>The community can now contribute code and solve issues more faster rather than a handful of people gatekeeping slowing down development
Everyone hates gatekeeping until they don't. Watch quality go down, issues increase, project direction become muddied, and suddenly people will be calling for more gatekeepers!
> The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
Sounds like he is salty that somebody found an exploit using LLM that he found manually (which probably took a significant amount of time.) I can partly understand it, but I mean that's also just the game that somebody else might find an exploit, LLMs just make it easier. LLMs finding bugs is not a bad thing, just sucks for enjoyers of open source software in this particular case.
>I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.
This guy has used on working with people that understand the scene, it seems that they were in contact, they agreed on something and then the next day they did something different.
This is really important in the context of what happened and probably the cherry on top of the current "hacking" cake, with the bar being lowered so much that anybody can jump in with some minor skill and luck and get something just for themselves.
"Sounds like he is salty that somebody found an exploit using LLM that he found manually"
No, he's salty that this last remaining hypervisor exploit is going to get patched, causing his PS5 Linux project to get wholly-fucked as now there will be no (currently-known) way to sideload the OS. Reading comprehension is very important here.
I think you've hit the nail on the head. I've seen this behavior from others in the space before too, it's not a one-off. They refuse to use LLMs themselves, and state as much publicly "I simply don't need to resort to using the slop machine, my skills are superior", yet FUME when others they deem as "lesser" are able to use it to achieve the same results as them, oftentimes faster.
I can guarantee this post would not have been made had he not been the one to find that vuln first.
That's not the fault of the model, though. Even knowledgeable people that found everything manually can (ir)responsibly disclose it to the vendor for a payout.
Just look at the iOS jailbreaking scene and how Apple repeatedly poached all the devs until there was no one left, killing it off well before LLMs.
No guarantee at all that a new exploit will be found, and even much lower probability that a suitable lead developer will be found. The slop kiddy was just an asshole TBH.
> The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
I don’t know if he’s mad AI scooped a bug? Or that LLM slop kiddies don’t pay attention to that something is already known?
I found it a bit hard to understand this discussion because I wasn't familiar with the background. If I've got this right, his project let you run Linux on a PlayStation 5 (thus also providing the ability to run modern games).
Slop kiddies using AI discovered the PS5 hypervisor exploit it relied on for installation. Initially they agreed to his request to delay reporting it to Sony until after GTA6 came out (so users could at least install and enjoy that highly anticipated game). But then they turned around and disclosed it anyway (the same or next day?).
They presumably gained a nominal bounty, but nuked the project he'd poured so much hard work into. Including support for PS5 Pro he was preparing to release next year.
The community used to be a group of talented researchers, but he's frustrated it's diluted into participants who don't even understand the hacks they produce.
In other words: when it's trivial to find an exploit from a vague description, someone will report it. It doesn't take "they" to report a vulnerability. A single person can do it.
This sounds like LLM noobs ruined the chance of legally playing GTA6 and habe Linux support and he seems pretty frustrated about it
> I am stepping away from the ps5 scene and stopping all my work on ps5 linux.
After pouring my heart and months of my life into it, including plans to finish ps5 pro support and release in 2027, it's all down the sink.
> The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
> I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.
> “Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
If one user could have found this using AI. Then I would imagine anyone else could have found it.
Then I would imagine anyone else could have found it.
Right, including Sony. AI finding security flaws is very good in general, but one downside is that it will become easier to make "secure" devices that are hostile toward their owners.
> If one user could have found this using AI. Then I would imagine anyone else could have found it.
People are still fixated on using AI to produce code (to reduce salary costs/dev time) rather than using it to audit bugs in one own's code, which they are better at.
Fascinating times we live in, when "the last hypervisor bug" in what is presumably one of the most hardened pieces of consumer hardware can be found by "noobs" and "slop kiddies".
No, it doesn't. Nobody would go do this just to report it to Sony for a few pennies. That is a non-existent motivation for people in the know, who understand the opportunity cost.
I say it's only because LLMs came out after the PS5 was developed. Presumably, future generations of hw (if there are any) will use the same methods to harden the attack surface. Good ole cat and mouse.
The headline here is off, PS5 Linux relies on bugs for installs, and the project couldn’t keep the last know hypervisor bug secret:
> Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
So what has really happened is the LLMs have lowered the participation floor for this space enough the dynamics are changing. The new comers would rather have a few dollars vs. the founders who would rather have a project. It’s likely the projects days were numbered either way because Sony could also just take a frontier LLM would and examine any released installer for the project and reverse engineer and bug.
Everyone in this scene knows upgrading your console is sure path to getting yourself locked out of current and probably future exploits. I don't think anything really changed here. The moment these exploits go public, they'll be patched in the next version.
This vulnerability will still exist in older versions. The project can still continue development of Linux on PS5 and, eventually, another exploit will be found that enables the installation on a later version.
Frankly, based on the language used, a resignation over this seems to have a lot more to do with the person being upset that LLMs are lowering the bar for entry. They seem more upset that their skills aren't as useful as they were.
It seems like the reputation as a PS5 hacker was the objective, not getting Linux running on PS5.
now imagine how many other devs and maintainers are contemplating this but just haven't been pushed to their personal breaking point yet. or take note of how many, when asked about the spam problem, just nervously go "yeah it's kinda rough haha...". or how many will vent about it on their twitter-like of choice with increasing frequency.
remember hacktoberfest 2020? that's just all public-facing source 365 days a year now, except instead of "updated README.md" it's some vaguely-plausible fix... then you read the PR body and someone couldn't even be bothered to, or, just as likely couldn't explain it themselves. and that sort of sinking dread sets in.
> now imagine how many other devs and maintainers are contemplating this but just haven't been pushed to their personal breaking point yet. or take note of how many, when asked about the spam problem, just nervously go "yeah it's kinda rough haha..."
At first, my brain parsed "spam" as in ye olde email spam. It took a moment for it to sink in that you meant code spam, instead.
But now that the two concepts are linked in my little pea brain: I kind of want to see how a system like SpamAssassin would work when applied to pull requests like it has been applied to email.
It can use reputation, real-time blacklists, triggers for form, and et cetera, with weighted scores for every aspect that are ultimately factored into one final score.
If final score is passing, the PR is presented for a human to review like a PR was (say) 5 years ago. If the final score fails, it goes into the circular file where it will probably die.
I've been on both sides of the spam arms race at different times of my life. While they'll never be able to claim victory, the good guys (usually!) seem to be winning -- and that's a lot better than accepting defeat.
Hobby groups projects like this are less fun for a lot of people who used to enjoy interacting with smart people. It's definitely become a game of just spam claude for answers with zero understanding or care for how anything actually works. That's fine to get things done and fine for a lot of side projects, but it definitely ruins the joy that people have in understanding systems and working with intellectuals.
This was already true (as sibling comments note) but it's _way_ sharper now. Even if you use an LLM to research or answer a question, editing it down for other people takes effort, and doing it well demonstrates understanding.
> Hobby groups projects like this are less fun for a lot of people who used to enjoy interacting with smart people
It is insane just how miserable the experience of FOSS hardware hacking in public is.
The expectation does not even the slightest match reality.
You'd think "ah yes many eyes meaning all bugs get shallow", but instead you get worst of XDA-Developers and toxic wastelands where no sane person even answers anymore.
But this predates LLMs and was as miserable as it is now before as well.
In fact, I might even argue that LLMs made this _better_, because you can now avoid the "opening up in hopes of finding 1 helpful person below 99 annoying ones" through simple GPU compute.
Previously, you had to hope that through this self-inflicted horror, you'd find an expert that can augment you. Now that expert rests on huggingface.
It's still.. not perfect, of course. But it might be less miserable - provided that you adapt to the current state of things and stop with the "trawling for volunteers".
__
Of course, this does not help you against "skids let claude find bugs that you'd need and burn it for no reason" as per the twitter thread, but I wouldn't rule out that they would not have done that, if less information was public.
And.. that too was an issue before LLMs.
Information wants to be free, but so does your cat, and your cat gets run over by some crackhead in a 30 year old rusty pickup if you just put it outside without thinking.
Isn't the problem just that open source, by it's very nature, is low quality since it comes from the unix-like ecosystem where everything is built atop everything else. So inevitably when the skid comes to you with a bug you can say "ah that's a bug in a specific build of your shell with these environment variables, myyyy code is clean as a whistle, minimal, and follows best practices" (if we ignore that in practice it depends on a billion different programs versions all of which are incorrect)
Complaining about the inevitable toxic noise when the same boneheaded development decisions are made over and over like everyone has gone insane. You don't have to build a death trap on the land your cat and children roam.
I have been disabling PRs in all my repos because of the mountain of garbage I receive. Previously I also accepted very few but was always able to use the opportunity to at least explain why things work the way they did, and often improve the submitter’s skills. If you submit an LLM fix, I don’t bother; you clearly haven’t bothered to understand the basics of project or how it works, so why should I waste my time and sanity explaining something you also won’t read and will at most shove into your LLM?
I haven’t yet started disabling issues. Let’s hope it doesn’t come to that.
completely different world, but i've seen this happen in music spaces as well.
the idea of gatekeeping is often seen as elitist or exclusionary (fairly enough in many cases) but i think this can be an exaggerated description of a culture that necessarily requires a standard of... let's say, desire to engage with material on a sufficiently deep level. many things can be for anybody, but they are not for everybody.
in the past i've seen the phenomenon of "opening up" subcultures or previously-niche intellectual/art fields described as democratization but i think that ignores a big part of what causes this, which can more accurately be described as commodification. access to difficult things was formerly measured by one's ability to expend effort in order to get there (ignoring, for now, the structural conditions that set one up for success in that effort). when these things are commodified, these efforts and identities become products to purchase, the right to which is nearly never limited; in fact, it's almost seen as evil to imply that they should not be available to any individual at any time that individual may desire access.
i know we all have to start somewhere, but there has always been some historical filtration that leads people who are not truly engaged with a subject on a deep level to disengage at some point. that's changing at a novel rate and scale across so many subcultures. it seems like a lot of us are just surprised at how many people even want access to what were once our sanctuaries and we're not capable of grappling with what it takes to adapt to these changes.
i don't think this will pass or that things will return to "the way they were" but there will always be pockets that resemble previous subcultures. we just have to re-learn how to identify them with a keener eye and how to better avoid or more-appropriately interact with those who have a more superficial interest in them.
I think the difference is that while you might have access to the subculture, there is no obligation for anyone else to respond, collaborate or engage with random you. This is a common mistaken understanding about open-source software projects; users often think they have "rights" to compel or coerce volunteer developers to listen or reply to them.
> While you might have access to the subculture, there is no obligation for anyone else to respond, collaborate or engage with random you.
true, but i think there's historically often been good-faith efforts to engage with newcomers in any field that requires intellectual or artistic curiosity or experimentation. what we're seeing played out is that this default good nature ignores the risk involved in growing a small garden beyond one's own property. there is a change in meta-social requirements at scale.
the extremes of this are super apparent in FOSS - one side of this being death-by-committee and overgovernance at the expense of the original project (requiring a support organization that outgrows the actual "work"), and the other side a harsh rejection of newcomers or calcification against new ideas.
but they're not limited to FOSS. i think these are probably fairly well-studied ideas in any form of organizations - business, social groups, churches, non-profits, unions, etc. i don't really know where to start to learn more about this or what the right approaches are (and i suspect they're often pretty unique to the group in question).
Projects like this probably need a dedicated noob-fork where 'anything goes', so the noobs feel like they're contributing but where their blast radius is contained.
And once in a blue moon something good comes out of it back to the real project.
This space is where AI usage is most confounding to me. Regardless of your stance on AI, this work does not need to be done. So if you don't enjoy it enough to actually do it, why are you even here? If you do enjoy the work, why are you letting the AI do your hobby? Don't you miss it?
In my hobby groups there has always been a second, smaller, more intimate invite-only space for people doing the deep work. It’s the only way to do the work in the age of 1000-member Discords where important conversations get lost in the scroll back instantly.
The experience in these spaces is largely the same. LLMs can be used there, too, but when the experts are using them with experience to back it up the results are a lot better.
The people who are really struggling in my few hobby groups (not PS5) are those who enjoyed some social status from their knowledge. They were heros and people sought them out and revered their work in 2023. LLMs came along and partially leveled the playing field. When a determined kid with a Deepseek subscription can produce a sloppy version of what took you years to find, that sense of being a heroic figure at the next level is gone.
I think this reveals another wrinkle, which is that the status hierarchy wasn’t that solid or worthwhile anyway. Outside of a few vocal people trying to enforce the status hierarchy, most people don’t care who releases their jailbreak or PS5 exploit. They just want it. Whoever gets it to them first becomes the new king.
This PS5 incident has some strange element where supposedly keeping the reveal secret for 2 more weeks would have changed something with the GTA6 release. There were also 3 people who found the same exploit independent and some large amount of money on the line for the first of them to report it. The person who reported it signed off to spend time with his dying mother, so can’t really fault them for doing the thing they earned according to the rules of the program.
The status thing is probably part of it, but I'm not sure "a kid with Deepseek can make a sloppy version" actually shows that the old hierarchy was meaningless.
> This PS5 incident has some strange element where supposedly keeping the reveal secret for 2 more weeks would have changed something with the GTA6 release.
Well it's that GTA 6 comes out in mid-November, so he wanted to wait until then to release the exploit so people could legally run GTA 6 on their hacked PS5s. Disclosing the exploit before the release means that they'll patch it before GTA 6 comes out so this is no longer an option.
I think this is unrelated because it happened after theflow0's statement, but Sony just released a major PS5 update that significantly increases the PS5's security ahead of GTA 6's release. Apparently it's impossible to rip games now without a hypervisor exploit, and since the last one just got reported to Sony this means that even people with hacked PS5s on old firmwares won't be able to pirate GTA 6 since nobody will be able to rip it. https://www.reddit.com/r/PS5_Jailbreak/comments/1wi0gpx/its_...
You don't have to want to give the policeman status: once he pulls you over after running a red light at 2am and you realise he might let you off the hook if you are nice and deferential, the status gradient almost establishes itself. So it was with tech wizards, once you encountered a problem you could not solve without their help.
This title and the first quote are misleading. A dev found an undisclosed hypervisor exploit using AI that TheFlow0 had been using and keeping secret, but the other dev had informed Sony to collect the bug bounty.
It's an issue that the dev attempted to collect the bug bounty, AI or no
It's strange working on Opensource these days. I've mostly worked on my own stuff alone which usually doesn't get much attention/additional contribution. Then I see on Reddit, HN or LinkedIn someone creating a major App or Plugin in a weekend. Sometimes I take a closer look the artisanal quality is effectively unmaintainable, at least for humans. But in the end it's hard to get a good overview, and the sheer quantity seems to dwarf any other efforts.
Not to mention how the code can then be sourced by an AI model in an instant without any credit.
> it seems that vibe-coders, or “slop kiddies” as the modder dubbed them, used AI to detect a bug that they were using to crack consoles, and reported it to Sony for a bounty.
That would indeed be incredibly demoralizing, even crushing. Quite a dick move.
Now that said, I imagine it was only a matter of time anyway until Sony found/fixed or someone else did the same thing. It's just a different world now.
As much as I'd love a non locked down PS5, anyone buying one knows what they're getting. If you care about user empowerment, PC (Valve hardware, etc) is the place to put your money and time. Sony is actively hostile toward you and wants you locked down, and trying to fight it with exploits is destined to be a nasty cat and mouse game. Go with a vendor that is more aligned to your values.
So the non-noob-but-asshole (supposedly talented) dev was relying on the fact that Sony would not run the same tools "noobs" did. Well, that's.. not smart.
> “Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
Ever since consoles became moving targets there's been deliberate gatekeeping - specifically, drip-feeding of bugs - to maximize the chance someone can actually use them to break DRM and install Linux. This relies on the fact that most people do not want to have to become FreeBSD kernel experts in order to install non-PlayStation software on their PlayStation. But if everyone is vibe-hacking their PS5s then none of this logic applies. Any bug Claude can find is one Sony also knows about and will get patched, possibly before you even release an exploit for it.
How this ultimately plays out depends on if it's even possible to write software without bugs. Maybe this reaches a new equilibrium where people are paying Claude to vibe-code jailbreaks - as I'd initially hoped. But it's equally as likely that this winds up reinforcing DRM rather than weakening it, for a few reasons:
1. Anthropic's AI safetyism culture encourages the prohibition of vibe-coded jailbreaks. The fact that the model runs on a server and people are spying on your chatlogs means Anthropic has actual knowledge of who is actually using their service to find PS5 hypervisor bugs. Letting Claude break DRM is legally risky; DMCA 1201 implies the only lawful way to break DRM is for you to find your own bugs. So it's probably not going to be long until everyone vibe-coding jailbreaks will get banned.
2. Sony will not be getting banned from these services, they will get trusted access as they're big enough for Anthropic to sue if it gets misused.
3. The attack surface of the thing you have to actually compromise to get code execution on any locked-down system is really small. The Xbox 360 had a 15+ year gap[0] of no softmodding because they'd isolated all the memory protection into a hypervisor. Apple learned the same lesson and iPhone jailbreaking went from incredibly commonplace to "if you know how to do it someone at Zerodium will hand you a million dollars to write spyware with it".
[0] AFAIK, the only two actual softmoddable bugs on Xbox 360 were the King Kong hack right at launch, which got patched in like a week, and that BadUpdate thing last year.
I think the reason to not invest your time in PS5 linux is that sony hates it and will patch it away over and over, and nobody really wants it. It's $200, mediocre hardware.
I might be showing a lot of unc energy here, but if you can't afford a raspberry pi or something to play with linux, or a used pc, gaming and having a playstation 5 should be de prioritized for a bit.
You've misunderstood something deeply. PS5 Linux doesn't exist because running Linux on PS5 is something useful or practical. Exists due to the curiosity and fun of running a free OS on a locked-down device. Maybe some nostalgia mixed in as Linux has existed in every other PS (even PSP/PS Vita).
> I might be showing a lot of unc energy here, but if you can't afford a raspberry pi or something to play with linux, or a used pc, gaming and having a playstation 5 should be de prioritized for a bit while you get your life together.
Your comment is framed as though Linux usage and what you deem an unstable lifestyle (lack of monetary means in your judgment) are mutually exclusive. Open-source software is for everybody, including the messy or disenfranchised. Would you frame a kid who got a PS5 for Christmas who doesn't have an allowance or job as a failure because they don't have $100 to spend on a Pi? It sounds like you just look down on people playing video games even when they want to use the very thing you're implicitly deriding to do the thing that you think they should be doing... doesn't seem to make a lot of sense.
There’s also the other side of the same coin where maintainers ignore your contributions. I’m happily forking things permanently and will likely rewrite them on cleaner foundations. I’ve never loved my tools more than I do now when I can get them coded at the same pace I think of them.
On the other hand, it’s been clear for a while that software as we knew will end up at a close to 0 marginal value.
LLMs have taken over so many projects already. If I were young,
would I want to contribute to projects maintained these days via
AI slop? I would not find that interesting at all.
We've solved this in our FOSS project by requiring all PRs to have been tested and manually signed off by a human. It significantly decreased the amount of spammy LLM made PRs, while empowering the core contributors to move faster.
I've seen kiddies take advantage of homebrew developers to develop game piracy many times, but this is the first time I've seen kiddies do it to fix the exploit for the bug bounty. How the times have changed.
Gatekeeping is a good thing. It's how communities stay healthy and vibrant. Gatekeeping means that when someone shows up to your birdwatching club and says "I hate going outdoors, can we just look at photos of birds from the Internet?", you politely but firmly say "sorry, this isn't the club for you". If you don't do this, then soon enough your club won't be about birdwatching at all, but will be about looking at pictures on the Internet. Same goes for any other community or subculture: it is perfectly okay to say "we aren't changing our standards, and this activity may not be for you".
Of course gatekeeping can also be toxic. But anything can be toxic if applied too much. You can die from water poisoning, that doesn't mean water is bad. It means you need to not overdo it. I've seen what a lack of gatekeeping has done to many communities I used to enjoy (including programming), and I think it's high time we did more gatekeeping. We don't want to overdo it, but right now we are doing far too little and that needs to change.
117 comments
[ 0.21 ms ] story [ 55.7 ms ] threadThe community can now contribute code and solve issues more faster rather than a handful of people gatekeeping slowing down development.
The power of the community is the future.
Everyone hates gatekeeping until they don't. Watch quality go down, issues increase, project direction become muddied, and suddenly people will be calling for more gatekeepers!
https://x.com/theflow0/status/2099987019954831744
Sounds like he is salty that somebody found an exploit using LLM that he found manually (which probably took a significant amount of time.) I can partly understand it, but I mean that's also just the game that somebody else might find an exploit, LLMs just make it easier. LLMs finding bugs is not a bad thing, just sucks for enjoyers of open source software in this particular case.
You can probably find more though.
This guy has used on working with people that understand the scene, it seems that they were in contact, they agreed on something and then the next day they did something different.
This is really important in the context of what happened and probably the cherry on top of the current "hacking" cake, with the bar being lowered so much that anybody can jump in with some minor skill and luck and get something just for themselves.
No, he's salty that this last remaining hypervisor exploit is going to get patched, causing his PS5 Linux project to get wholly-fucked as now there will be no (currently-known) way to sideload the OS. Reading comprehension is very important here.
I can guarantee this post would not have been made had he not been the one to find that vuln first.
Just look at the iOS jailbreaking scene and how Apple repeatedly poached all the devs until there was no one left, killing it off well before LLMs.
But I guess Sony being a gatekeeper wasn't a gatekeeper enough for certain regulatory agencies.
I don’t know if he’s mad AI scooped a bug? Or that LLM slop kiddies don’t pay attention to that something is already known?
Slop kiddies using AI discovered the PS5 hypervisor exploit it relied on for installation. Initially they agreed to his request to delay reporting it to Sony until after GTA6 came out (so users could at least install and enjoy that highly anticipated game). But then they turned around and disclosed it anyway (the same or next day?).
They presumably gained a nominal bounty, but nuked the project he'd poured so much hard work into. Including support for PS5 Pro he was preparing to release next year.
The community used to be a group of talented researchers, but he's frustrated it's diluted into participants who don't even understand the hacks they produce.
> I am stepping away from the ps5 scene and stopping all my work on ps5 linux. After pouring my heart and months of my life into it, including plans to finish ps5 pro support and release in 2027, it's all down the sink.
> The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
> I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.
If one user could have found this using AI. Then I would imagine anyone else could have found it.
Right, including Sony. AI finding security flaws is very good in general, but one downside is that it will become easier to make "secure" devices that are hostile toward their owners.
People are still fixated on using AI to produce code (to reduce salary costs/dev time) rather than using it to audit bugs in one own's code, which they are better at.
The latter has "always" been obvious to me.
It's just boring.
> Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony,” the modder said on social media. “I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy linux. They agreed to wait, but not a day passed and they decided to waste it instead.”
So what has really happened is the LLMs have lowered the participation floor for this space enough the dynamics are changing. The new comers would rather have a few dollars vs. the founders who would rather have a project. It’s likely the projects days were numbered either way because Sony could also just take a frontier LLM would and examine any released installer for the project and reverse engineer and bug.
How old was this bug? How much energy has been devoted to RE of this proprietary console? Not enough, apparently.
This vulnerability will still exist in older versions. The project can still continue development of Linux on PS5 and, eventually, another exploit will be found that enables the installation on a later version.
Frankly, based on the language used, a resignation over this seems to have a lot more to do with the person being upset that LLMs are lowering the bar for entry. They seem more upset that their skills aren't as useful as they were.
It seems like the reputation as a PS5 hacker was the objective, not getting Linux running on PS5.
remember hacktoberfest 2020? that's just all public-facing source 365 days a year now, except instead of "updated README.md" it's some vaguely-plausible fix... then you read the PR body and someone couldn't even be bothered to, or, just as likely couldn't explain it themselves. and that sort of sinking dread sets in.
At first, my brain parsed "spam" as in ye olde email spam. It took a moment for it to sink in that you meant code spam, instead.
But now that the two concepts are linked in my little pea brain: I kind of want to see how a system like SpamAssassin would work when applied to pull requests like it has been applied to email.
It can use reputation, real-time blacklists, triggers for form, and et cetera, with weighted scores for every aspect that are ultimately factored into one final score.
If final score is passing, the PR is presented for a human to review like a PR was (say) 5 years ago. If the final score fails, it goes into the circular file where it will probably die.
I've been on both sides of the spam arms race at different times of my life. While they'll never be able to claim victory, the good guys (usually!) seem to be winning -- and that's a lot better than accepting defeat.
Same thing did happen to many work places. People at all levels proxy questions through LLMs and don't even bother to read/trim/edit the response.
Funny, how suddenly a tight, 1-2 sentence response on point is a sign of skill.
It is insane just how miserable the experience of FOSS hardware hacking in public is.
The expectation does not even the slightest match reality. You'd think "ah yes many eyes meaning all bugs get shallow", but instead you get worst of XDA-Developers and toxic wastelands where no sane person even answers anymore.
But this predates LLMs and was as miserable as it is now before as well.
In fact, I might even argue that LLMs made this _better_, because you can now avoid the "opening up in hopes of finding 1 helpful person below 99 annoying ones" through simple GPU compute.
Previously, you had to hope that through this self-inflicted horror, you'd find an expert that can augment you. Now that expert rests on huggingface.
It's still.. not perfect, of course. But it might be less miserable - provided that you adapt to the current state of things and stop with the "trawling for volunteers".
__
Of course, this does not help you against "skids let claude find bugs that you'd need and burn it for no reason" as per the twitter thread, but I wouldn't rule out that they would not have done that, if less information was public.
And.. that too was an issue before LLMs.
Information wants to be free, but so does your cat, and your cat gets run over by some crackhead in a 30 year old rusty pickup if you just put it outside without thinking.
So don't let it go out unattended.
Complaining about the inevitable toxic noise when the same boneheaded development decisions are made over and over like everyone has gone insane. You don't have to build a death trap on the land your cat and children roam.
Just like humans by their very nature are low quality, since they come from the biology ecosystem, where everything is built atop everything else.
Filthy carbon-based mammals.
I haven’t yet started disabling issues. Let’s hope it doesn’t come to that.
the idea of gatekeeping is often seen as elitist or exclusionary (fairly enough in many cases) but i think this can be an exaggerated description of a culture that necessarily requires a standard of... let's say, desire to engage with material on a sufficiently deep level. many things can be for anybody, but they are not for everybody.
in the past i've seen the phenomenon of "opening up" subcultures or previously-niche intellectual/art fields described as democratization but i think that ignores a big part of what causes this, which can more accurately be described as commodification. access to difficult things was formerly measured by one's ability to expend effort in order to get there (ignoring, for now, the structural conditions that set one up for success in that effort). when these things are commodified, these efforts and identities become products to purchase, the right to which is nearly never limited; in fact, it's almost seen as evil to imply that they should not be available to any individual at any time that individual may desire access.
i know we all have to start somewhere, but there has always been some historical filtration that leads people who are not truly engaged with a subject on a deep level to disengage at some point. that's changing at a novel rate and scale across so many subcultures. it seems like a lot of us are just surprised at how many people even want access to what were once our sanctuaries and we're not capable of grappling with what it takes to adapt to these changes.
i don't think this will pass or that things will return to "the way they were" but there will always be pockets that resemble previous subcultures. we just have to re-learn how to identify them with a keener eye and how to better avoid or more-appropriately interact with those who have a more superficial interest in them.
true, but i think there's historically often been good-faith efforts to engage with newcomers in any field that requires intellectual or artistic curiosity or experimentation. what we're seeing played out is that this default good nature ignores the risk involved in growing a small garden beyond one's own property. there is a change in meta-social requirements at scale.
the extremes of this are super apparent in FOSS - one side of this being death-by-committee and overgovernance at the expense of the original project (requiring a support organization that outgrows the actual "work"), and the other side a harsh rejection of newcomers or calcification against new ideas.
but they're not limited to FOSS. i think these are probably fairly well-studied ideas in any form of organizations - business, social groups, churches, non-profits, unions, etc. i don't really know where to start to learn more about this or what the right approaches are (and i suspect they're often pretty unique to the group in question).
And once in a blue moon something good comes out of it back to the real project.
Cherrypicking the occasional winner is just a side benefit.
The experience in these spaces is largely the same. LLMs can be used there, too, but when the experts are using them with experience to back it up the results are a lot better.
The people who are really struggling in my few hobby groups (not PS5) are those who enjoyed some social status from their knowledge. They were heros and people sought them out and revered their work in 2023. LLMs came along and partially leveled the playing field. When a determined kid with a Deepseek subscription can produce a sloppy version of what took you years to find, that sense of being a heroic figure at the next level is gone.
I think this reveals another wrinkle, which is that the status hierarchy wasn’t that solid or worthwhile anyway. Outside of a few vocal people trying to enforce the status hierarchy, most people don’t care who releases their jailbreak or PS5 exploit. They just want it. Whoever gets it to them first becomes the new king.
This PS5 incident has some strange element where supposedly keeping the reveal secret for 2 more weeks would have changed something with the GTA6 release. There were also 3 people who found the same exploit independent and some large amount of money on the line for the first of them to report it. The person who reported it signed off to spend time with his dying mother, so can’t really fault them for doing the thing they earned according to the rules of the program.
Well it's that GTA 6 comes out in mid-November, so he wanted to wait until then to release the exploit so people could legally run GTA 6 on their hacked PS5s. Disclosing the exploit before the release means that they'll patch it before GTA 6 comes out so this is no longer an option.
I think this is unrelated because it happened after theflow0's statement, but Sony just released a major PS5 update that significantly increases the PS5's security ahead of GTA 6's release. Apparently it's impossible to rip games now without a hypervisor exploit, and since the last one just got reported to Sony this means that even people with hacked PS5s on old firmwares won't be able to pirate GTA 6 since nobody will be able to rip it. https://www.reddit.com/r/PS5_Jailbreak/comments/1wi0gpx/its_...
It's an issue that the dev attempted to collect the bug bounty, AI or no
Not to mention how the code can then be sourced by an AI model in an instant without any credit.
That would indeed be incredibly demoralizing, even crushing. Quite a dick move.
Now that said, I imagine it was only a matter of time anyway until Sony found/fixed or someone else did the same thing. It's just a different world now.
As much as I'd love a non locked down PS5, anyone buying one knows what they're getting. If you care about user empowerment, PC (Valve hardware, etc) is the place to put your money and time. Sony is actively hostile toward you and wants you locked down, and trying to fight it with exploits is destined to be a nasty cat and mouse game. Go with a vendor that is more aligned to your values.
Ever since consoles became moving targets there's been deliberate gatekeeping - specifically, drip-feeding of bugs - to maximize the chance someone can actually use them to break DRM and install Linux. This relies on the fact that most people do not want to have to become FreeBSD kernel experts in order to install non-PlayStation software on their PlayStation. But if everyone is vibe-hacking their PS5s then none of this logic applies. Any bug Claude can find is one Sony also knows about and will get patched, possibly before you even release an exploit for it.
How this ultimately plays out depends on if it's even possible to write software without bugs. Maybe this reaches a new equilibrium where people are paying Claude to vibe-code jailbreaks - as I'd initially hoped. But it's equally as likely that this winds up reinforcing DRM rather than weakening it, for a few reasons:
1. Anthropic's AI safetyism culture encourages the prohibition of vibe-coded jailbreaks. The fact that the model runs on a server and people are spying on your chatlogs means Anthropic has actual knowledge of who is actually using their service to find PS5 hypervisor bugs. Letting Claude break DRM is legally risky; DMCA 1201 implies the only lawful way to break DRM is for you to find your own bugs. So it's probably not going to be long until everyone vibe-coding jailbreaks will get banned.
2. Sony will not be getting banned from these services, they will get trusted access as they're big enough for Anthropic to sue if it gets misused.
3. The attack surface of the thing you have to actually compromise to get code execution on any locked-down system is really small. The Xbox 360 had a 15+ year gap[0] of no softmodding because they'd isolated all the memory protection into a hypervisor. Apple learned the same lesson and iPhone jailbreaking went from incredibly commonplace to "if you know how to do it someone at Zerodium will hand you a million dollars to write spyware with it".
[0] AFAIK, the only two actual softmoddable bugs on Xbox 360 were the King Kong hack right at launch, which got patched in like a week, and that BadUpdate thing last year.
I might be showing a lot of unc energy here, but if you can't afford a raspberry pi or something to play with linux, or a used pc, gaming and having a playstation 5 should be de prioritized for a bit.
Your comment is framed as though Linux usage and what you deem an unstable lifestyle (lack of monetary means in your judgment) are mutually exclusive. Open-source software is for everybody, including the messy or disenfranchised. Would you frame a kid who got a PS5 for Christmas who doesn't have an allowance or job as a failure because they don't have $100 to spend on a Pi? It sounds like you just look down on people playing video games even when they want to use the very thing you're implicitly deriding to do the thing that you think they should be doing... doesn't seem to make a lot of sense.
On the other hand, it’s been clear for a while that software as we knew will end up at a close to 0 marginal value.
Hopefully "people" doesn't mean scrapers
AI skynet is currently winning the war.
LLMs have taken over so many projects already. If I were young, would I want to contribute to projects maintained these days via AI slop? I would not find that interesting at all.
Of course gatekeeping can also be toxic. But anything can be toxic if applied too much. You can die from water poisoning, that doesn't mean water is bad. It means you need to not overdo it. I've seen what a lack of gatekeeping has done to many communities I used to enjoy (including programming), and I think it's high time we did more gatekeeping. We don't want to overdo it, but right now we are doing far too little and that needs to change.