Live data from Hacker News

OpenSSH 10.5/10.5p1

openssh.org

11–20 of 32 posts

Re: OpenSSH 10.5/10.5p1

#11
post #9

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

You need to understand that they have no choice.

Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them.

So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release.

As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports.

> so using AI like ASAN etc. is welcome.

AddressSanitizer is not "AI", nor does it use AI. [0]

[0] https://static.googleusercontent.com/media/research.google.c...

Re: OpenSSH 10.5/10.5p1

#12
post #11
post #9

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

You need to understand that they have no choice. Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them. So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release. As long as the submitter shows their understanding of the reported bug m…

Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.

Re: OpenSSH 10.5/10.5p1

#13
post #9

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

> No, AI assistance is NOT welcome in general.

Can you cite that? I see them specifically welcoming AI security reports; I don't see any evidence that other AI submissions are not welcome.

Re: OpenSSH 10.5/10.5p1

#14
post #7

Earlier quoted context omitted.

It's just not my day.

"AI assistance" is still not welcome in general. AI security reports are.

Is that the case? I see this note focusing on AI reports in the release notes, and I've poked around the OpenSSH project more generally and don't see any indication that they don't accept or welcome other AI inputs.

Re: OpenSSH 10.5/10.5p1

#15
post #13
post #9

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

> No, AI assistance is NOT welcome in general. Can you cite that? I see them specifically welcoming AI security reports; I don't see any evidence that other AI submissions are not welcome.

The AI boosters should look for evidence that they do allow AI contributions! Why would they mention in the release notes that AI security bug reports are welcome if they allowed AI in general anyway?

Re: OpenSSH 10.5/10.5p1

#16
post #11
post #9

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

You need to understand that they have no choice. Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them. So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release. As long as the submitter shows their understanding of the reported bug m…

I'm not a native speaker, but in other languages the cited text clearly means "using AI in the manner of ASAN or similar tools".

Re: OpenSSH 10.5/10.5p1

#17
post #11

Earlier quoted context omitted.

You need to understand that they have no choice. Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them. So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release. As long as the submitter shows their understanding of the reported bug m…

Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.

If you need to make exemptions for critical code because you must admit that AI is undeniably of significant utility, it's pretty foolish to still apply a blanket "hard stand" against it elsewhere.

AI is here, and it's not going anywhere. It's not going to be pretty, but the people that are going to be hit the hardest are those who cannot -- or worse, refuse to -- adapt.

I'm sympathetic -- I feel both a loss and an existential dread. I've also never, in my 30 years in my field, seen something sweep the technology space so quickly and change things so much overnight, and I see no chance of it stopping anytime soon.

Post reply on HN