top 50 comments

sorted by: hot top controversial new old
[–] 79 points 1 month ago (38 children)

Responsible use of llms can't be achieved. Can you verify that all of your training data are square with its creators? If not, how is that responsible?

  • source
  • hideshow 38 child comments
  • [–] 32 points 1 month ago (2 children)

    Can you verify that it didn't reproduce any code that's proprietary or has more restrictive licenses than your own?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 11 points 1 month ago (5 children)

    It can if you control the training data, or if the data is public domain.

    But I get your point. You can say all the Diamonds you use are conflict free, but out of the thousands you have, how do you know some have not slipped in.

    At what point do you say you did a good enough job, and at what point is it too contaminated?

    Like many things, it difficult to draw a line, so its up to communities to set a reasonable standard.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (3 replies)
  • [–] 5 points 1 month ago (23 children)

    Code should've never been copyrightable from the start. It's basically the compute equivalent of a recipe. That aside, almost all modern transformer models are trained on generated data by this point, how would we even apply traditional copyright to that? Whole thing needs tossed and retooled. Entire economic system with it tbh, just slows innovation, and despite what you might believe it doesn't protect the little guy, it just allows massive corporate conglomerates to buy up everything and control for what will be pretty much the extent of your lifetime.

  • source
  • parent
  • hideshow 23 child comments
  • load more comments (23 replies)
  • load more comments (5 replies)
    [–] 48 points 1 month ago (6 children)

    In a nutshell, it looks like AI disclosures are encouraged, but not required, and AI usage is encouraged to be human reviewed, but not required. They have also stated they will not allow the use of online AI services for security reasons (but how this will be enforced I'm not sure, since they are relying on the judgement of contributors)

  • source
  • hideshow 6 child comments
  • load more comments (6 replies)
    [–] 47 points 1 month ago (7 children)

    The only question I have is why. Genuinely.

    Debian exists. It has existed for decades. It works. "Oh but AI makes it faster" so fucking what? We didn't need "faster" for years whilst it worked fine, it's not a product on a deadline.

  • source
  • hideshow 7 child comments
  • [–] 7 points 1 month ago (2 children)

    No community distro has the capacity to fork thousands of packages and maintain them. That's what a true no Ai policy would require. I also have to add that the Linux kernel itself would need to be forked and then maintained. Just the latter point alone is enough to make all this moot.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (1 reply)
  • [–] 37 points 1 month ago* (last edited 1 month ago)

    At first I was afraid that they would allow for an irresponsible use. But no, they explicitly say "responsible", so that danger is no more. I'm very much relieved.

    Also they explicitly mention that humans will remain accountable. Not Nature, or Fate, or the gods; mark that. Good thinking there!

    Problems solved.

  • source
  • [–] 29 points 1 month ago

    This is good news; Debian is still the way to go for me:

    Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material. The Project does not seek to resolve these unsettled legal questions through this General Resolution, nor does it adopt a position on whether AI-generated output is, in whole or in part, copyrightable or derived from copyrighted works.

  • source
  • [–] 24 points 1 month ago* (last edited 1 month ago)

    They basically pass the buck to the individual developer without taking any responsibility themselves.

    Debian acknowledges that the legal status of material produced by generative AI systems remains the subject of ongoing discussion in many jurisdictions, including questions relating to copyright, authorship, licensing, and potential reproduction of training material.

    The responsibility for every contribution rests with the contributor who submits it, who remains accountable for its technical quality, legal acceptability, and suitability for inclusion in Debian.

    "It may be illegal or against FOSS, but that's up to you to decide, good luck I guess"

  • source
  • [–] 15 points 1 month ago (14 children)

    Yikes, rest in peace Deb users. I just hope it never happens to my distro.

  • source
  • hideshow 14 child comments
  • [–] 21 points 1 month ago (6 children)

    I ain't shook up about it. There's not really a surefire way to detect tool-assisted code gen anyway, so IMO the acceptance criteria should be the same as it's always been, tool-assisted or otherwise. Which is ultimately the path they chose to take.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 7 points 1 month ago (5 children)

    Obvious slop should be immediate permanently banworthy, sloppers can just keep burning new accounts (as long as they have access to new IP addresses) while real developers deserving of praise and reputation thrive.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 22 points 1 month ago

    sloppers can just keep burning new accounts (as long as they have access to new IP addresses) while real developers deserving of praise and reputation thrive.

    Becoming a Debian developer requires you to meet an existing Debian developer in person and have your public key signed by them. It's not possible to keep burning new accounts unless you go and meet a different Debian developer each time and there's a limited number of them in each region and they usually meet together, so more than one person will see your face.

  • source
  • parent
  • [–] 7 points 1 month ago (3 children)

    Yep. I'm not familiar with Debian's strategy specifically, but generally, I think any new contributor to a project should be subject to heightened scrutiny. My policy is that new contributors should start small and develop a rapport with the maintainers before submitting more ambitious (and for the maintainers, more costly to review) large and/or critical path PRs. It was a good policy before LLMs and I think it remains a pretty robust method of weeding out irresponsible devs without wasting a ton of maintainer time. There are simply more slop PRs to reject sight unseen these days, which is admittedly very annoying, but the process is much the same as it's always been.

    I'll admit I don't maintain any projects anywhere near the popularity or volume of the Debian project, so I'm not really sure what the view is from their vantage point.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 5 points 1 month ago* (2 children)

    I still think that's not good enough, that treating them fairly is a stupid waste of time and resources and unfair to everyone else.

    Just make the rule "any slop" and give the idiots a checkbox so they can ban themselves for reasons which will never be revealed to them (sloppers don't read documents, it'll take them a while to figure out). Also start banning people when evidence surfaces of them admitting to slopping.

    I don't like this concept that a slopper can potentially produce decent code, the data shows this simply isn't true: sloppers produce vast amounts more and worse bugs and vulnerabilities. It's better for the health of the project to ban it in every scenario.

  • source
  • parent
  • hideshow 2 child comments
  • load more comments (2 replies)
  • load more comments (1 reply)
    [–] 15 points 1 month ago

    i'm actually a little surprised, given their history about being so hardcore about dfsg compliance.

  • source
  • [–] 10 points 1 month ago (5 children)

    This email from 2016 by jwz springs to mind.

    I guess you want Debian to be the kind of operation that uses the work of others while blatantly and explicitly ignoring the wishes of the person who did the actual creative work.

    I am increasingly of the opinion that all software developers and adjacent people are fucking scum unless proven otherwise.

  • source
  • hideshow 5 child comments
  • [–] 9 points 1 month ago

    As long as they don't allow AI bots to submit changes, this is probably a realistic decision. Assuming that code generated by AI is never going to be copyrighted by the AI companies. In light of this uncertainty I don't understand why they don't require AI code to be flagged as such. That bit seems like a really bad idea, legally speaking.

  • source
  • [–] 9 points 1 month ago
    [–] 9 points 1 month ago (2 children)

    There is no such thing as "responsible use of GenAI". That said, I understand the decision in the face of even Linus Torvalds allowing AI-generated code into the kernel. If Debian would have banned AI code entirely they would have had to fork every single thing they include in their distro, wipe the AI code from it, and then work to develop it further themselves. It would be too gargantuan a task.

  • source
  • hideshow 2 child comments
  • load more comments (1 reply)
    [–] 5 points 1 month ago (4 children)

    Dammit. Need to find a new OS.

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [–] 4 points 1 month ago

    I love Debian. An ol' rock ballad from the 90s

  • source
  • load more comments
    view more: next ›