‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. boutell · · focus · HN ↗
    I head a much, much smaller open source project. Since the November Singularity we've been seeing at least six responsibly reported security advisories a month. However, this last month we had 22 unique security advisories. Our project has been built with adherence to the OWASP Top Ten Guidelines and other best practices from the beginning. But software is hard and AI is thorough.

    Each month, we fix them all in our monthly maintenance release and disclose at that time. We fight AI fire with fire, and hand-review, of course.

    So far, we can keep up. One hopes this is possible at the scale of the Linux project, which assuredly has more humans and more AI to throw at the problem. But team size does not scale linearly with interested audience, and potential bugs do scale with codebase size (and other extremely important factors, like code quality, at which the Linux team is assuredly much better than we are).

    ("November Singularity" is a cheeky reference to the arrival of Opus 4.5 and "good enough" coding models and harnesses generally.)

    1. jrflo · · focus · HN ↗
      I like the November Singularity, I hope that catches on. That was definitely the point where I went from "AI is overhyped" to "oh shit the hype bros may be on to something"
      1. ACS_Solver · · focus · HN ↗
        Yes, good name and I also feel that was a major inflection point. Up until then I found all AI models to be terrible at programming, with the difference between GPT o3, Sonnet 4 and every other model since GPT-3 being just the exact flavor of terrible they were.

        November 2025, with Opus 4.5, was the first time I was impressed by an LLM doing something non-trivial with a reasonably good level of quality.

        1. boutell · · focus · HN ↗
          Yes, and Qwen 3.8 27b is a similar inflection point for local, although I wouldn't claim it's quite as good as Opus 4.5 it is genuinely useful. Whether that actually matters will depend on whether it ever becomes the most cost-effective tool for the job, but it's impressive as all heck
          1. KiwiJohnno · · focus · HN ↗
            Yeah before Qwen 3.8 27b all local LLMs did feel like not very smart chat completion models. You would hit the limits of their intelligence all the time. Chatting with Qwen 3.8 is night and day, and it can do some pretty damn good coding and agentic work for its size. IMO its better than where frontier labs were at about 18 months ago, which is mind-blowing for a small locally hosted model.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.