oss-security 'AI slops from Eve' thread: LLM-generated fake advisories trigger moderation debate
An oss-security thread (2026-09-11 to 2026-09-13) discussed AI-generated 'slop' postings from an account known as Eve. Moderator Solar Designer said he may reject repetitive AI-generated submissions but moderates by content, not sender domain; a header-less…
The oss-security thread 'AI slops from Eve' (2026-09-11 through 2026-09-13) centered on LLM-generated fake security reports posted from an account known as Eve. On 2026-09-11, list moderator Solar Designer said he may start rejecting repetitive AI-generated submissions, and later the same day clarified that moderation is primarily by content rather than sender domain, noting no domain produces enough unwanted traffic to warrant pre-filtering; he referenced a mail hosting provider claiming roughly 1.4 million users. Contributor Joe Krause took a harder line, describing cock.li as hosting many script kiddies and advising recipients to treat almost any email from that domain as spam — a stance in tension with the moderator's content-based approach. On 2026-09-12, David A. Wheeler argued AI will greatly reduce attack costs, making attacks proliferate and be painful for years, urged defending all IT systems (not just critical ones), and noted AI also helps find and fix vulnerabilities; Collin Funk criticized AI labs for offering short free compute trials to free software projects to create paid dependency. On 2026-09-13, Jeroen Roovers asked whether a header-less LLM-generated message came from the same source as a fake advisory posted May 15, 2026 titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers' (both lack Date headers); Solar Designer concluded the suspicious messages share only trivial traits (missing Date header, LLM use), saw no significant problem with any particular sender or model, and said no investigation is needed. The thread contained no CVEs, advisories for real vulnerabilities, or concrete incidents.
- Thread 'AI slops from Eve' ran on oss-security from 2026-09-11 to 2026-09-13, discussing LLM-generated fake security reports ('AI slop') posted from an account known as Eve.
- 2026-09-11: Moderator Solar Designer said he may start rejecting repetitive AI-generated submissions on oss-security.
- 2026-09-11: Solar Designer stated moderation is primarily by content, not sender domain; no domain produces enough unwanted traffic to warrant pre-filtering; he referenced a mail hosting provider claiming roughly 1.4 million users.
- 2026-09-11: Joe Krause described cock.li as a mail host housing many script kiddies and advised treating almost any email from that domain as spam, then declined to continue the discussion.
- Sources differ on domain handling: Krause urged treating cock.li mail as spam, while moderator Solar Designer said moderation is by content rather than sender domain and no domain warrants pre-filtering.
- 2026-09-12: David A. Wheeler argued AI greatly reduces the cost of attacks, so attacks will greatly proliferate and be painful for many over the next few years; he urged protecting all IT systems, noting many who assumed 'I won't get…
- 2026-09-12: Collin Funk criticized major AI labs for offering temporary free compute trials to free/open-source projects to create paid dependency rather than genuinely helping with maintenance.
- 2026-09-13: Jeroen Roovers asked whether a current LLM-generated message without a Date header came from the same source as a May 15, 2026 posting titled 'Security Advisory: Multiple Vulnerabilities in llama.cpp GGUF Format Parsers'; both…
Coverage timelineoldest first · each row is one article
- · 7d agoRe: AI slops from Eve
oss-security· 12
oss-security commenter argues AI models remain human-built algorithms while reflecting on recent AI-slop incidents in open-source