zlacker

[parent] [thread] 16 comments
1. jfindp+(OP)[view] [source] 2025-12-03 16:45:55
>AFAICT, they're AI generated.

What is the "tell"? I'm not saying they are or aren't, but... people say this about literally everything now and it's typically some flimsy reasoning like "they used a bullet point". I don't see anything in particular that makes me think ai over a standard template some junior fills out.

>the vulnerability was not found by a Wiz employee at all

I've re-read the Wiz article a few times. Maybe I'm just dumb, but where did Wiz claim to have found this vulnerability?

replies(3): >>tenseg+A4 >>mmsc+n5 >>karimf+re
2. tenseg+A4[view] [source] 2025-12-03 17:04:16
>>jfindp+(OP)
the tl;dr definitely came out of an llm

presentation and formatting aside the constant attempts to manufacture legitimacy and signal urgency are a classic tell. everything is "near-100%" reliable, urgent, critical, reproducible, catastrophic. siren emoji

replies(1): >>jfindp+I5
3. mmsc+n5[view] [source] 2025-12-03 17:08:02
>>jfindp+(OP)
Hackernews' submission guidelines clearly state: "Please submit the original source. If a post reports on something found on another site, submit the latter." [0]

The Wiz post has significantly changed since it was first published (and how it looked when first posted to HN), FYI -- see [1]. When it was published, it was a summary of the React announcement, and was somehow longer than the original and yet provided less useful information than the original.

In any case, the "tell" is the syntactic structure (as Chomsky would say) and certain phrases used in the post.

[0]: https://news.ycombinator.com/newsguidelines.html

[1]: https://web.archive.org/web/20251203162416/https://www.wiz.i...

◧◩
4. jfindp+I5[view] [source] [discussion] 2025-12-03 17:09:28
>>tenseg+A4
The authors have said it isn't.

I can't believe saying a security vulnerability is "reproducible", "critical", etc. is a "classic tell of ai".

I've used "reproducible" and "critical" in my deliverables since well before ai was a thing.

replies(1): >>rvnx+58
◧◩◪
5. rvnx+58[view] [source] [discussion] 2025-12-03 17:20:09
>>jfindp+I5
Is it so important ? It's a mix of AI and human-written. It's normal nowadays and perfectly acceptable.

+ it is maybe 10% AI max, which seems to be for the structure / readability, and there is legit information under.

replies(3): >>jfindp+89 >>nostra+G9 >>aprilt+Xf
◧◩◪◨
6. jfindp+89[view] [source] [discussion] 2025-12-03 17:24:26
>>rvnx+58
>Because author says it, it doesn't mean that it is true.

And because random HNer says it is ai doesn't mean it is ai.

>But still, is it so important?

Not to me, no. If the information is useful/entertaining/etc., I don't really care. But having to read "it's ai!" comments on literally every article/blog posted for the next 10 years is going to be super annoying. Especially if the reasoning provided is "they used the word critical". At least you pointed to something kind of interesting with the quotation marks (although, certainly not definitive of anything), rather than saying some extremely common word = ai.

replies(1): >>rvnx+4a
◧◩◪◨
7. nostra+G9[view] [source] [discussion] 2025-12-03 17:26:44
>>rvnx+58
So smart quotes is now an LLM tell? You know that a lot of people write in word processors that automatically replace standard quotes with smart quotes (like, say, MS Word), and that these word processors can then export HTML straight into your block or preserve the smart quotes across a copy & paste? Several blog WYSIWYG editors will also directly insert them as well.
replies(1): >>Nitpic+Mb
◧◩◪◨⬒
8. rvnx+4a[view] [source] [discussion] 2025-12-03 17:28:16
>>jfindp+89
Absolutely, anyway you'll have critical judgment to make your own opinion.

What bothers me about the Wiz post is why they want to hide this HTTP request is actually not helpful in terms of security.

On the plus side, they help getting the word out there, so at least something.

◧◩◪◨⬒
9. Nitpic+Mb[view] [source] [discussion] 2025-12-03 17:35:09
>>nostra+G9
I think what they're saying is that having both in a document is the tell.
replies(1): >>nostra+Xi
10. karimf+re[view] [source] 2025-12-03 17:49:05
>>jfindp+(OP)
When I saw "WIZ Research - Critical Vulnerabilities in React and Next.js" on the big image banner, I immediately thought that Wiz found the vulnerability.
replies(1): >>jfindp+Hi
◧◩◪◨
11. aprilt+Xf[view] [source] [discussion] 2025-12-03 17:54:46
>>rvnx+58
Yeah it's important, it degrades trust in the reader if you use AI without disclosing or ensuring them the document was proofread.

Same way if you read an article full of typos you lose trust in it. Those tells of AI voice undermine the author and make the reader suspicious

replies(1): >>jfindp+2p
◧◩
12. jfindp+Hi[view] [source] [discussion] 2025-12-03 18:09:08
>>karimf+re
When Reuters has an article that says "Reuters Business - Interest rates going up", do you think Reuters made the interest rates go up themselves or that they are reporting on the interest rates?
replies(1): >>acdha+bA
◧◩◪◨⬒⬓
13. nostra+Xi[view] [source] [discussion] 2025-12-03 18:10:05
>>Nitpic+Mb
The document doesn't have both in it. It's possible it was edited, but someone else in the thread posted the archive.org original version, and it also doesn't have smart quotes:

https://web.archive.org/web/20251203162416/https://www.wiz.i...

(Note also that you can end up with mismatched quotes if you paste in a segment of text from some other source that uses them, which is pretty common in journalism for a fast-changing story.)

replies(1): >>mmsc+5k
◧◩◪◨⬒⬓⬔
14. mmsc+5k[view] [source] [discussion] 2025-12-03 18:16:14
>>nostra+Xi
https://archive.md/2025.12.03-165833/https://www.wiz.io/blog...

Mismatched smart quotes are visible in this archive.

◧◩◪◨⬒
15. jfindp+2p[view] [source] [discussion] 2025-12-03 18:39:24
>>aprilt+Xf
>Same way if you read an article full of typos you lose trust in it

Not for long! This seems like this will soon be the only way to put something on the internet without people rabidly saying its ai (at least for a few weeks, until people start prompting for typos to be included).

◧◩◪
16. acdha+bA[view] [source] [discussion] 2025-12-03 19:35:08
>>jfindp+Hi
Reuters isn’t a bank. Wiz is a security company so they have a greater responsibility to distinguish between their own original work and discoveries made by other researchers.
replies(1): >>jfindp+fJ
◧◩◪◨
17. jfindp+fJ[view] [source] [discussion] 2025-12-03 20:15:44
>>acdha+bA
They do that by saying "we discovered this" when they discover it.
[go to top]