Dr. Hax on Nostr: OK, at the risk of stirring up a hornet's nest, I'm going to #AskNostr to help me ...
OK, at the risk of stirring up a hornet's nest, I'm going to #AskNostr to help me understand why people think an army of script kiddies is a security threat to any decent open source project.
I get why they'd be a threat to something that was hacked together in a hurry, and doubly so if it's unnecessarially complex (design, dependencies, etc.). That makes perfect sense.
I don't consider the above to meet my definition of a "decent open source project". If you're fixing security holes every day for months on end, your code is not very good. Sorry, not sorry. You need to ask why you didn't catch these things earlier. And if the answer is that it's all upstream bugs, you need to ask yourself why you have those dependencies.
Whether the attackers use AI or not doesn't seem like it should change the equation. If doesn't matter how advanced your AI is, it's a question of attack surface and code quality.
I do understand why the developers could be overrun by a ton of meritless bug reports generated by AI. That's a very real operational problem, but that's not a security theat.
My take is this: script kiddies and AI tools help reveal the difference between projects that have good code, and ones that don't.
Previously, we could look at the number of dependencies and complexity of a project and get a feel for whther it's held together with bailing wire and duct tape. Now, if AI can write a functional exploit, we can also get evidence of what we suspected. I think this is a good thing. Change my mind.
Published at
2026-08-11 20:22:30 UTCEvent JSON
{
"id": "079a39dcbcf5105fd979ba598900365968248c3c6d08ba90604347a0d74c4539",
"pubkey": "d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511",
"created_at": 1786479750,
"kind": 1,
"tags": [
[
"alt",
"A short note: OK, at the risk of stirring up a hornet's nest, I'..."
],
[
"t",
"AskNostr"
],
[
"t",
"asknostr"
]
],
"content": "OK, at the risk of stirring up a hornet's nest, I'm going to #AskNostr to help me understand why people think an army of script kiddies is a security threat to any decent open source project.\n\nI get why they'd be a threat to something that was hacked together in a hurry, and doubly so if it's unnecessarially complex (design, dependencies, etc.). That makes perfect sense.\n\nI don't consider the above to meet my definition of a \"decent open source project\". If you're fixing security holes every day for months on end, your code is not very good. Sorry, not sorry. You need to ask why you didn't catch these things earlier. And if the answer is that it's all upstream bugs, you need to ask yourself why you have those dependencies.\n\nWhether the attackers use AI or not doesn't seem like it should change the equation. If doesn't matter how advanced your AI is, it's a question of attack surface and code quality.\n\nI do understand why the developers could be overrun by a ton of meritless bug reports generated by AI. That's a very real operational problem, but that's not a security theat.\n\nMy take is this: script kiddies and AI tools help reveal the difference between projects that have good code, and ones that don't.\n\nPreviously, we could look at the number of dependencies and complexity of a project and get a feel for whther it's held together with bailing wire and duct tape. Now, if AI can write a functional exploit, we can also get evidence of what we suspected. I think this is a good thing. Change my mind.",
"sig": "191d19c79f722ccea4815b5feb21f5269beec8d75a9d0c3c65a77a738453b774b11659b625757d9d6351d348d0044567b657263682f5e558315c573523bb2beb"
}