Several vulnerabilities have been discovered in the Linux kernel
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Several vulnerabilities have been discovered in the Linux kernel
Unofficial Hacker News client; not affiliated with Y Combinator.
Fordec · · focus · HN ↗
But, does that all of these being found now call into question, not the open source model logic itself, but the ability of human eyes to find security issues? These vulnerabilities have been sitting here for however long, but how many thousands of humans did not find them before AI?
SchemaLoad · · focus · HN ↗
1over137 · · focus · HN ↗
SchemaLoad · · focus · HN ↗
zakisaad · · focus · HN ↗
catlifeonmars · · focus · HN ↗
wat10000 · · focus · HN ↗
marcus_holmes · · focus · HN ↗
Like everything in CS, apparently this is a trade-off, not an absolute. You can get bug-free code, but it's not commercially viable and is extremely tedious to do.
kccqzy · · focus · HN ↗
<a href="https://www.eng.auburn.edu/~kchang/comp6710/readings/They%20Write%20the%20Right%20Stuff.pdf" rel="nofollow">https://www.eng.auburn.edu/~kchang/comp6710/readings/They%20...
anal_reactor · · focus · HN ↗
When asked, people prefer €15 burger no tip, but when actually making a choice, they prefer €10 burger with €5 tip. Similarly, companies state "bug-free code" as a goal or requirement, but then they prioritize other goals over code correctness. My workplace is in the process of completely removing code reviews. And actually, I don't disagree with the decision - my career is short, but I have never seen reviews fulfill any purpose other than to share the blame in case of an incident.
cindyllm · · focus · HN ↗
[dead]
brabel · · focus · HN ↗
0c3ca83 · · focus · HN ↗
It's incredibly problematic for many reasons, but it finds bugs in C really well.
spoaceman7777 · · focus · HN ↗
For Linux, the threshold is nearer to the point of it being questionable whether a bug is even exploitable on a real production distro, compiled and run with any sort of sane configuration.
hn_submit · · focus · HN ↗
NoPicklez · · focus · HN ↗
Also there are likely a lot of vulnerabilities identified but the work required to fix them vs the complexity to exploit them means they don't get fixed.
I'd wager we don't have an issue with identifying vulnerabilities but the ability to fix them.
I work in security consulting and identifying vulnerabilities isn't the difficult part its actually fixing them and fixing the ones that have valid exploitable attack chains that matter