‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. usernomdeguerre · · focus · HN ↗
    Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

    From his Kernel Recipes 2026 slide on Mythos

    ```

      Mythos's 79 vulnerabilities:
      24 - no detail at all "something crashed"
      14 - not a bug at all
      3 - totally made up data
      15 - already fixed in latest release
        - 11 by others
        - 4 by anthropic
      20 - fixes were needed
        - 7 "assume a malicious filesystem image"
        - 2 "assume you can inject a malicious network packet into the middle of the stack"
        - 2 "NOMMU"
        - 6 sctp networking issues for untrusted devices
        - 2 ipv6 minor network issues 
        - 1 gpu driver for local malicious user
    
    ```

    GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

    1. saidnooneever · · focus · HN ↗
      people have different opinions of what Risk is. hence greg doesnt recognise certain things as risks that others do. That bein said most of those others wouldnt run Linux, and for sure 100% a shoe salesmen will try to sell you their shoes whatever the quality. They will also defend their price and quality whatever the quality though so that knife cuts both ways and on either end its consumer that gets cut
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.