‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. usernomdeguerre · · focus · HN ↗
    Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

    From his Kernel Recipes 2026 slide on Mythos

    ```

      Mythos's 79 vulnerabilities:
      24 - no detail at all "something crashed"
      14 - not a bug at all
      3 - totally made up data
      15 - already fixed in latest release
        - 11 by others
        - 4 by anthropic
      20 - fixes were needed
        - 7 "assume a malicious filesystem image"
        - 2 "assume you can inject a malicious network packet into the middle of the stack"
        - 2 "NOMMU"
        - 6 sctp networking issues for untrusted devices
        - 2 ipv6 minor network issues 
        - 1 gpu driver for local malicious user
    
    ```

    GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

    1. catdog · · focus · HN ↗
      Related: <a href="https:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2026&#x2F;05&#x2F;11&#x2F;mythos-finds-a-curl-vulnerability&#x2F;" rel="nofollow">https:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2026&#x2F;05&#x2F;11&#x2F;mythos-finds-a-curl-v...

      Mythos turned out to be exactly the marketing stunt it smelled like.

      There are others like AISLE who seem to be a bit more successful in finding actual issues using LLMs in some shape or form though, whatever they do differently. Chances are high the secret sauce is not so much about the model being exceptionally powerful which would be bad news for the frontier labs.

      1. duttish · · focus · HN ↗
        <a href="https:&#x2F;&#x2F;aisle.com&#x2F;blog&#x2F;system-over-model-zero-day-discovery-at-the-jagged-frontier" rel="nofollow">https:&#x2F;&#x2F;aisle.com&#x2F;blog&#x2F;system-over-model-zero-day-discovery-...

        My understanding: Many many small models in a custom system rather than the biggest and latest

        1. goobreee · · focus · HN ↗
          here <a href="https:&#x2F;&#x2F;stanislavfort.substack.com&#x2F;p&#x2F;mythos-at-home-and-its-called-aisle" rel="nofollow">https:&#x2F;&#x2F;stanislavfort.substack.com&#x2F;p&#x2F;mythos-at-home-and-its-... they say &quot;we match and beat Mythos, in some cases even using models you can run on your own hardware&quot;, so they seem to be using small models at least in some cases
      2. internet_points · · focus · HN ↗
        well of course, it has no model number:

        <a href="https:&#x2F;&#x2F;files.mastodon.social&#x2F;cache&#x2F;media_attachments&#x2F;files&#x2F;117&#x2F;371&#x2F;826&#x2F;895&#x2F;212&#x2F;456&#x2F;original&#x2F;96ce1f4bfe103ee4.jpeg" rel="nofollow">https:&#x2F;&#x2F;files.mastodon.social&#x2F;cache&#x2F;media_attachments&#x2F;files&#x2F;...

      3. Faaak · · focus · HN ↗
        Funnily enough, &quot;mythos&quot; in french is slang for compulsive liar
      4. wslh · · focus · HN ↗
        I think Daniel is giving a more balanced view with:

        &gt; Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools. Mythos will, and so will many of the others.

        Greg&#x27;s video is a good reality check on the hype. But I&#x27;d be careful about generalizing from Linux, libcurl, etc which get far more scrutiny than software projects in general. LLM-assisted bug finding still matter a lot for everyday custom and less popular software.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.