Live data from Hacker News

Claude Code Found a Linux Vulnerability Hidden for 23 Years

mtlynch.io

301–303 of 303 posts

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#301

Earlier quoted context omitted.

It is, but that's not a useful or insightful thing to say

Are you sure about that? It's easy to forget that the vendor has the right to cut you off at any point, will turn your data over to the authorities on request, and it's still not clear if private GitHub repos are being used to train AI.

Two of these are basic contractual problems, your company should have a lawyer who can sort them out easily. The third (data being turned over to authorities) is something that the vast majority of companies do not care about in the slightest.

Re: Claude Code Found a Linux Vulnerability Hidden for 23 Years

#302
post #294

Earlier quoted context omitted.

Perhaps the argument isn't about the ethics of security research, but rather the divide between those who can afford non-free software licenses and those who ethically or circumstancially can't.

You'd see the same thing in 1990s full-disclosure debates, where people trying to create a social/cultural argument against vulnerability research would throw this kind of stuff against the wall just to see what would stick. It's either good to know about vulnerabilities in the code you rely on or it isn't.

Yes, of course. It's a bloody shame some of those tools are inaccessible to the poor, the not poor but f* your stupid payment system that doesn't connect to my bank, the software freedom enthousiasts, possibly others.

For myself, software freedom isn't just an ethical issue but also a practical neccesity.

Post reply on HN