Live data from Hacker News

Claude Code Found a Linux Vulnerability Hidden for 23 Years

mtlynch.io

201–210 of 303 posts

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#201
post #197

Earlier quoted context omitted.

[flagged]

More like, if you pay a fee to use a service, you can find the bombs already hidden somewhere in your premises.

And? They didn't put the bombs on your premises. Before "the service", you had bombs you didn't know about; after, you get to know about them.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#202

Earlier quoted context omitted.

The lesson here shouldn't be that Claude Code is useless, but that it's a powerful tool in the hands of the right people.

I'm growing allergic to the hype train and the slop. I've watched real-life talks about people that sent some prompt to Claude Code and then proudly present something mediocre that they didn't make themselves to a whole audience as if they'd invented the warm water, and that just makes me weary. But at the same time, it has transformed my work from writing everything bit of code myself, to me writing the cool and com…

I am also torn because obviously the LLMs have a lot of value but the amount of misuse is overwhelming. People just keep pasting slop into story descriptions that no one can keep up. There should be guidelines at work places to use AI responsibly.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#203
post #178

[flagged]

[flagged]

Thank you for your kind comment. I recommend you watch the actual talk, and then understand what exploiting RCEs in things like the Linux kernel at such a scale that defenders can no longer keep up with actually means. The latter is their claim, not mine.

Also realize that, unlike a security researcher, an attacker doesn't necessarily need to review the model out carefully to filter out the slop before a bug submission. They mostly just need to run the shit.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#204
post #139

Earlier quoted context omitted.

>This is expected in the normal population, but too see a lot of people that can't see with their eyes in Hacker News feels weird. You are replying to an account created in less than 60 days.

This is a bit unfair. Hackers are born every day.

In relation to the quality of its comment. I thought it was a fair. He just completely made up about false positives.

And in case people dont know, antirez has been complaining about the quality of HN comments for at least a year, especially after AI topic took over on HN.

It is still better than lobster or other place though.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#205
post #139

Earlier quoted context omitted.

That's not what is happening right now. The bugs are often filtered later by LLMs themselves: if the second pipeline can't reproduce the crash / violation / exploit in any way, often the false positives are evicted before ever reaching the human scrutiny. Checking if a real vulnerability can be triggered is a trivial task compared to finding one, so this second pipeline has an almost 100% success rate from the POV: i…

>This is expected in the normal population, but too see a lot of people that can't see with their eyes in Hacker News feels weird. You are replying to an account created in less than 60 days.

[dead]

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#206

Earlier quoted context omitted.

Well, the cloud is someone else's computer.

It is, but that's not a useful or insightful thing to say

It's not an insightful statement right now, but it was at the peak of cloud hype ca. 2010, when "the cloud" often used in a metaphorical sense. You'd hear things like "it's scalable because it's in the cloud" or "our clients want a cloud based solution." Replacing "the cloud" in those sorts of claims with "another person's computer" showed just how inane those claims were.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#207
post #181
post #154

Earlier quoted context omitted.

> Checking if a real vulnerability can be triggered is a trivial task compared to finding one Have you ever tried to write PoC for any CVE? This statement is wrong. Sometimes bug may exist but be impossible to trigger/exploit. So it is not trivial at all.

I'm tickled at the idea of asking antirez [1] if he's ever written a PoC for a CVE. [1] https://en.wikipedia.org/wiki/Salvatore_Sanfilippo

I actually like when that happens. Like when people "correct" me about how reddit works. I appreciate that we still focus on the content and not who is saying it.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#208
post #197

Earlier quoted context omitted.

More like, if you pay a fee to use a service, you can find the bombs already hidden somewhere in your premises.

And? They didn't put the bombs on your premises. Before "the service", you had bombs you didn't know about; after, you get to know about them.

But the service also tells criminals and adversaries about the bomb locations.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#209

Earlier quoted context omitted.

And? They didn't put the bombs on your premises. Before "the service", you had bombs you didn't know about; after, you get to know about them.

But the service also tells criminals and adversaries about the bomb locations.

And? So do a variety of other services. Was it your impression that the criminals and adversaries were behind the 8 ball on this?

AI is reviving debates about vulnerability research that we thought we killed off in the 1990s.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#210
post #203

Earlier quoted context omitted.

[flagged]

Thank you for your kind comment. I recommend you watch the actual talk, and then understand what exploiting RCEs in things like the Linux kernel at such a scale that defenders can no longer keep up with actually means. The latter is their claim, not mine. Also realize that, unlike a security researcher, an attacker doesn't necessarily need to review the model out carefully to filter out the slop before a bug submissi…

Is your pitch that the reports are slop? Or that they’re so dangerous it’s morally indefensible to share the research?
Post reply on HN