‹ BackHN Continuity

Thread

Pop!_OS bans AI-generated code from much of its codebase

116 points · 167 comments · bundie

  1. ItsMattyG · · focus · HN ↗
    I don't see how this will survive the attacker/defender gap as ls get increasingly good at cyber security and finding 0 days... but maybe it's an obscure enough is it doesn't matter?
    1. VCFundedGenYer · · focus · HN ↗
      AI finds a lot of "vulnerabilities" but most are fake, untested, or not actually vulnerabilities.

      Reminder that AI is quite stupid.

      1. novafunc · · focus · HN ↗
        It may have a high false positive rate, but at the speed AIs can review code, there's still plenty, of real vulnerabilites mixed in with the garbage.

        I&#x27;ll trust the words of groups like curl (<a href="https:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2026&#x2F;06&#x2F;10&#x2F;a-human-in-control&#x2F;" rel="nofollow">https:&#x2F;&#x2F;daniel.haxx.se&#x2F;blog&#x2F;2026&#x2F;06&#x2F;10&#x2F;a-human-in-control&#x2F;), Linux, and even the infamously anti-AI Gnome (<a href="https:&#x2F;&#x2F;blogs.gnome.org&#x2F;mcatanzaro&#x2F;2026&#x2F;10&#x2F;02&#x2F;the-era-of-software-quality-or-the-era-of-ostriches&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blogs.gnome.org&#x2F;mcatanzaro&#x2F;2026&#x2F;10&#x2F;02&#x2F;the-era-of-sof...) that AI is finding real vulnerabilities and you&#x27;re your project a disservice by ignoring them.

        Edit: Though Greg did recently have a talk (that I skimmed) where he was a little reserved on LLMs: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=NnV_cWeoo5Q" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=NnV_cWeoo5Q

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.