6 ms·
> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalabl
by nativeit 1y ago
> On February 6, someone posted a lengthy and detailed critique of Elez’s code on the GitHub “issues” page for async-ip-rotator, calling it “insecure, unscalable and a fundamental engineering failure.”
“If this were a side project, it would just be bad code,” the reviewer wrote. “But if this is representative of how you build production systems, then there are much larger concerns. This implementation is fundamentally broken, and if anything similar to this is deployed in an environment handling sensitive data, it should be audited immediately.”
- deepfriedrice 1y agoThe "critique" is nuts. Surely AI generated. If I didn't trust the domain, I'd assume the author to be incredible for seriously referencing something like this. Look at the critique [0] and then look at the code [1]. [0] https://web.archive.org/web/20250423135719/https://github.com/markoelez/async-ip-rotator/issues/1 https://web.archive.org/web/20250423135719/https://github.co... [1] https://github.com/ricci/async-ip-rotator/blob/master/src/async_ip_rotator/__init__.py https://github.com/ricci/async-ip-rotator/blob/master/src/as...
- krferriter 1y agoLol that's so funny. Can't imagine writing that. (the critique, not the code).
- captainkrtek 1y agoYea clearly AI with the keyword bolding, numbered arguments, and so on. Feel like lots of AI produced content follow this structured response pattern.
- dragonwriter 1y agoIt's uses a simple, purpose-focused template of a type that is a common recommendation for clear communication, outline numbering, and highlights keywords using monospaced text, as is common practice in technical writing. None of that is unusual for a human, especially writing something that they know is going to be high visibility, to do. Modestly competent presentation is now getting portrayed as an "AI tell".
- captainkrtek 1y agoI’m not arguing that it’s unusual for humans to write in this manner, but when you use something like chatgpt with some frequency and see that as a common response template it’s an obvious pattern..
- drusepth 1y agoPeople say emdashes are a signal that something's from chatgpt also — yet people forget that the cliches or patterns of LLMs are learned from real-world patterns. What is common in something like ChatGPT has a good chance to also be common outside of it, and _lots_ of false positives (and false negatives) are bound to creep up frequently when trying to do any sort of pattern-based "detection" here.
- chongli 1y agoYes, emdashes are inserted automatically by iOS when a user inputs a double dash: —
- op00to 1y agoI’ve never encountered emdashes in emails from my colleagues before ChatGPT was available, and it’s obvious now where there are emdashes, the content is at least in part AI generated. Same with semicolons. Yes, proper grammar and syntax use semicolons but in most casual business communication those rules are modified for simplicity.
- ahwelatif 1y agoI'm relatively confident this critique is AI-powered. The dead giveaways: 1. Verbosity. Developers are busy people and security researcher devs are busy even moreso. Someone so skilled wouldn't spend more than 2-3 sentences of time in critiquing this repo. 2. Hostility. Writing bug free code is hard, even impossible for most. Unless your name is Linus Torvalds, Richard Hipp, or maybe Dan Abramov, most devs are not comfortable throwing stones while knowing they live in glass houses. 3. Ownership. "Killshot" comments like this are only ever written by frustrated gatekeepers against weak PRs that would hurt "their baby". Nobody would get emotionally invested in other people's random utility projects. This is just a single python file here without much other context. 4. Author. The author is still an aspiring developer. See their starred repo highlighting adherence to SOLID/DRY principles as a primary feature of their project. Not something you'd expect to see from a seasoned security researcher. https://github.com/SSD1805/EchoFlow https://github.com/SSD1805/EchoFlow 5. Content. The critique is... wrong. It says the single file, utility repo is "awful" for being a "less maintainable" monolith. Hilariously, it calls the code bad because it does not need dependency injection. This was a top critique in the comment! -- Regardless of political persuasion, I hope this trend of using AI to cyberbully people you don't like goes away.
- mquander 1y agoSeeing Krebs link to this downgrades my impression of how trustworthy his assessments are.
- dessimus 1y ago> it should be audited immediately. Certainly Elon made him print it out on paper to personally code review.