You know, it’s petty, but I think one of the things I hate the most about AI is that it surpassed front end JavaScript frameworks in terms of changing what the standard is every few years.
What’s the point of learning anything if it becomes obsolete faster than the seasons change?
Just so you know, the frontend framework wars started and ended pretty quickly in the latter half of the 2010s.
It was the downstream effect of the browser wars settling down and W3C making big moves on getting vendors to finally implement standards that were sorely needed. It had nothing to do with web dev culture.
The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
Sounds like he is salty that somebody found an exploit using LLM that he found manually (which probably took a significant amount of time.) I can partly understand it, but I mean that's also just the game that somebody else might find an exploit, LLMs just make it easier. LLMs finding bugs is not a bad thing, just sucks for enjoyers of open source software in this particular case.
Sounds like he is salty that somebody found an exploit using LLM that he found manually
Nope. He is salty because someone made public the secret exploit that Linux-on-PS5 apparently relies upon to bypass Sony's hypervisor protection. Now Sony will fix the exploit, and there will be no more Linux on the PS5 until another exploit is found.
I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.
This guy has used on working with people that understand the scene, it seems that they were in contact, they agreed on something and then the next day they did something different.
This is really important in the context of what happened and probably the cherry on top of the current "hacking" cake, with the bar being lowered so much that anybody can jump in with some minor skill and luck and get something just for themselves.
“Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
If one user could have found this using AI. Then I would imagine anyone else could have found it.
Then I would imagine anyone else could have found it.
Right, including Sony. AI finding security flaws is very good in general, but one downside is that it will become easier to make "secure" devices that are hostile toward their owners.
Sure, but that wasn't what I was getting at. The guy is complaining about the exploit being disclosed to Sony, but anyone who used the same tools could have found it. It's kind of like complaining that someone has spoilt the ending to a film when it been out for over a year.
If one user could have found this using AI. Then I would imagine anyone else could have found it.
People are still fixated on using AI to produce code (to reduce salary costs/dev time) rather than using it to audit bugs in one own's code, which they are better at.
Fascinating times we live in, when "the last hypervisor bug" in what is presumably one of the most hardened pieces of consumer hardware can be found by "noobs" and "slop kiddies".
The headline here is off, PS5 Linux relies on bugs for installs, and the project couldn’t keep the last know hypervisor bug secret:
Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
So what has really happened is the LLMs have lowered the participation floor for this space enough the dynamics are changing. The new comers would rather have a few dollars vs. the founders who would rather have a project. It’s likely the projects days were numbered either way because Sony could also just take a frontier LLM and examine any released installer for the project and reverse engineer and bug.
now imagine how many other devs and maintainers are contemplating this but just haven't been pushed to their personal breaking point yet. or take note of how many, when asked about the spam problem, just nervously go "yeah it's kinda rough haha...". or how many will vent about it on their twitter-like of choice with increasing frequency.
remember hacktoberfest 2020? that's just all public-facing source 365 days a year now, except instead of "updated README.md" it's some vaguely-plausible fix... then you read the PR body and someone couldn't even be bothered to, or, just as likely couldn't explain it themselves. and that sort of sinking dread sets in.
I would guess we'll start seeing more open source projects with much tighter restrictions on who can participate. Closed contributions and heavily automated (or even closed) issue tracking is probably already happening and will spread faster.
I entirely sympathize with these maintainers too. I've had 2 instances where an LLM has surfaced a bug and I just couldn't get myself to open a PR and dump more work onto these maintainers, even after manually writing one up (neither were critical bugs, it's fine).
Seeing popular projects (like hermes) having 5k issues and 5k pull requests is madness.
now imagine how many other devs and maintainers are contemplating this but just haven't been pushed to their personal breaking point yet. or take note of how many, when asked about the spam problem, just nervously go "yeah it's kinda rough haha..."
At first, my brain parsed "spam" as in ye olde email spam. It took a moment for it to sink in that you meant code spam, instead.
But now that the two concepts are linked in my little pea brain: I kind of want to see how a system like SpamAssassin would work when applied to pull requests like it has been applied to email.
Reputation, real-time blacklists, triggers for form, and et cetera, with weighted scores for all of it.
If final score is passing, it's presented for a human to review. If the final score fails, it goes into the circular file where it will probably die.
Hobby groups projects like this are less fun for a lot of people who used to enjoy interacting with smart people. It's definitely become a game of just spam claude for answers with zero understanding or care for how anything actually works. That's fine to get things done and fine for a lot of side projects, but it definitely ruins the joy that people have in understanding systems and working with intellectuals.
In general, society is experience a decoupling of fun from work. I can't say I enjoy every aspect of my job, but it's nice to enjoy some of it, and lots of people do find a lot of their job at least somewhat rewarding.
People who hate their job of course like to come out of the woodwork and say no one should enjoy it, but isn't it nice to have a society where at least some people can enjoy their work? I used to enjoy teaching but I'd never get a teaching job now because of how AI is being used in that sector.
Technophiles will say that we should embrace the future because its inevitable but how many good people quitting does it take before they realize that a vibe-coded future of fun isn't all there is to life?
but isn't it nice to have a society where at least some people can enjoy their work?
That’s an interesting question. I thought about it for a minute and was surprised that I came to the conclusion that the answer isn’t obviously “yes”.
An analogous question is “isn't it nice to have a society where at least some people are rich?”, and I think that question should make it clearer to many people why that is so.
Hobby groups projects like this are less fun for a lot of people who used to enjoy interacting with smart people.
This is definitely the case for me. Before AI tools became mainstream, it was already a difficult proposition to find other smart people who you could get along with and talk to, do something interesting together. The Internet made all the difference in my life because I was able to get outside my geographic region to do big things through open source and hacker communities. Now, that very important filter mechanism no longer works. It's Eternal September all over again. In a way, it's very much a domination of "ends" over "means" in the wider community that is being forced upon those who long focused on "means". For a lot of intelligent people, understanding something is /valuable on its own/, but for the wider world there is no value in simply knowing things, but what you do with that knowledge (or now that lack of knowledge). I even experienced this recently at DEFCON 34 where I saw other participants in some of the CTFs with me using AI tools and not really understanding what the tools were doing or what was happening, but just kind of bruteforcing/tokenmaxxing their way through. This isn't to say that those AI tools are fundamentally a bad thing to use in building open source software, security research, or even as a tool in a CTF, but that the "understanding" step needs to still be present or it destroys the fun in everything.
I'm certainly not having as much fun with computers these days, even as I've invested a lot of effort myself in local LLMs and trying to understand the tools and understand how to apply them reasonably, I've found I prefer much more analog entertainments. Thankfully there's always photography and lockpicking to entertain me at the moment and provide a pathway to meet other interesting fellows.
It is insane just how miserable the experience of FOSS hardware hacking in public is.
The expectation does not even the slightest match reality.
You'd think "ah yes many eyes meaning all bugs get shallow", but instead you get worst of XDA-Developers and toxic wastelands where no sane person even answers anymore.
But this predates LLMs and was as miserable as it is now before as well.
In fact, I might even argue that LLMs made this _better_, because you can now avoid the "opening up in hopes of finding 1 helpful person below 99 annoying ones" through simple GPU compute.
Previously, you had to hope that through this self-inflicted horror, you'd find an expert that can augment you. Now that expert rests on huggingface.
It's still.. not perfect, of course. But it might be less miserable - provided that you adapt to the current state of things and stop with the "trawling for volunteers".
This title and the first quote are misleading. A dev found an undisclosed hypervisor exploit using AI that TheFlow0 had been using and keeping secret, but the other dev had informed Sony to collect the bug bounty.
It's an issue that the dev attempted to collect the bug bounty, AI or no
It's strange working on Opensource these days. I've mostly worked on my own stuff alone which usually doesn't get much attention/additional contribution. Then I see on Reddit, HN or LinkedIn someone creating a major App or Plugin in a weekend. Sometimes I take a closer look the artisanal quality is effectively unmaintainable, at least for humans. But in the end it's hard to get a good overview, and the sheer quantity seems to dwarf any other efforts.
Not to mention how the code can then be sourced by an AI model in an instant without any credit.
it seems that vibe-coders, or “slop kiddies” as the modder dubbed them, used AI to detect a bug that they were using to crack consoles, and reported it to Sony for a bounty.
That would indeed be incredibly demoralizing, even crushing. Quite a dick move.
Now that said, I imagine it was only a matter of time anyway until Sony found/fixed or someone else did the same thing. It's just a different world now.
“Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
Ever since consoles became moving targets there's been deliberate gatekeeping - specifically, drip-feeding of bugs - to maximize the chance someone can actually use them to break DRM and install Linux. This relies on the fact that most people do not want to have to become FreeBSD kernel experts in order to install non-PlayStation software on their PlayStation. But if everyone is vibe-hacking their PS5s then none of this logic applies. Any bug Claude can find is one Sony also knows about and will get patched, possibly before you even release an exploit for it.
How this ultimately plays out depends on if it's even possible to write software without bugs. Maybe this reaches a new equilibrium where people are paying Claude to vibe-code jailbreaks - as I'd initially hoped. But it's equally as likely that this winds up reinforcing DRM rather than weakening it, for a few reasons:
1. Anthropic's AI safetyism culture encourages the prohibition of vibe-coded jailbreaks. The fact that the model runs on a server and people are spying on your chatlogs means Anthropic has actual knowledge of who is actually using their service to find PS5 hypervisor bugs. Letting Claude break DRM is legally risky; DMCA 1201 implies the only lawful way to break DRM is for you to find your own bugs. So it's probably not going to be long until everyone vibe-coding jailbreaks will get banned.
2. Sony will not be getting banned from these services, they will get trusted access as they're big enough for Anthropic to sue if it gets misused.
3. The attack surface of the thing you have to actually compromise to get code execution on any locked-down system is really small. The Xbox 360 had a 15+ year gap[0] of no softmodding because they'd isolated all the memory protection into a hypervisor. Apple learned the same lesson and iPhone jailbreaking went from incredibly commonplace to "if you know how to do it someone at Zerodium will hand you a million dollars to write spyware with it".
[0] AFAIK, the only two actual softmoddable bugs on Xbox 360 were the King Kong hack right at launch, which got patched in like a week, and that BadUpdate thing last year.
Misleading title, there's another major reason: it's an embargo agreement violation that jeopardizes Linux support on PS5.
https://x.com/theflow0/status/2099987019954831744
Nothing misleading about the title and you are splitting hairs.
Omitting half of the story is misleading, this isn't a pro/anti LLM story.
Vibecoding has been the norm for months, it's the embargo violation today that triggered his resignation.
The headline accurately summarizes the main point of the story, and the part that is emphasized is from the subject of the story.
You know, it’s petty, but I think one of the things I hate the most about AI is that it surpassed front end JavaScript frameworks in terms of changing what the standard is every few years.
What’s the point of learning anything if it becomes obsolete faster than the seasons change?
To be fair the JS frontend communities brought this to themselves way before LLM slop.
Just so you know, the frontend framework wars started and ended pretty quickly in the latter half of the 2010s.
It was the downstream effect of the browser wars settling down and W3C making big moves on getting vendors to finally implement standards that were sorely needed. It had nothing to do with web dev culture.
It's the fear of being left behind that fuels both these things.
Sounds like he is salty that somebody found an exploit using LLM that he found manually (which probably took a significant amount of time.) I can partly understand it, but I mean that's also just the game that somebody else might find an exploit, LLMs just make it easier. LLMs finding bugs is not a bad thing, just sucks for enjoyers of open source software in this particular case.
You can probably find more though.
Rather, he's annoyed because the LLM User submitted the exploit to Sony (to get paid) and killed the only known viable path forward for development.
yeah, and tbh he should be, one douche ruined it for the rest of us
Any noticing what it paid?
Nope. He is salty because someone made public the secret exploit that Linux-on-PS5 apparently relies upon to bypass Sony's hypervisor protection. Now Sony will fix the exploit, and there will be no more Linux on the PS5 until another exploit is found.
Okay, I misunderstood. But it wasn't particularly secret if 'noobs' had access then?
This guy has used on working with people that understand the scene, it seems that they were in contact, they agreed on something and then the next day they did something different.
This is really important in the context of what happened and probably the cherry on top of the current "hacking" cake, with the bar being lowered so much that anybody can jump in with some minor skill and luck and get something just for themselves.
All Sony had to do was give us a path forward to run our own code on the PS5.
But I guess Sony being a gatekeeper wasn't a gatekeeper enough for certain regulatory agencies.
If one user could have found this using AI. Then I would imagine anyone else could have found it.
Then I would imagine anyone else could have found it.
Right, including Sony. AI finding security flaws is very good in general, but one downside is that it will become easier to make "secure" devices that are hostile toward their owners.
Sure, but that wasn't what I was getting at. The guy is complaining about the exploit being disclosed to Sony, but anyone who used the same tools could have found it. It's kind of like complaining that someone has spoilt the ending to a film when it been out for over a year.
People are still fixated on using AI to produce code (to reduce salary costs/dev time) rather than using it to audit bugs in one own's code, which they are better at.
The latter has "always" been obvious to me.
Fascinating times we live in, when "the last hypervisor bug" in what is presumably one of the most hardened pieces of consumer hardware can be found by "noobs" and "slop kiddies".
Makes you wonder if it really was "noobs" and "slop kiddies" that found it.
Well, sure, the same way that I can cook a three michelin star meal by going out to eat at the French Laundry.
It's just boring.
Hypervisor bugs are boring? Maybe to you.
Hiring someone else to find them is boring as hell. If you only care about being spoonfed results, I don't think there's much to talk about.
The headline here is off, PS5 Linux relies on bugs for installs, and the project couldn’t keep the last know hypervisor bug secret:
So what has really happened is the LLMs have lowered the participation floor for this space enough the dynamics are changing. The new comers would rather have a few dollars vs. the founders who would rather have a project. It’s likely the projects days were numbered either way because Sony could also just take a frontier LLM and examine any released installer for the project and reverse engineer and bug.
So the slop kiddies both don’t understand what they are doing, and they ruin the party for everyone else. Nice.
As usual: Normies end up destroying every community they get into
Lowered the barrier to entry, but also raised the stakes. My money is on dedication to the high-stakes problem.
How old was this bug? How much energy has been devoted to RE of this proprietary console? Not enough, apparently.
now imagine how many other devs and maintainers are contemplating this but just haven't been pushed to their personal breaking point yet. or take note of how many, when asked about the spam problem, just nervously go "yeah it's kinda rough haha...". or how many will vent about it on their twitter-like of choice with increasing frequency.
remember hacktoberfest 2020? that's just all public-facing source 365 days a year now, except instead of "updated README.md" it's some vaguely-plausible fix... then you read the PR body and someone couldn't even be bothered to, or, just as likely couldn't explain it themselves. and that sort of sinking dread sets in.
Oh man, if you read the threads about that it's such a time capsule of a different era:
e.g. from this thread: https://news.ycombinator.com/item?id=31628342
I would guess we'll start seeing more open source projects with much tighter restrictions on who can participate. Closed contributions and heavily automated (or even closed) issue tracking is probably already happening and will spread faster.
I entirely sympathize with these maintainers too. I've had 2 instances where an LLM has surfaced a bug and I just couldn't get myself to open a PR and dump more work onto these maintainers, even after manually writing one up (neither were critical bugs, it's fine).
Seeing popular projects (like hermes) having 5k issues and 5k pull requests is madness.
At first, my brain parsed "spam" as in ye olde email spam. It took a moment for it to sink in that you meant code spam, instead.
But now that the two concepts are linked in my little pea brain: I kind of want to see how a system like SpamAssassin would work when applied to pull requests like it has been applied to email.
Reputation, real-time blacklists, triggers for form, and et cetera, with weighted scores for all of it.
If final score is passing, it's presented for a human to review. If the final score fails, it goes into the circular file where it will probably die.
Hobby groups projects like this are less fun for a lot of people who used to enjoy interacting with smart people. It's definitely become a game of just spam claude for answers with zero understanding or care for how anything actually works. That's fine to get things done and fine for a lot of side projects, but it definitely ruins the joy that people have in understanding systems and working with intellectuals.
In general, society is experience a decoupling of fun from work. I can't say I enjoy every aspect of my job, but it's nice to enjoy some of it, and lots of people do find a lot of their job at least somewhat rewarding.
People who hate their job of course like to come out of the woodwork and say no one should enjoy it, but isn't it nice to have a society where at least some people can enjoy their work? I used to enjoy teaching but I'd never get a teaching job now because of how AI is being used in that sector.
Technophiles will say that we should embrace the future because its inevitable but how many good people quitting does it take before they realize that a vibe-coded future of fun isn't all there is to life?
That’s an interesting question. I thought about it for a minute and was surprised that I came to the conclusion that the answer isn’t obviously “yes”.
An analogous question is “isn't it nice to have a society where at least some people are rich?”, and I think that question should make it clearer to many people why that is so.
This is definitely the case for me. Before AI tools became mainstream, it was already a difficult proposition to find other smart people who you could get along with and talk to, do something interesting together. The Internet made all the difference in my life because I was able to get outside my geographic region to do big things through open source and hacker communities. Now, that very important filter mechanism no longer works. It's Eternal September all over again. In a way, it's very much a domination of "ends" over "means" in the wider community that is being forced upon those who long focused on "means". For a lot of intelligent people, understanding something is /valuable on its own/, but for the wider world there is no value in simply knowing things, but what you do with that knowledge (or now that lack of knowledge). I even experienced this recently at DEFCON 34 where I saw other participants in some of the CTFs with me using AI tools and not really understanding what the tools were doing or what was happening, but just kind of bruteforcing/tokenmaxxing their way through. This isn't to say that those AI tools are fundamentally a bad thing to use in building open source software, security research, or even as a tool in a CTF, but that the "understanding" step needs to still be present or it destroys the fun in everything.
I'm certainly not having as much fun with computers these days, even as I've invested a lot of effort myself in local LLMs and trying to understand the tools and understand how to apply them reasonably, I've found I prefer much more analog entertainments. Thankfully there's always photography and lockpicking to entertain me at the moment and provide a pathway to meet other interesting fellows.
Same thing did happen to many work places. People at all levels proxy questions through LLMs and don't even bother to read/trim/edit the response.
Funny, how suddenly a tight, 1-2 sentence response on point is a sign of skill.
I think a lot of workplaces would do well to ban LLM-based replies in certain spaces.
Wasn't it always?
It is insane just how miserable the experience of FOSS hardware hacking in public is.
The expectation does not even the slightest match reality. You'd think "ah yes many eyes meaning all bugs get shallow", but instead you get worst of XDA-Developers and toxic wastelands where no sane person even answers anymore.
But this predates LLMs and was as miserable as it is now before as well.
In fact, I might even argue that LLMs made this _better_, because you can now avoid the "opening up in hopes of finding 1 helpful person below 99 annoying ones" through simple GPU compute.
Previously, you had to hope that through this self-inflicted horror, you'd find an expert that can augment you. Now that expert rests on huggingface.
It's still.. not perfect, of course. But it might be less miserable - provided that you adapt to the current state of things and stop with the "trawling for volunteers".
This title and the first quote are misleading. A dev found an undisclosed hypervisor exploit using AI that TheFlow0 had been using and keeping secret, but the other dev had informed Sony to collect the bug bounty.
It's an issue that the dev attempted to collect the bug bounty, AI or no
It's strange working on Opensource these days. I've mostly worked on my own stuff alone which usually doesn't get much attention/additional contribution. Then I see on Reddit, HN or LinkedIn someone creating a major App or Plugin in a weekend. Sometimes I take a closer look the artisanal quality is effectively unmaintainable, at least for humans. But in the end it's hard to get a good overview, and the sheer quantity seems to dwarf any other efforts.
Not to mention how the code can then be sourced by an AI model in an instant without any credit.
That would indeed be incredibly demoralizing, even crushing. Quite a dick move.
Now that said, I imagine it was only a matter of time anyway until Sony found/fixed or someone else did the same thing. It's just a different world now.
Ever since consoles became moving targets there's been deliberate gatekeeping - specifically, drip-feeding of bugs - to maximize the chance someone can actually use them to break DRM and install Linux. This relies on the fact that most people do not want to have to become FreeBSD kernel experts in order to install non-PlayStation software on their PlayStation. But if everyone is vibe-hacking their PS5s then none of this logic applies. Any bug Claude can find is one Sony also knows about and will get patched, possibly before you even release an exploit for it.
How this ultimately plays out depends on if it's even possible to write software without bugs. Maybe this reaches a new equilibrium where people are paying Claude to vibe-code jailbreaks - as I'd initially hoped. But it's equally as likely that this winds up reinforcing DRM rather than weakening it, for a few reasons:
1. Anthropic's AI safetyism culture encourages the prohibition of vibe-coded jailbreaks. The fact that the model runs on a server and people are spying on your chatlogs means Anthropic has actual knowledge of who is actually using their service to find PS5 hypervisor bugs. Letting Claude break DRM is legally risky; DMCA 1201 implies the only lawful way to break DRM is for you to find your own bugs. So it's probably not going to be long until everyone vibe-coding jailbreaks will get banned.
2. Sony will not be getting banned from these services, they will get trusted access as they're big enough for Anthropic to sue if it gets misused.
3. The attack surface of the thing you have to actually compromise to get code execution on any locked-down system is really small. The Xbox 360 had a 15+ year gap[0] of no softmodding because they'd isolated all the memory protection into a hypervisor. Apple learned the same lesson and iPhone jailbreaking went from incredibly commonplace to "if you know how to do it someone at Zerodium will hand you a million dollars to write spyware with it".
[0] AFAIK, the only two actual softmoddable bugs on Xbox 360 were the King Kong hack right at launch, which got patched in like a week, and that BadUpdate thing last year.