If one user could have found this using AI. Then I would imagine anyone else could have found it.
Right, including Sony. AI finding security flaws is very good in general, but one downside is that it will become easier to make "secure" devices that are hostile toward their owners.
It's just boring.
> Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
So what has really happened is the LLMs have lowered the participation floor for this space enough the dynamics are changing. The new comers would rather have a few dollars vs. the founders who would rather have a project. It’s likely the projects days were numbered either way because Sony could also just take a frontier LLM and examine any released installer for the project and reverse engineer and bug.
How old was this bug? How much energy has been devoted to RE of this proprietary console? Not enough, apparently.
remember hacktoberfest 2020? that's just all public-facing source 365 days a year now, except instead of "updated README.md" it's some vaguely-plausible fix... then you read the PR body and someone couldn't even be bothered to, or, just as likely couldn't explain it themselves. and that sort of sinking dread sets in.
Oh man, if you read the threads about that it's such a time capsule of a different era:
e.g. from this thread: https://news.ycombinator.com/item?id=31628342
> I am honestly surprised how little SPAM there is on GitHub in general. Please don’t take that as a challenge!
I entirely sympathize with these maintainers too. I've had 2 instances where an LLM has surfaced a bug and I just couldn't get myself to open a PR and dump more work onto these maintainers, even after manually writing one up (neither were critical bugs, it's fine).
Seeing popular projects (like hermes) having 5k issues and 5k pull requests is madness.
People who hate their job of course like to come out of the woodwork and say no one should enjoy it, but isn't it nice to have a society where at least some people can enjoy their work? I used to enjoy teaching but I'd never get a teaching job now because of how AI is being used in that sector.
Technophiles will say that we should embrace the future because its inevitable but how many good people quitting does it take before they realize that a vibe-coded future of fun isn't all there is to life?
This is definitely the case for me. Before AI tools became mainstream, it was already a difficult proposition to find other smart people who you could get along with and talk to, do something interesting together. The Internet made all the difference in my life because I was able to get outside my geographic region to do big things through open source and hacker communities. Now, that very important filter mechanism no longer works. It's Eternal September all over again. In a way, it's very much a domination of "ends" over "means" in the wider community that is being forced upon those who long focused on "means". For a lot of intelligent people, understanding something is /valuable on its own/, but for the wider world there is no value in simply knowing things, but what you do with that knowledge (or now that lack of knowledge). I even experienced this recently at DEFCON 34 where I saw other participants in some of the CTFs with me using AI tools and not really understanding what the tools were doing or what was happening, but just kind of bruteforcing/tokenmaxxing their way through. This isn't to say that those AI tools are fundamentally a bad thing to use in building open source software, security research, or even as a tool in a CTF, but that the "understanding" step needs to still be present or it destroys the fun in everything.
I'm certainly not having as much fun with computers these days, even as I've invested a lot of effort myself in local LLMs and trying to understand the tools and understand how to apply them reasonably, I've found I prefer much more analog entertainments. Thankfully there's always photography and lockpicking to entertain me at the moment and provide a pathway to meet other interesting fellows.
It's an issue that the dev attempted to collect the bug bounty, AI or no
Not to mention how the code can then be sourced by an AI model in an instant without any credit.
Same thing did happen to many work places. People at all levels proxy questions through LLMs and don't even bother to read/trim/edit the response.
Funny, how suddenly a tight, 1-2 sentence response on point is a sign of skill.
arnaudsm•27m ago
https://x.com/theflow0/status/2099987019954831744
seki285•26m ago
arnaudsm•17m ago
Vibecoding has been the norm for months, it's the embargo violation today that triggered his resignation.
lokar•15m ago
lovich•11m ago
You know, it’s petty, but I think one of the things I hate the most about AI is that it surpassed front end JavaScript frameworks in terms of changing what the standard is every few years.
What’s the point of learning anything if it becomes obsolete faster than the seasons change?
Daishiman•5m ago
sva_•15m ago
Sounds like he is salty that somebody found an exploit using LLM that he found manually (which probably took a significant amount of time.) I can partly understand it, but I mean that's also just the game that somebody else might find an exploit, LLMs just make it easier. LLMs finding bugs is not a bad thing, just sucks for enjoyers of open source software in this particular case.
You can probably find more though.
deletedie•11m ago
Qiu_Zhanxuan•6m ago
tetromino_•6m ago
Nope. He is salty because someone made public the secret exploit that Linux-on-PS5 apparently relies upon to bypass Sony's hypervisor protection. Now Sony will fix the exploit, and there will be no more Linux on the PS5 until another exploit is found.
sva_•4m ago
kotaKat•6m ago
But I guess Sony being a gatekeeper wasn't a gatekeeper enough for certain regulatory agencies.