Live data from Hacker News

Claude wrote a full FreeBSD remote kernel RCE with root shell

github.com

121–128 of 128 posts

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#121

Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…

Nonsense. Claude did find this CVE and hundreds of similar Linux CVE's, plus it did the complete writeup and the reproducer. The Linux bugs are more worrying. His backlog is hundreds of yet unreported zero days.

He did a talk at unblocked last month.

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#122
post #103
post #102

Earlier quoted context omitted.

[flagged]

This very question was asked to Nicholas Carlini from Anthropic at this talk: https://www.youtube.com/watch?v=1sd26pWhfmg The answer is complex, worth watching the video. But mainly, they don't know where to place the line. Defenders need tools, as good as attackers. Attackers will jailbreak models, defender might not, it's the safeguard positive in that case? Carlini actively asks the audience and community for "hel…

[dead]

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#123
post #121

Key point is that Claude did not find the bug it exploits. It was given the CVE writeup[1] and was asked to write a program that could exploit the bug. That said, given how things are I wouldn't be surprised if you could let Claude or similar have a go at the source code of the kernel or core services, armed with some VMs for the try-fail iteration, and get it pumping out CVEs. If not now, then surely not in a too di…

Nonsense. Claude did find this CVE and hundreds of similar Linux CVE's, plus it did the complete writeup and the reproducer. The Linux bugs are more worrying. His backlog is hundreds of yet unreported zero days. He did a talk at unblocked last month.

Not unblocked but unprompted: https://www.youtube.com/watch?v=1sd26pWhfmg Great talk.

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#124

Earlier quoted context omitted.

Letting Claude get at the source code to try to find CVEs. I found it particularly entertaining that after finding none it just devolved to a grep for "strcat."

Oh, I see. No, you're wrong. That's absolutely not what it did and not at all an accurate way to sum up what it found. This isn't a complete rebuttal to your argument but I'll note with irony that we're commenting on a thread about a FreeBSD kernel remote that Claude both found and wrote a reliable exploit for (though people will come out of the woodwork to say that reliable exploitation of FreeBSD kernel remotes isn…

[flagged]

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#126

Earlier quoted context omitted.

God damn, how much time am I wasting by writing full paragraphs to the Skinner box when I could just write half-formed sentences with no punctuation or grammar?

> can we demon strait somehow a unpriv non root user "demon strait". Was this speech to text? That might explain the punctuation and grammar.

The grammar doesn't matter. It's a total waste of time. Obviously not when writing to another human, when then it's a show of respect.

Re: Claude wrote a full FreeBSD remote kernel RCE with root shell

#127

I could see that being an incremental time save (perhaps not worth the token spend except for the dev team, not a high-value bug). But nbody finds this kind of bug "by hand" and hasn't for a long time now. Do people here really care about kernel security or testing automation? They're just talking about it because Claude? Everything on HN is people doing unpaid promotional work for Anthropic, just talking about all t…

I get what you’re saying, but I think the interesting part isn’t that people don’t find this by hand anymore, it’s that we’re starting to automate finding stuff no one was really catching consistently.

HN hype is definitely real lol, but I don’t think it’s just unpaid promo. People are just trying to figure out where these tools are actually useful and where it’s just vibes.

And “not a high value bug” kinda depends. For product maybe not, but for infra or security, small wins can add up if they scale.

Post reply on HN