‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. blinkingled · · focus · HN ↗
    It's great to hear about $topic from someone no-nonsense and in-the-know like Greg KH. You can verify all of this too - since, well Linux kernel. (As opposed to what Microsoft or Apple claims to fix as far as LLM finds.)

    Mythos may not be great today but it is not far fetched to imagine bug discovery, analysis and fixes can be made much quicker, accurate and even newly possible with specialized models trained on say Linux kernel specifics - with codemap/coding standards/threat models, good and bad coding patterns, tools to validate etc. an LLM can be much more relentless than humans and if it has the help to be accurate it will be worth the electricity burned. Oh and another model trained on triage data to validate the first one's findings would be good.

    (I think Microsoft is doing this internally - different models trained internally alongside Mythos - there was some talk about it on the tubes, don't recall where exactly.)

    1. stonogo · · focus · HN ↗
      His presentation style may be no-nonsense, but the content is brimming with nonsense. I would like to hear Greg Kroah-Hartman explain how the Mythos output was 'only 10 real bugs' but there were simultaneously over 1300 CVEs issued last month. It seems not much counts as a 'real bug' when an LLM comes up with it, but when it's time to bully distros into shipping an LTS release, anything goes?
      1. Iknowsheknows · · focus · HN ↗
        Every bugfix is assigned a CVE.

        "the CVE assignment team is overly cautious and assign CVE numbers to any bugfix that they identify. This explains the seemingly large number of CVEs that are issued by the Linux kernel team."

        <a href="https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html" rel="nofollow">https:&#x2F;&#x2F;docs.kernel.org&#x2F;process&#x2F;cve.html

      2. rcxdude · · focus · HN ↗
        What he means is that the headline-grabbing mythos output amounted to 10 actual bugs out of 79^H6 (and all of those got CVEs because that&#x27;s how linux does it). The other 1300 CVEs came from other sources (the big increase likely being everyone else running LLMs through the codebase and filtering through the false positives). The Mythos output is mainly meant as an example of how even the top-tier models still have a high false-positive rate and that can be pretty tiring to deal with.

        I do think he repeats some myths in the video, or at least confidently states some things that are not demonstrated to be true, but his core point of &#x27;you still gotta check these things&#x27; seems pretty solid.

        1. blinkingled · · focus · HN ↗
          &gt; he repeats some myths in the video, or at least confidently states some things that are not demonstrated to be true

          I am genuinely curious what the myths&#x2F;unproven things he states - I watched the video and it&#x27;s repetitive sure but not much felt controversial to me.

      3. blinkingled · · focus · HN ↗
        Fair point, but he was talking about Mythos in particular and the point wasn&#x27;t so much that LLMs will always have false positives rather he was saying they are causing a lot of them right now and how to deal with it.

        Also as other replies said Linux kernel process is to assign CVE to everything - some of them may be just DDOSes, very hard to exploit and everything in between. All of them are bugs so they all get fixed and it&#x27;s not a bad thing if distros ship those fixes and people update their kernel.

    2. simoncion · · focus · HN ↗
      &gt; Mythos may not be great today but it is not far fetched to imagine...

      I...

      Look. Mythos was hyped up as the absolute best bug hunting tool ever made... no software was safe from its awesome bug-finding and exploit-writing capabilities. So strong was it that access _had_ to be limited to a select few pre-vetted entities, lest these awesome capabilities fall into the hands of Evildoers(!!!). Mythos&#x27; claimed capabilities were absolutely an important part of the &quot;The LLM-based tools we&#x27;re building are so dangerous that we must have new laws made to regulate us, or else all of humanity is likely to die!&quot; story that the major LLM manufacturers have been building for a while and are telling now.

      Now? Not even six months after release? &quot;Well, yeah, okay, it&#x27;s actually not that great. But imagine how great the next one could be!&quot;... which is the story I&#x27;ve been hearing roughly every six months for what feels like five years now.

      As an aside: I often wish we lived in a world where it was illegal for companies to use hype or any other types of emotional manipulation when advertising (or otherwise speaking in an official capacity) about tools that are to be used in a professional setting. Is it anything other than a bare statement of verifiable facts? Big fines, and repeat offenders get jail time. I know it&#x27;s never going to happen, but it sure would be nice.

      1. blinkingled · · focus · HN ↗
        Just for the &#x27;record&#x27; - I am totally with you on the hype and just in general the normalization of sleazy behavior surrounding it but I&#x27;m not sure we as normal people have any say anymore including where our money is going to be invested.
        1. simoncion · · focus · HN ↗
          &gt; I&#x27;m not sure we as normal people have any say anymore [in regards to] where our money is going to be invested.

          Unless that was your money being invested, and it was a substantial fraction of the total pool of money being invested, was there ever a time when &quot;normal people&quot; had a real say in where the money was being invested?

          AFAIK, the only thing &quot;normal people&quot; can do is vote with their &quot;feet&quot; and pick a different prepackaged investment product, different investment company, or take their money and do the investment themselves.

          Honestly, this comment of yours seems a non-sequitur and doesn&#x27;t really address anything I said... you don&#x27;t have the power to bend investment firms to your whim, but that doesn&#x27;t mean that you need to -knowingly or not- carry water for the major LLM manufactures by perpetuating the &quot;But think of how great the tools will be in the future!&quot; meme. It has been years now, and everyone who has been paying attention can say with confidence that the LLM-based tools of the future are never that great... they&#x27;re often not useless, but they&#x27;re not worth the billions of dollars that have been and continue to be poured into their manufacture.

          Related to your &quot;We little people don&#x27;t have any power anymore!&quot; commentary, I note that TFA mentions that the kernel community has found that these LLM-based bug-finding tools have a false positive rate of ~50%. TFA goes on to mention that Coverity spent a huge number of years trying so hard to get people to buy its automated scanning software that had only a 20% false positive rate, and could not get enough people to buy the software.

          Coverity went under because everyone hated how stupid and annoying the tooling was... at a 20% false positive rate. Once the hype machine starts slowing down, no one working at the coal face is going to buy a tool with a 50% false-positive rate. I personally very strongly believe that even if the tools had a 10% false positive rate, no one would pay the actual price that OpenAI and&#x2F;or Anthropic would have to charge to recoup the research and manufacturing costs of a cutting-edge LLM-based bug-finding tool.

          1. blinkingled · · focus · HN ↗
            Even after acknowledging that LLMs are fuzzy matchers and have been hyped, I am in the camp that rationally believes they will get better at some things including hunting bugs &#x2F; chasing security vulnerabilities - my point also is that you and me can do whatever we can but on the grand societal scale we are not going to make a difference as far as slowing LLM adoption down - it just makes sense for some things and there&#x27;s a lot of people with time and money that will make it do the rest - that&#x27;s how it works until everything is saturated in the market.

            So no I have no way to address anything you said - that was the point, I don&#x27;t believe you can - not with regulation and not with voting with your money (I am sure some people tried to vote with their money to slow down mega stores and keep the mom and pop shop alive - there maybe some of those still there, but largely it&#x27;s big chains occupying most of the market) - that stuff hasn&#x27;t worked - heck LLMs work better today that that stuff has ever.

            1. simoncion · · focus · HN ↗
              &gt; So no I have no way to address anything you said...

              No, you do.

              1) Refuse to spread the &quot;Well, okay, the tools aren&#x27;t good now, but imagine how good they could be in the future!&quot; meme. And -because these tools are SAAS and the resources allocated to them can be adjusted at any time without warning- evaluate the tools soberly and dispassionately three to six months after release, and ignore 100% of what the manufacturer claims the tools do.

              2) Remind people that the major LLM manufacturers have pretty much never not lied about the capabilities of the tools that they produce and sell. Remind folks that the rational thing to do is to ignore the claims of both the manufacturers and boosters and -given that the tools are deliberately designed to aggressively flatter [0] the operator- to evaluate one&#x27;s interactions with these tools with a huge serving of skepticism.

              I get that you feel like there&#x27;s nothing you can do to change things. But -as I&#x27;ve repeatedly said- you can stop carrying water for these companies by repeating their propaganda.

              Assuming that the regulatory-capture and retroactive-immunity [1] gambit the major LLM manufacturers are currently attempting fails, when the fucknormously huge bill for the tools and the fact that so many GPUs are sitting in storage become public knowledge, things will sort themselves out pretty quickly. I&#x27;m fairly certain that continued progression of the -IDK- ten or twenty+ lawsuits against the major LLM manufacturers for the crimes they&#x27;ve committed over the years will help push that process along.

              [0] ...I think kids these days call this &quot;glazing&quot;...

              [1] ...don&#x27;t believe that Congress would retroactively make obviously illegal conduct legal thereby mooting all in-progress lawsuits seeking justice for that obviously illegal conduct? Go read up on the FISA Amendments Act of 2008.

        2. rglover · · focus · HN ↗
          Don&#x27;t lower yourself like this. The people working on this are &quot;normal people&quot; too. Don&#x27;t put them on a pedestal. That&#x27;s part of the problem here: lionizing people who are actively lying to others to protect their bags and reputation. Stop acting like a pawn for these people. Buying into their delusions of grandeur is what&#x27;s perpetuating this mess. LLMs are a tool, not a monolith.
          1. blinkingled · · focus · HN ↗
            I am not lowering myself or lionizing anyone - I am being practical about this. If we as a society have a workable stance for&#x2F;against LLMs that is beneficial to all of us I am very open to hearing about it - It would however be fair to say that I am pessimistic given a lot of our collective history. And on oop of that nobody seems to be talking about any real solutions either this time around. Just being dismissive or being all-in are equally bad approaches.
            1. simoncion · · focus · HN ↗
              &gt; ...nobody seems to be talking about any real solutions...

              I guess you didn&#x27;t bother to watch the video that is TFA. Greg K-H mentions that if you&#x27;re going to use LLMs to do bug-finding, you should use open-weights models that run locally and &quot;harnesses&quot; built by members of the community You really should watch the video to hear his reasons for why.

              There&#x27;s nothing wrong with LLM-the-technology. There&#x27;s everything wrong with the major LLM manufacturers.

              1. blinkingled · · focus · HN ↗
                I wasn&#x27;t talking about fixing the tools or using open weight models - I don&#x27;t need to watch anything to know that&#x27;s an option. You are also now contradicting your earlier stance somewhat by saying what I was saying - LLMs can and will get better - you have now introduced an irrelevant open vs close element which doesn&#x27;t really matter. There&#x27;s no way only open weight models and harnesses get better - if you understand even a little, proprietary models with access to same open information but with billions to burn on research and hardware will get better faster.
                1. simoncion · · focus · HN ↗
                  &gt; You are also now contradicting your earlier stance somewhat...

                  Not even a little bit, no. Go back and read carefully. [0][1][2][3]

                  [0] &lt;<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49943382">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49943382&gt;

                  [1] &lt;<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49944036">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49944036&gt;

                  [2] &lt;<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49951289">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49951289&gt;

                  [3] &lt;<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49951466">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49951466&gt;

                  1. blinkingled · · focus · HN ↗
                    Ugh stop posting links dude - answer what do you mean by your previous claim for fixing everything you were complaining about earlier - &quot;you should use open-weights models that run locally and &quot;harnesses&quot; built by members of the community&quot; - like how is that not contradicting what you are saying - if open weights and local harnesses can do it Anthropic and OpenAI will do it faster and better. That doesn&#x27;t make sense at all in this conversation.
                    1. simoncion · · focus · HN ↗
                      &gt; ...like how is that not contradicting what you are saying...

                      A careful and honest reader notes that I&#x27;ve never claimed or suggested that there exists a software project that will never get better with enough time and appropriately-focused effort.

                      But, the single thing in this thread that statement by GK-H addresses is your claim [0] that

                        ...nobody seems to be talking about any real [alternatives to using LLMs provided by the major LLM manufacturers]...
                      
                      Of the things I&#x27;ve talked about in this thread, that&#x27;s the least important one. However, I do understand that it is the easiest one for you to talk about while still staying vaguely &quot;on message&quot;.

                      [0] &lt;<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49948725">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49948725&gt;

      2. 20k · · focus · HN ↗
        Every 6 months without exception people claim that the new generation of tools is absolutely incredible, and the old ones were total garbage, and that you only think they&#x27;re crap if you were using the old tools. This just gets repeatedly memory holed again and again, and we&#x27;re expected to always uncritically buy into the idea that they&#x27;re actually good now against all evidence from the real world
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.