A senior security researcher critiques 1Password Off-by-1 Labs’ FLAWED report as sloppy, misleading, and harmful to the research ecosystem. The piece documents concrete problems - incorrect diagrams, arithmetic and textual inconsistencies, and a tiny, mostly corporate citation set (19 citations) that omits obvious prior work such as PatchBench and Meta’s AutoPatchBench and a relevant NDSS paper on LLM security pitfalls. It also flags factual misattribution around Patch the Planet contributors and questions the ratio of human to AI involvement. Those defects mattered because the report received wide distribution, influenced press and defender roadmaps, and crowded out more rigorous, less-resourced academic and open-source work.
The core argument is that industry teams cannot adopt the trappings of scholarly research without meeting its norms: full literature engagement, transparent public records, community review, and public corrections or retractions when warranted. The report misused “peer review,” was not posted to scholarly repositories, and issued an update that failed to address substantive rebuttals. That pattern creates a vulnerability where well-promoted but weak work can distort policy and practice; the remedy urged is stronger enforcement of research norms, collaboration with academics, and amplification of rigorous independent work to protect the integrity of AI security research.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.