Live data from Hacker News

Claude Code Found a Linux Vulnerability Hidden for 23 Years

mtlynch.io

171–180 of 303 posts

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#172

This isn't surprising. What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out.

What is with negativity against AI in YC? Can anyone point a finger of why this anti take is so prominent? We're living through the most revolutionary moment of software since it's its inception and the main thing that gets consistently upvoted is negativity, FUD and it doesn't work in this case, or it's all slop.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#174

This isn't surprising. What is not mentioned is that Claude Code also found one thousand false positive bugs, which developers spent three months to rule out.

That's not what is happening right now. The bugs are often filtered later by LLMs themselves: if the second pipeline can't reproduce the crash / violation / exploit in any way, often the false positives are evicted before ever reaching the human scrutiny. Checking if a real vulnerability can be triggered is a trivial task compared to finding one, so this second pipeline has an almost 100% success rate from the POV: i…

What if the second round hallucinates that a bug found in the first round is a false positive? Would we ever know?

> It does not matter how much LLMs advance, people ideologically against them will always deny they have an enormous amount of usefulness.

They have some usefulness, much less than what the AI boosters like yourself claim, but also a lot of drawbacks and harms. Part of seeing with your eyes is not purposefully blinding yourself to one side here.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#175
post #139

Earlier quoted context omitted.

>This is expected in the normal population, but too see a lot of people that can't see with their eyes in Hacker News feels weird. You are replying to an account created in less than 60 days.

This is a bit unfair. Hackers are born every day.

Bots too, vanderBOT!

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#176
post #154

Earlier quoted context omitted.

That's not what is happening right now. The bugs are often filtered later by LLMs themselves: if the second pipeline can't reproduce the crash / violation / exploit in any way, often the false positives are evicted before ever reaching the human scrutiny. Checking if a real vulnerability can be triggered is a trivial task compared to finding one, so this second pipeline has an almost 100% success rate from the POV: i…

> Checking if a real vulnerability can be triggered is a trivial task compared to finding one Have you ever tried to write PoC for any CVE? This statement is wrong. Sometimes bug may exist but be impossible to trigger/exploit. So it is not trivial at all.

Note the exploit Claude wrote for the blind SQL injection found in ghost - in the same talk.

https://youtu.be/1sd26pWhfmg?is=XLJX9gg0Zm1BKl_5

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#177
post #65

Earlier quoted context omitted.

Unfortunately, also in the hands of the __wrong__ people. Maybe even more so, because who is going to wade through all those false positives? A bad actor is maybe more likely to do that.

> A bad actor is maybe more likely to do that. Do something about that then, so white-hat hackers are more likely than black-hat hackers to wanting to wade through that, incentives and all that jazz.

Good luck with that. Security is at the bottom of everyone's budget allocation list.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#179

Earlier quoted context omitted.

I’ve been around long enough to remember people saying that VMs are useless waste of resources with dubious claims about isolation, cloud is just someone else’s computer, containers are pointless and now it’s AI. There is a astonishing amount of conservatism in the hacker scene..

Well, the cloud is someone else's computer.

It is, but that's not a useful or insightful thing to say
Post reply on HN