Re: AI slop "contributions" to IETF working groups
Robert Moskowitz <rgm-ietf@htt-consult.com> Tue, 10 February 2026 19:18 UTC
Return-Path: <rgm-ietf@htt-consult.com>
X-Original-To: ietf@mail2.ietf.org
Delivered-To: ietf@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 774E9B4E516D for <ietf@mail2.ietf.org>; Tue, 10 Feb 2026 11:18:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=htt-consult.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d55x_j_uH9rc for <ietf@mail2.ietf.org>; Tue, 10 Feb 2026 11:18:34 -0800 (PST)
Received: from klovia.htt-consult.com (klovia.htt-consult.com [23.123.122.149]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256)) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 2E8F7B4E5164 for <ietf@ietf.org>; Tue, 10 Feb 2026 11:18:34 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=htt-consult.com; s=mail; t=1770751112; bh=ZCCLyTIrNmANnnMCwx1+qzSbqsvwBf4mFsMenf2dFKU=; h=Date:Subject:To:Cc:References:From:In-Reply-To:From; b=Nd4aVNbojjeA+HPaLxh/ZLA25wh7EvjXYTzetmOMZETXvcp7X3fbGeRHBm6OTr4gG Cd2WpxJ1BLUoMXsESSr4WFjnCfmQ1n7asST2XaaZE5Q9yzKRQSWgjajTlvCe2FVAoE YQ1OOx+Q/xgrDnLz05aJGTMVQRnmTzy5ncDNZOCJZzQsvF1uB+XeAIRnLtHAw/iUSg OakjNRnzv3+r1FJ0mC+EAn8rqJ5/Nb5/JDrgT3WnpNpXzxcexV5SxNctk0TnXjSlhF BS1hFzruJv9H9Xf73JHKvVDQT+crQJJoUJGNriq73Zo+7UnDgV+2idDMdMYROybLBh ZQ+3IHB/Qcyew==
Received: from authenticated-user (klovia.htt-consult.com [23.123.122.149]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by klovia.htt-consult.com (Postfix) with ESMTPSA id 9FC0D4A043D; Tue, 10 Feb 2026 14:18:32 -0500 (EST)
Content-Type: multipart/alternative; boundary="------------jy7WC6GlqL5OMb3gHpRXgrfg"
Message-ID: <e638be09-9302-47a9-81ad-738a815e7a71@htt-consult.com>
Date: Tue, 10 Feb 2026 14:18:32 -0500
MIME-Version: 1.0
Subject: Re: AI slop "contributions" to IETF working groups
Content-Language: en-US
To: noloader@gmail.com, ietf@ietf.org
References: <7b702e8f-d2be-5b08-e262-33fbed538f98@foobar.org> <460BCE12-4C45-45D0-94C8-83B8E2D45049@gmail.com> <922b6d08-1cb5-4791-974f-ff17850de25f@gmail.com> <5DCE2993-39C8-4FAC-AD91-7B8E504E996C@gmail.com> <20260208015537.8D945F5944ED@ary.qy> <cd492277-0bca-4219-a3ad-eb75ccd2ebe7@gmail.com> <m27bsk6d9c.fsf@ja.int.chopps.org> <d5bccc8e-f013-c3e5-09cc-30913983b2f0@foobar.org> <b94b3e13-ebc9-4fb1-932f-89b05c2ce3ec@joelhalpern.com> <28670ac9-159c-4830-afe7-c5df4ce354da@htt-consult.com> <CAMm+LwiDfNb1j3khkWCik8ZTziyzOFFyqEZqbVX_F9DStwx9yQ@mail.gmail.com> <CAH8yC8knKz5a=i90tJ69ghoiQ_CaeT0CYkTtB-LSTsUSC9tsEw@mail.gmail.com>
From: Robert Moskowitz <rgm-ietf@htt-consult.com>
In-Reply-To: <CAH8yC8knKz5a=i90tJ69ghoiQ_CaeT0CYkTtB-LSTsUSC9tsEw@mail.gmail.com>
Message-ID-Hash: KQTWEITZVEHIEVQ5G4GT6AEJG572P4FR
X-Message-ID-Hash: KQTWEITZVEHIEVQ5G4GT6AEJG572P4FR
X-MailFrom: rgm-ietf@htt-consult.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-ietf.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Phillip Hallam-Baker <phill@hallambaker.com>
X-Mailman-Version: 3.3.9rc6
Precedence: list
List-Id: "IETF-Discussion. This is the most general IETF mailing list, intended for discussion of technical, procedural, operational, and other topics for which no dedicated mailing lists exist." <ietf.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/UXtLv5LO6W1PHTK9wK2dyUCvqd8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Owner: <mailto:ietf-owner@ietf.org>
List-Post: <mailto:ietf@ietf.org>
List-Subscribe: <mailto:ietf-join@ietf.org>
List-Unsubscribe: <mailto:ietf-leave@ietf.org>
On 2/10/26 2:07 PM, Jeffrey Walton wrote: > > > On Tue, Feb 10, 2026 at 1:36 PM Phillip Hallam-Baker > <phill@hallambaker.com> wrote: > > How is using an AI different from using fuzzing though? > > One of the most effective hacking tools is to simply spam the > inputs with garbage and see what happens. So it isn't exactly > surprising that when people write code in unsafe languages without > null pointer and array bounds checking, they can discover low > hanging fruit vulnerabilities faster than others. > > What such testing doesn't show is that the code is secure because > AI generated tests aren't exhaustive. Just as 'write slop, check > it by fuzzing' isn't a valid method for producing secure code, > neither is 'check with AI'. > > > A dangerous (?) trend I am seeing at $dayjob... We perform static > scans on an app's code base, and dynamic scans on a running > application in a test environment. A tool produces a finding that > triggers a code review. The dev team will often say the finding is a > false positive because "<favorite AI tool> says it is Ok." > > I like to remind the dev teams that Edsger Dijkstra's observation > still holds. AI tools can be used to confirm the presence of a bug, > not the absence of them. > > I feel AI tools would be much more useful during development if they > produced boatloads of negative test cases that attempted to break the > application. Since AI is supposed to be smart, it should be easy for > it to create the boundary test cases that developers often miss. One of the side discussions we were having. I think some of this is going on behind security walls. > > Which brings up another interesting question: should AI be allowed to > write the code and the test cases? Would that violate separation of > duties? Also discussed. Test cases are needed more.... > > Jeff
- AI slop "contributions" to IETF working groups Nick Hilliard
- Re: AI slop "contributions" to IETF working groups Loganaden Velvindron
- Re: AI slop "contributions" to IETF working groups Kathleen Moriarty
- Re: AI slop "contributions" to IETF working groups Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups Colin Perkins
- Re: AI slop "contributions" to IETF working groups Bob Hinden
- Re: AI slop "contributions" to IETF working groups John Levine
- Re: AI slop "contributions" to IETF working groups John Levine
- Re: AI slop "contributions" to IETF working groups Orie
- Re: AI slop "contributions" to IETF working groups Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups Kathleen Moriarty
- RE: AI slop "contributions" to IETF working groups Cheng Li
- Re: AI slop "contributions" to IETF working groups George Michaelson
- Re: AI slop "contributions" to IETF working groups Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups George Michaelson
- Re: AI slop "contributions" to IETF working groups Christian Hopps
- Re: AI slop "contributions" to IETF working groups Nick Hilliard
- Re: AI slop "contributions" to IETF working groups Joel Halpern
- Re: AI slop "contributions" to IETF working groups Job Snijders
- Re: AI slop "contributions" to IETF working groups Robert Moskowitz
- Re: AI slop "contributions" to IETF working groups Nick Hilliard
- Re: AI slop "contributions" to IETF working groups Phillip Hallam-Baker
- Re: AI slop "contributions" to IETF working groups Robert Moskowitz
- Re: AI slop "contributions" to IETF working groups Jeffrey Walton
- Re: AI slop "contributions" to IETF working groups Robert Moskowitz
- Re: AI slop "contributions" to IETF working groups Rob Wilton (rwilton)
- Re: AI slop "contributions" to IETF working groups Rich Kulawiec
- Re: AI slop "contributions" to IETF working groups Phillip Hallam-Baker
- Re: AI slop "contributions" to IETF working groups George Michaelson
- Re: AI slop "contributions" to IETF working groups Carsten Bormann
- Re: AI disclosure [was: AI slop "contributions" t… John Levine
- Re: AI disclosure [was: AI slop "contributions" t… John R Levine
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups Behcet Sarikaya
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI disclosure [was: AI slop "contributions" t… Stephane Bortzmeyer
- Re: AI slop "contributions" to IETF working groups Arturo Servin
- AI disclosure [was: AI slop "contributions" to IE… Brian E Carpenter
- Re: AI disclosure [was: AI slop "contributions" t… Michael Richardson
- Re: AI slop "contributions" to IETF working groups Laurence Lundblade
- Re: AI disclosure [was: AI slop "contributions" t… Michael Richardson
- Re: AI disclosure [was: AI slop "contributions" t… Donald Eastlake
- Re: AI disclosure [was: AI slop "contributions" t… John R Levine
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI disclosure [was: AI slop "contributions" t… Phillip Hallam-Baker
- Re: AI disclosure [was: AI slop "contributions" t… Lixia Zhang
- Re: AI disclosure [was: AI slop "contributions" t… Robert Moskowitz
- Re: AI disclosure [was: AI slop "contributions" t… Christian Huitema
- Re: AI slop "contributions" to IETF working groups Phillip Hallam-Baker
- Re: AI disclosure [was: AI slop "contributions" t… Phillip Hallam-Baker
- Re: AI slop "contributions" to IETF working groups Tal Mizrahi
- Re: AI disclosure [was: AI slop "contributions" t… John R Levine
- Re: AI disclosure [was: AI slop "contributions" t… John R Levine
- Re: AI slop "contributions" to IETF working groups Rob Sayre
- Re: AI disclosure [was: AI slop "contributions" t… Jeffrey Walton
- Re: AI disclosure [was: AI slop "contributions" t… Lixia Zhang
- Re: AI disclosure [was: AI slop "contributions" t… Michael Richardson
- Re: AI disclosure [was: AI slop "contributions" t… John Levine
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups Jeffrey Walton
- Re: AI disclosure [was: AI slop "contributions" t… lloyd.wood
- Re: AI disclosure [was: AI slop "contributions" t… Abdussalam Baryun
- Re: AI disclosure [was: AI slop "contributions" t… Lloyd W
- Re: AI slop "contributions" to IETF working groups Lixia Zhang
- Re: AI disclosure [was: AI slop "contributions" t… Michael Richardson
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI slop "contributions" to IETF working groups Joel Halpern
- Re: AI slop "contributions" to IETF working groups Nick Hilliard
- Re: AI slop "contributions" to IETF working groups Phillip Hallam-Baker
- Re: AI disclosure [was: AI slop "contributions" t… Christian Huitema
- Re: AI disclosure [was: AI slop "contributions" t… George Michaelson
- Re: AI disclosure [was: AI slop "contributions" t… Brian E Carpenter
- Re: AI disclosure [was: AI slop "contributions" t… Toerless Eckert
- Re: AI disclosure [was: AI slop "contributions" t… Lixia Zhang
- Re: AI disclosure [was: AI slop "contributions" t… Abdussalam Baryun
- Re: AI slop "contributions" to IETF working groups Elmar K. Bins
- Human SI - Re: AI slop "contributions" to IETF wo… Toerless Eckert
- Re: AI slop "contributions" to IETF working groups Toerless Eckert
- Re: AI disclosure [was: AI slop "contributions" t… Christian Huitema
- Re: AI slop "contributions" to IETF working groups Michael Richardson
- Re: AI disclosure [was: AI slop "contributions" t… Toerless Eckert
- Re: AI disclosure [was: AI slop "contributions" t… George Michaelson
- Re: AI disclosure [was: AI slop "contributions" t… Martin J. Dürst