Live data from Hacker News

Linux security mailing list 'almost unmanageable'

theregister.com

71–80 of 116 posts

Re: Linux security mailing list 'almost unmanageable'

#71

Earlier quoted context omitted.

I'm a huge AI advocate but even I can't get on board with this. Feel free to fork the kernel and maintain your own vibe-coded disaster.

I'm confused by your answer, the previous post doesn't seem to be about vibe-coding at all. It seems to be more about: 1. auto grouping duplicate security reports 2. auto validating if they are likely viable or likely nonsense 3. auto checking if they have recently been patched 4. auto assessing if they likely "invalide" for other reasons (e.g. they are for a very old long time no longer maintained Linux version, out…

AI slop causes additional noise on the mailing list. Your suggestion is to use more AI to filter the noise?

How about we just reduce the noise?

Re: Linux security mailing list 'almost unmanageable'

#72
Nonsense advice, he's just asking for duplicate slop patches too this way.

It's a catch 22. Why not make a separate list for AI generated reports that can be subscribed to instead? If the claim is that these are not private anyhow, no reason not to, and then a reasonable expectation could be held against submitters to check against existing reports.

That is unless it is still absolutely sensitive, in which case the only way forward that I see is to start using AI for triaging and duplicate detection as well.

Re: Linux security mailing list 'almost unmanageable'

#73
post #4

Earlier quoted context omitted.

Linus also said “AI tools are great, but only if they actually help, rather than cause unnecessary pain and pointless make-believe work,” he wrote. “Feel free to use them, but use them in a way that is productive and makes for a better experience.” So I think the closing remark from the register isn’t really appropriate given the context from the quotes they pulled.

the problem here is that many of the submissions are not "make-believe work" but actual existing security issues it's just that in the past people most times didn't find security vulnerabilities independently of each other without knowing about the others en mass worse it's non trivial to dedup on the submitter side, nor on the receiver site (as long as we stay with a classical mailing list format) and while this mig…

> the problem here is that many of the submissions are not "make-believe work" but actual existing security issues

Not exactly, the submissions are reports about actual existing security issues. They are make-believe work because everybody has access to AI, and anybody could have done it. Deduping is not productive work, it's a search for productive work.

Instead of spamming bug reports generated by AI, people should spam cash or token credit of some sort so the project can generate these themselves. The real unnecessary part of the entire process is the submitter. There's no need for an AI middleman.

If somebody comes up with some witty trick that gets an AI to find a bug that it wouldn't have found on its own, submit the prompt.

Re: Linux security mailing list 'almost unmanageable'

#74

Earlier quoted context omitted.

I'd warn HN users not to click on that link simply because it will load a 26Mb message that will likely cause quite a strain on kernel.org's servers if everyone here does it.

Does a 26MB message actually cause noticeable strain on the server much beyond loading the page? I would think serving a contiguous 26MB chunk would be relatively similar to say 20 normal sized messages.

Way off. I went to an arbitrary message on lore.kernel.org. Firefox's network inspector says 7.37kB was transferred, including stylesheets. 26MB is roughly 3500x 7.37kB.

Re: Linux security mailing list 'almost unmanageable'

#75
post #52

Earlier quoted context omitted.

old people like the old tools that they grew up using

This is the reason behind essentially every reply I've ever seen to this question. "I like it this way because it's always been this way and once you change your entire email workflow and customize your email client, it's almost as good as PHPbb" Forums are built for threads and are immediately visible and accessible for everyone , not just people who want to spend their limited time dicking with email clients. Maili…

I understand it is out of fashion, but technologically more advanced are systems that use well defined interfaces and allow pieces to be exchanged easily. After all, we’re communicating over a number of open protocols here. A forum merges all elements into one silo. I prefer web over AOL/Compuserve. If you want a forum-like interface, there’s no technical reason why this couldn’t be done on top of a mailing list. In fact, Discourse and others attempted it.

This discussion has been happening since forever. And also the idea that it serves anyone to complain how others are obviously doing it wrong, without even attempting to understand why they’re doing it a certain way. And then be irritated when the response is negative, and labeling others as elitist for using and providing open platforms over decades and not silos.

If you don’t know, feel free to ask. And then suggest (or provide!) improvements that factor in current requirements and goals instead of dismissing them as stupid.

Life advice: if you want anybody to change what they do, you need to first understand why they’re doing it, and then offer suggestions based on that understanding that improve it with them. Otherwise you’re going to continue to recreate your own victim position, and an “elite” position that you will never belong to.

Re: Linux security mailing list 'almost unmanageable'

#76
post #9

Fun fact (or not so fun if you're a subscriber): Somebody is spamming kernel mailing lists under the name Marian Corcodel with a 26 MByte message multiple times per day containing a collection of nonsensical patches. Looks AI-generated, perhaps with the intention to poison LLMs. This has been going on for a few days now. https://lore.kernel.org/all/CAGg4U=GNtCObd_Nbm_1Rr5FEvPb69Yz...

I'd warn HN users not to click on that link simply because it will load a 26Mb message that will likely cause quite a strain on kernel.org's servers if everyone here does it.

The page is gzipped in transit - only 5 MB of traffic are generated.

Re: Linux security mailing list 'almost unmanageable'

#77
post #64

Make it anonymous and the problem will go away. The problem is people trying to get individual credit for merely running a script that spams a mailing list. Many of those people are likely not even C programmers or programmers at all. Without the immense personal reward and recognition and job offers as a motivation, the problem will disappear. The problem will also disappear with time as the people lauding and celeb…

I really like this idea. Removes the fame, blog & resume/job hunting incentive from it.

The kernel isn't the only OSS project with this issue either. Requiring submissions & issues to be anonymous could help a ton of other open source projects currently drowning in AI slop issues.

Re: Linux security mailing list 'almost unmanageable'

#78

Will never understand why some people prefer mailing lists to do development, it always feels like the most convoluted way to hold a discussion, especially if there are multiple topics at the same time. It probably doesn't really change that much in this scenario but with a forum or any other topics-based platform you can at least just close and ignore these things without it affecting everyone else.

Because ther don't have to keep switching from discussion client to discussion client or whatever tools the use for each project they are involved with, at the same time being distracted by adverts, geegaws, random emojis and other kinds of nonsense.

They are simply more efficient and more importantly censoring is done by the user themselves, not by politically motivated admins who ban discussions based on their ideologies and whims.

Re: Linux security mailing list 'almost unmanageable'

#79

Earlier quoted context omitted.

How do you navigate the web, everything is CTRL+L then manually type the address, or you have some fancier solution?

the web is useless outside of hn

90% of it yeah, but the 10% is still worth it, like HN.

Re: Linux security mailing list 'almost unmanageable'

#80

Earlier quoted context omitted.

I was curious how much of an impact HN could have. Napkin math: HN gets 24M views a day. Assume those views are evenly distributed across the front page (they aren’t), and that’s about 1M views for each front page post, assuming each user clicks on one post. By the rule of 10s (also not exact), there are 10x less views on comment threads. So assume around 100k views on a comment thread as a theoretical average. If ev…

> HN gets 24M views a day This is available info?

https://news.ycombinator.com/item?id=33450094

2022 from dang:

> There's no stats page but last I checked it was around 5M monthly unique users (depending on how you count them), perhaps 10M page views a day (including a guess at API traffic), and something like 1300 submissions (stories) and 13k comments a day.

> The most interesting number is the 1300 submissions because that hasn't grown since 2011 - it just fluctuates. Everything else has been growing more or less linearly for a long time, which is how we like it.

Post reply on HN