Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

38% Positive

Analyzed from 1167 words in the discussion.

Trending Topics

#book#activity#github#public#used#author#claude#https#com#writing

Discussion (38 Comments)Read Original on HackerNews

this_userabout 16 hours ago
Well, the "About the Author" section should probably just be a link to claude.ai.
jllyhillabout 12 hours ago
For anyone wondering, here's the author confirming it

https://news.ycombinator.com/item?id=48966159

And here's their Claude skill for writing

https://github.com/AdrianMastronardi/bookwright

sevgabout 16 hours ago
Yeah the (annoyingly) excessive use of colons feels like recent Claude models to me.

Looks like author posted this themselves earlier, and even used Claude for the HN comment:

https://news.ycombinator.com/item?id=48958457

infinite_spinabout 15 hours ago
I've always used a lot of semi-colons in my writing, especially in my technical writing. So I did a search on this pdf for semi colons, and there are 260 in a 264 page document. I then repeated this for the last book I read, Candide by Voltaire, and there were 507 semi colons in a 189 page book.

This seems like a witch hunt.

rwmjabout 15 hours ago
I read parts of it, being first hand involved in all this, and it seems like it was written by AI to me. If you used an AI to write it or help with it, why not just admit to it?
jstanleyabout 15 hours ago
I pasted the introduction into Pangram and it said 100% AI.
sevgabout 14 hours ago
You know I said colons right? Not semi colons :)
progbitsabout 15 hours ago
In last month or two I noticed semicolons getting used where previously it would be em-dash, in both cases excessively and often incorrectly.

I assumed some of my coworkers added "replace all em-dashes with semicolons" into their CLAUDE.md as a really crappy attempt at hiding their inability to write a single sentence without assistance.

tux3about 15 hours ago
Come on now, you can't also take away my semicolons. What am I supposed to do now; I barely have any punctuation left.
eth0upabout 15 hours ago
"free book" "no paywall and nothing to buy."

Might this not actually be a reasonable purpose for AI? I can tolerate the quirky style and AI signatures for something honest and free.

rwmjabout 15 hours ago
But prompting an AI adds nothing. Journalism is about research, interviewing the people involved, finding new facts, and then presenting that to your audience in a way they can understand. Getting an AI to write about something is just diluting the signal for future researchers.
bandramiabout 14 hours ago
Why not just post the prompt you used? I have access to LLMs too.
dhxabout 15 hours ago
See [1] for April 2024 Clickhouse Github activity analysis of the xz backdoor.

I haven't seen anyone write up a proper analysis that includes consideration of:

- GitHub activity (e.g. all API actions on GitHub side including replying to comments) _and_ mailing list activity _and_ other public facing activity all considered together.

- Complexity of public actions e.g. was there a queue of code changes that would have taken 20 hours effort to put together that were all committed at once? Were there any long streaks of high activity where it might reveal how many people were involved?

- Latency of public actions e.g. if an issue was raised by some random person, how long did it take for the attacker to respond, and later resolve/commit a patch? Similar to the complexity of public actions, it might reveal how many people were involved by estimation of the time needed for an experienced developer to fix an issue vs. actual time taken, both in terms of level of effort and duration.

- International dispersement of a team in different timezones with some core hours for collaboration, review and public facing activity.

- Public holidays, country/region-specific work habits, etc--e.g. consideration of "summer holiday" periods or similar common holiday periods, consideration of unusual days of no/low activity versus snow days, power outages, etc which might have been experienced by the attacker.

Distribution of actions from Github indicates the attacker used a 6 day work week excluding Sunday, and almost all activity conducted between UTC 12:00-16:00. Within these 6 days, activity was uneven at 0.5, 1, 1, 1, 1, 0.5 effort per day. There are low activity periods too that line up with summer solstice (southern hemisphere) or winter solstice (northern hemisphere).

There are interesting patterns in the data not yet publicly analysed (I think?) that seemingly would reveal the true location of attackers, particularly because attacker actions are anchored to uncontrollable events such as a known-good contributor (such as Linux distro maintainer) raising a Github issue against a repository and the attacker replying an hour later. For such events with low latency of reply, it'd be well worth considering when a reply was made quickly, and when it wasn't, across a few years of data points.

[1] https://news.ycombinator.com/item?id=39905375

OldMateyabout 16 hours ago
Given the time and effort that went into this, and the luck that one diligent person noticed, investigated and discovered what was going on before it could get further... it seems very likely to me that this has happened already in other libraries without being discovered.
VladVladikoffabout 14 hours ago
I wonder if the nation state actors are doing people profiling on owners of important packages to find the most vulnerable for an attack.
mirambaabout 16 hours ago
Exactly, and I wonder since then: How closely did people in comparable situations look? Since nothing similar has been reported, I suspect not very close…
IshKebababout 13 hours ago
The effort of gaining trust over an existing project isn't even really required. All you need to do is monitor when popular GitHub repos get archived. That's usually when the original authors don't want to work on it any more. Then just quickly make a fork to continue the project (think Phabricator -> Phorge), and if you're quick enough and authoritative sounding enough, boom control of the project!

Maintain it for a bit so people switch to your version, and job done.

akimbostrawmanabout 14 hours ago
Anybody running opensnitch would notice
pflenkerabout 13 hours ago
It’s great to have the entire topic brought together into a cohesive book - but wow, I find it very annoying to read.
ptxabout 12 hours ago
Probably because LLM output only gives the appearance of cohesive writing, but the more you try to understand the author's intent and meaning, the more confusing and annoying it gets, as there is no author, no intent and no meaning there to understand.
skippyfishabout 13 hours ago
Here's the tool developed by the author that was almost certainly used to generate this book in its entirety - "A structured pipeline for writing long-form nonfiction, packaged as a Claude Code skill":

https://github.com/AdrianMastronardi/bookwright

There's nowhere near enough public information about the xz vuln to be worth turning into a book, so the merits of AI-generated text aside, this is just a very inefficient way to learn about the topic.

eth0upabout 11 hours ago
"There's nowhere near enough public information about the xz vuln to be worth turning into a book," As an actual person, who reads, and having glanced at this book, I do not agree. I can already see part of the purpose is to put perspective on the crazy reality of backdoors/exploits and the undermined implications thereof. Jia Tan alone could warrant a book or film. It also says "for the general reader" and non-technical, which is where I myself think the importance really is. Maybe the AI is catching blindspots.

I downloaded the book. It's not fake. Perhaps no masterpiece, but far from worthless. Also, not "enough public information" really sells inference and imagination short. There is a rich amount of material to work with here. More than enough.

I am going to go ahead and say that flagging this was more information suppression than crankiness about AI. A lot of folks get strange when Jia Tan or similar subjects come up. I guess it's wiser to just wait until the grid goes down, or the water supply gets a bit more chlorinated....

kreyenborgiabout 16 hours ago
> The catch is where the book begins, not what it is about.
edblairabout 14 hours ago
Half expecting the next few paragraphs to contain, verbatim, "The smoking gun was a performance issue in a development build of Debian. It's was a sharp observation, and sharper than you may think."
tryauuumabout 16 hours ago
So Microsoft did something good? I thought they are too busy keeping my personal data in a prison and writing tight bash loops wasting 100 percent of a core
akimbostrawmanabout 14 hours ago
no, someone who just happens to work for microsoft doing something at home did something good.
lucasRWabout 16 hours ago
It's only going to recycle old news. The missing piece is attribution. Had it been the usuals (DPRK, Russia, China), the attribution would have been made publicly. The fact that is has not points as a friendly - especially when Microsoft (who owns Github) had all that telemetry and very likely has the means to find out. Some serious OSINT (consistency of timezone across months if not years of commits) pointed to the Middle East. An obvious Unit name comes to mind.
diogocpabout 16 hours ago
Fun fact: the guy who reported it (Andres Freund) works for Microsoft.

Another fun fact: Moscow is in the same time zone as the Middle East.

kryogen1cabout 15 hours ago
The middle east is not one time zone

https://whichtimezone.com/me/middle-east-map/

lucasRWabout 15 hours ago
Other fun fact: Microsoft and Mandiant have never had any problem doxing Russian APTs when they caught them.
anonreplierabout 15 hours ago
"all that telemetry" doesn't count for much if it's behind a VPN