‹ BackHN Continuity

Thread

Greg Kroah-Hartman – Security in the LLM Age [video]

337 points · 128 comments · usernomdeguerre

  1. usernomdeguerre · · focus · HN ↗
    Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

    From his Kernel Recipes 2026 slide on Mythos

    ```

      Mythos's 79 vulnerabilities:
      24 - no detail at all "something crashed"
      14 - not a bug at all
      3 - totally made up data
      15 - already fixed in latest release
        - 11 by others
        - 4 by anthropic
      20 - fixes were needed
        - 7 "assume a malicious filesystem image"
        - 2 "assume you can inject a malicious network packet into the middle of the stack"
        - 2 "NOMMU"
        - 6 sctp networking issues for untrusted devices
        - 2 ipv6 minor network issues 
        - 1 gpu driver for local malicious user
    
    ```

    GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

    1. keeda · · focus · HN ↗
      And I suppose large companies like Microsoft, Google, Adobe, Apple (very famously sitting out the AI bubble) and Mozilla have been shipping record number of vulnerability fixes in their patches just because of the hype machine? ;-)
      1. crote · · focus · HN ↗
        All of them are heavily invested in AI, and just because a change was merged doesn't mean it closed an actual vulnerability.

        Let's say you work at a big tech company. Some rockstar developer's AI agent from the Trailblazer Team drowns you in five dozen "critical vulnerability" tickets for the component you are responsible for.

        Do you: a) spend several hours on each ticket to prove that the vulnerability is a hallucination and the "fix" just adds a redundant check - just to get a bad yearly review for "below-average productivity", "not being a team player", and "failing to adjust to the evolving technological landscape".

        Or do you b) glance over it, see that it is harmless, and press "Merge" after two minutes with a "LGTM, keep up the good work!" - and get a good yearly review with a raise due to "great cycle time"?

        1. keeda · · focus · HN ↗
          Right, because all these companies and developers are all so nonchalant about pumping out arbitrary code changes, because they have never learned that even small changes cause huge issues despite having experienced it countless times, sometimes to losses of millions of dollars!

          There's also c) use your own agent to take the vulnerability and get back to you with an assessment including whether it managed to devise a working exploit, and you go from there.

          Or do you have doubts about the ability of these things to devise working exploits? ;-)

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.