‹ BackHN Continuity

Thread

Pop!_OS bans AI-generated code from much of its codebase

116 points · 167 comments · bundie

  1. ItsMattyG · · focus · HN ↗
    I don't see how this will survive the attacker/defender gap as ls get increasingly good at cyber security and finding 0 days... but maybe it's an obscure enough is it doesn't matter?
    1. PorciiVorbesc · · focus · HN ↗
      Probably because pop_os and Cosmic are so niche and their market share so insignificant, that they're irrelevant to attackers and bad actors, when those now have much bigger fish to fry to make their time and effort worth it. See the Arch AUR attacks, for perspective.

      I think even amongst the HN and Linux userbase, pop_os is still niche, let alone amongst normies who never heard about Linux. So they can afford take the high road and treat it like their personal sandbox, accepting only human written code.

      But larger and more important projects like Fedora and Debian are more pragmatic with the fact that they'll have to accept AI written(but human reviewed) code, if they wish to keep up with the real world development and threats, as expressed by Linus Torvalds himself.

      The thing is, the cat's out of the bag on this one now, especially in the field of pen-testing and reverse-engineering. AI can brute-force its way into projects in ways that beat even experienced researchers, so your only choice to keep up is to accept the use of AI generated fixes as a counter defense.

      1. DelightOne · · focus · HN ↗
        It also means security is not held as high and vulnerabilities not as much found. A simple 0-day may survive for years. Not much effort needed to have permanent access.
        1. PorciiVorbesc · · focus · HN ↗
          Sorry, I don't understand what you mean by this, can you elaborate pls?
          1. DelightOne · · focus · HN ↗
            Its easier for an LLM to find vulnerabilities in a project with less usage, and those vulnerabilities will stay open longer, making them much cheaper to attack to keep the door open.
            1. PorciiVorbesc · · focus · HN ↗
              What's the point of attacking projects that almost nobody uses?

              Do you think Netanyahu, Trump or Xi-Jinping are somehow secretly using Cosmic DE at home, to be worthy targets?

              Bad actors have limited time, lives of their own and mouths to feed as well, so they concentrate their efforts where "the fish are" if they want to PWN someone for profit.

              That's why Windows was the biggest target in the past for so long and why MacOS and Linux were ignored. Because most of the fish were on Windows.

              1. DelightOne · · focus · HN ↗
                If it costs you as good as nothing, you might as well do it.

                Previously, time was the most precious resource. Now its tokens, and more cheaply at at.

                1. PorciiVorbesc · · focus · HN ↗
                  Offensive security employees, tokens, and peoples' time are still a finite resource that get allocated based on target priorities and operational end-goals, even by state actors.

                  If you assume Mossad and NSA are Token-maxxing every single niche FOSS project out there to cast as large as possible fishnet on hacking all Average Joes on the planet just in case, then maybe using Mozilla and MacOS gets you hacked too, maybe even visiting HN and commenting here gets you hacked by some zero days you don't yet know.

                  Where does this open-ended paranoia argument end?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.