social media concurs. Major, major life upgrade.
I should not have to be on X to get notifications about new security issues. I should not have to sift through Meta's latest algorithm enhancements to find out if my servers are currently hanging their backsides out on the information superhighway.
Secondly, I don't want all security research to go via commercial channels, either via clearinghouses, orgs with "marketing teams" (I actually want to scream at the idea this is OK), or even through platforms like social media that exist to sell advertising.
Mailing lists are clean, simple, filterable, and readable - or ignorable - on any device of my choosing. I can route emails to ticketing systems without fear an API token is going to get revoked, an RSS feed is disabled by a "product owner", or a web scraper fails because somebody added a new react component for "improved usability". Email is email, and it's glorious, in a way no other communication mechanism has ever come close to matching because it's so simple.
Those two other security mailing lists suffer from not having critical mass. Bugtraq may or may not get critical mass back. I hope it does, not just for nostalgia reasons, but because we need a critical mass movement behind security research given the current threat landscape.
jamal-kumar
|root
|parent
|next
[-]
That said it would be nice if people sending stuff to oss-security would batch their emails instead of sending like 10-50 for each little CVE (I'm looking at you, apache software foundation)
BadBadJellyBean
|root
|parent
|next
|previous
[-]
Thank you! I am so sick of these comments under EVERY POST.
zith
|root
|parent
|next
|previous
[-]
efficax
|root
|parent
|previous
[-]
> I have acquired securityfocus.com and the Bugtraq name. Not to build a museum - to restart the conversation. The mission is unchanged: full disclosure, researcher-first, no corporate filter.
This has the ai patter, the rhythm, the “not this, but that” trope, the list of threes, everything about it screams LLM to me
PaulRobinson
|root
|parent
[-]
AI is trained on all that material and regurgitates it. It is trained to do that.
So the problem we have is that AI sounds like that, because humans sound like that. The "identifier" you've found isn't real. It just shows - if an LLM did this - that it's working, and that corporate speak is ubiquitous.
And the lists of threes, man, that's just basic English composition I was taught when I was 8 years old - it's everywhere. It has, to a native English-speaking ear, a rhythm, cadence and elegance. See?
tptacek
|next
|previous
[-]
survivalcrziest
|next
|previous
[-]
jaapz
|next
|previous
[-]
> This list is [...]. Same address. Same purpose. New era.
Please. I don't care you use AI to write your shit. But please at least put in the effort to have it write in your own voice.