‹ BackHN Continuity

Thread

Several vulnerabilities have been discovered in the Linux kernel

576 points · 408 comments · luispa

  1. boutell · · focus · HN ↗
    I head a much, much smaller open source project. Since the November Singularity we've been seeing at least six responsibly reported security advisories a month. However, this last month we had 22 unique security advisories. Our project has been built with adherence to the OWASP Top Ten Guidelines and other best practices from the beginning. But software is hard and AI is thorough.

    Each month, we fix them all in our monthly maintenance release and disclose at that time. We fight AI fire with fire, and hand-review, of course.

    So far, we can keep up. One hopes this is possible at the scale of the Linux project, which assuredly has more humans and more AI to throw at the problem. But team size does not scale linearly with interested audience, and potential bugs do scale with codebase size (and other extremely important factors, like code quality, at which the Linux team is assuredly much better than we are).

    ("November Singularity" is a cheeky reference to the arrival of Opus 4.5 and "good enough" coding models and harnesses generally.)

    1. jasondigitized · · focus · HN ↗
      Seems to me we need tooling to do automatic offensive security as soon as a new frontier model comes out, with quickly turned around patches using the same frontier model. Rinse and repeat. Virtuous agentic security loop.
      1. roosterIllusi0n · · focus · HN ↗
        Isn't that part of the cloud AI business model now? Businesses have to pay for early access so they can weed out any new bugs before the model goes public. Which is kind of crazy, because you are paying for early access to protect yourself from other paying customers of the same cloud AI model.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.