‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. Fordec · · focus · HN ↗
    This is great, more access did provide more eyes on these problems.

    But, does that all of these being found now call into question, not the open source model logic itself, but the ability of human eyes to find security issues? These vulnerabilities have been sitting here for however long, but how many thousands of humans did not find them before AI?

    1. SchemaLoad · · focus · HN ↗
      Even before AI we have known that no one is smart enough to write bug free C. And with every bug being a launch platform for a full exploit it's become a big deal.
      1. 1over137 · · focus · HN ↗
        No one is smart enough to write bug free in any language.
        1. marcus_holmes · · focus · HN ↗
          I can't find it now, but I heard that NASA developed processes to produce completely error-free code (for the moon landings iirc). The problem is that it's incredibly time consuming and expensive to do.

          Like everything in CS, apparently this is a trade-off, not an absolute. You can get bug-free code, but it's not commercially viable and is extremely tedious to do.

          1. kccqzy · · focus · HN ↗
            It’s probably about how they write the space shuttle software, and it’s quite a famous article. The original is now paywalled but there are many copies.

            <a href="https:&#x2F;&#x2F;www.eng.auburn.edu&#x2F;~kchang&#x2F;comp6710&#x2F;readings&#x2F;They%20Write%20the%20Right%20Stuff.pdf" rel="nofollow">https:&#x2F;&#x2F;www.eng.auburn.edu&#x2F;~kchang&#x2F;comp6710&#x2F;readings&#x2F;They%20...

            1. anal_reactor · · focus · HN ↗
              This is example of what I call &quot;the tipping paradox&quot;, and I&#x27;m almost sure that this phenomenon has its own proper scientific name.

              When asked, people prefer €15 burger no tip, but when actually making a choice, they prefer €10 burger with €5 tip. Similarly, companies state &quot;bug-free code&quot; as a goal or requirement, but then they prioritize other goals over code correctness. My workplace is in the process of completely removing code reviews. And actually, I don&#x27;t disagree with the decision - my career is short, but I have never seen reviews fulfill any purpose other than to share the blame in case of an incident.

              1. cindyllm · · focus · HN ↗

                [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.