‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. boutell · · focus · HN ↗
    I head a much, much smaller open source project. Since the November Singularity we've been seeing at least six responsibly reported security advisories a month. However, this last month we had 22 unique security advisories. Our project has been built with adherence to the OWASP Top Ten Guidelines and other best practices from the beginning. But software is hard and AI is thorough.

    Each month, we fix them all in our monthly maintenance release and disclose at that time. We fight AI fire with fire, and hand-review, of course.

    So far, we can keep up. One hopes this is possible at the scale of the Linux project, which assuredly has more humans and more AI to throw at the problem. But team size does not scale linearly with interested audience, and potential bugs do scale with codebase size (and other extremely important factors, like code quality, at which the Linux team is assuredly much better than we are).

    ("November Singularity" is a cheeky reference to the arrival of Opus 4.5 and "good enough" coding models and harnesses generally.)

    1. sparklingmango · · focus · HN ↗
      I too use November 2025 as a true turning point.
      1. soulofmischief · · focus · HN ↗
        It was. That's when I stopped coding most things by hand. The difference in what I could reliably get AI to do for me in February 2025 vs February 2026 is just massive. I immediately became a huge advocate amongst my peers for going all-in on automated engineering because this curve is about to get very steep and if you're not staying ahead, you might get left behind.
        1. gamerdonkey · · focus · HN ↗
          I'm genuinely curious: if the trend is toward "AI accomplishes my goals more easily than in the past", what curve are you "staying ahead" of?

          Why isn't even easier for an AI noob to jump in at the next step with less friction than the current one?

          1. Roark66 · · focus · HN ↗
            It requires skill to prompt the AI to do best possible work. I have senior colleagues that produce horrible slop and others that always produce great results. Managing the context, knowing when to stop the AI. Knowing what to question, what to "trust" in is a big deal.

            Also knowing what models are good for what. There was time half a year ago when Google genuinely had a better model than everyone else. I used it for everything and 3 weeks later they lobotomise it (sorry "optimised") and I went back to opus...

            I think Anthropic is like a drug dealer, giving us the sweet sweet drug for free (I don't think our $200 a month subscriptions even cover the electricity for our use) and the time to pay will come very soon...

            I expect this subscription will cost $2k a month. Will it be a normal increase? Or will the "enshittify" existing models to the point you'll pay $2k to get fable 6 to do what opus 4.8 did fine in July 2026?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.