Earlier quoted context omitted.
The lesson here shouldn't be that Claude Code is useless, but that it's a powerful tool in the hands of the right people.
The same could be said about a Roulette wheel set before a seasoned gambler
Claude Code Found a Linux Vulnerability Hidden for 23 Years
111–120 of 303 posts
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#112Earlier quoted context omitted.
> What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out. Source? I haven't seen this anywhere. In my experience, false positive rate on vulnerabilities with Claude Opus 4.6 is well below 20%.
In TFA: I have so many bugs in the Linux kernel that I can’t report because I haven’t validated them yet… I’m not going to send [the Linux kernel maintainers] potential slop, but this means I now have several hundred crashes that they haven’t seen because I haven’t had time to check them. —Nicholas Carlini, speaking at [un]prompted 2026
Please explain how a bug can both be unvalidated, and also have undergone a three month process to determine it is a false positive?
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#113Earlier quoted context omitted.
Those aren't false positives; they're results he hasn't yet inspected. I wrote a longer reply here: https://news.ycombinator.com/item?id=47638062
> Those aren't false positives; they're results he hasn't yet inspected. It's not a XOR
If the claim was instead just "a good portion of the hundreds more potential bugs it found might be false positives", then sure.
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#114Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#115This isn't surprising. What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out.
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#116Earlier quoted context omitted.
No, they haven't. Read the ai slop you posted carefully. It's a policy update that enables maintainers to ignore low effort "contributions" that come from untrusted people in order to reduce reviewing workload. An Eternal September problem, kind of.
Didn't you just restate what the parent claimed?
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#117Earlier quoted context omitted.
Claude and Codex pro/max subs aren't supposed to be used for commercial/enterprise development so its not really an option for execs in enterprise. They need to take into account API costs. At my F500 company execs are very wary of the costs of most of these tools and its always top of mind. We have dashboards and gather tons of internal metrics on which tools devs are using and how much they are costing.
> Claude and Codex pro/max subs aren't supposed to be used for commercial/enterprise development lolwut?
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#118Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#119Earlier quoted context omitted.
Didn't you just restate what the parent claimed?
No, that's not at all the same thing: ai-generated contributions from people with a track record for useful contributions are still accepted.
The fact that there’s a small carve out for a specific set of contributors in no way disputes what Supermancho claimed.
Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years
#120Earlier quoted context omitted.
The lesson here shouldn't be that Claude Code is useless, but that it's a powerful tool in the hands of the right people.
The same could be said about a Roulette wheel set before a seasoned gambler