BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Subject: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- Date: Sat, 05 Sep 2026 12:54:15 -0400
- In-reply-to: <6a12c91b-94a7-4c81-93da-3615760f0c83@borg.org>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com> <20260411214838.56b593e0.Richard.Pieri@gmail.com> <mhAY9OfKywiwe5p9jbuWP4ZxR5fGgd7_uUqrqbjEws0md5d1BH7updt-DQ7IxVGAWZtMxIQEMFd_TyLwwGLDReULVRqU4GGGU_jnvKXUZOM=@cryptnet.net> <qh5h3x3w2kbe5voii3hcgo2vuapoxl7nrlvzgoug4nrsv2kr3v@mhmssfwu7rvo> <mFlzau6ezeaBP0gH7cGlxjM-oRrpyUc8glznQi72OZNepcPt-wIa5as8gnoeLwP9aUw6MPrmh3P8vutoMlhGvYQFdX4McXm4LKkiiX3RFoI=@cryptnet.net> <20260417142530.5ba22435.Richard.Pieri@gmail.com> <8f8940a4-6ef8-435f-85b4-684834f8b4b4@app.fastmail.com> <20260903203656.174df76c.Richard.Pieri@gmail.com> <f49ca5a7-3419-4509-90d5-ec219a25d589@app.fastmail.com> <20260904081559.0e8ae553.Richard.Pieri@gmail.com> <47b87f50-7632-4094-a197-dab54523d841@app.fastmail.com> <20260904140511.582fdbd0.Richard.Pieri@gmail.com> <beaccecd-bee0-4bec-bf6b-fcd825ca64c2@app.fastmail.com> <20260904151819.030790b7.Richard.Pieri@gmail.com> <c3e5aecd-ce1d-4d11-aaa8-1d559040f2ce@app.fastmail.com> <6a12c91b-94a7-4c81-93da-3615760f0c83@borg.org>
Interesting perspective. > setting up and running a criminal > enterprise, or setting up and running a spy agency, is real work. [...] > Also, only some targets can be squeezed for lots of money or valuable > intelligence, and there is little point in attacking the others. I partly agree about criminal enterprises, but not really about spy agencies. Crime: Criminals do put a lot of effort into lucrative attacks against airlines, hospitals, banks, etc, so many of the most talented cybercriminals go after these big targets. But at every point in the history of crime, there has been a steady stream of criminal attacks against targets at every economic level, including against people who are far from wealthy (and against even the smallest businesses). If more people go into cybercrime, some will start specializing in small-time crime, including attacks from less wealthy countries against people in more wealthy countries. On another note, I think we are probably more or less at the point where cybercriminals will develop an illegal tool that can be used by seducers to hack into a target's phone, analyze their behavior using AI, and recommend ways to seduce them. Spy agencies: For major spy agencies, the incentives are different. A major spy agency does want to get into everyone's system, both domestically and internationally. They want to understand the population's behavior and how views develop and spread, and they want to find ways to influence all of that along lines their nations' policymakers want. Some of this can be done "legally" using data brokers and the business services offered by social media platforms, and when corporations try to influence the public they do it largely in that way. But hacking helps do it on a bigger scale. If you don't want to be personally spied on by your own country's and other countries' spy agencies, you do have an interest in using systems that are secure against hacking. I suppose the best systems now for protecting against spy agencies are ones like OpenBSD and Qubes, but I haven't looked into that recently. I guess I should. Linux may not be particularly helpful for protecting against spy agencies, but I would say that using Linux or another open-source OS is an essential part of the solution for protecting against manipulation and surveillance by corporations. Beyond spy agencies, there is also the military use of hacking. In a major war, nations have an interest in doing harm to the population of their adversary nations, and hacking can certainly help with that. I don't feel I understand whether it's more strategic from a military perspective to harm a nation's population by attacking utilities etc or, instead, to do some attacks against the population's personal devices. In any case, mutual deterrence, including nuclear deterrence, is what currently puts a limit on this. But in all these areas (crime, spy agencies, intrusion by corporations, military use) we would be better off if we can switch as soon as possible to an open-source OS that was developed in a less vulnerable way than Linux is with its C code, and preferably this should be a formally verified OS. On Sat, Sep 5, 2026, at 10:13 AM, Kent Borg wrote: > An interesting thing about the flood of new vulnerabilities is > :crickets:.? There does not seem to be a flood of new attacks. > > I think it is because computer systems are so poorly cobbled together, > with so many vulnerabilities, that discovering a few more > vulnerabilities doesn't much matter, having a vulnerability isn't the > blocking item for cyber attackers. > > It seems that a bigger problem is that setting up and running a criminal > enterprise, or setting up and running a spy agency, is real work. > Finding a vulnerability isn't the hard part. > > Also, only some targets can be squeezed for lots of money or valuable > intelligence, and there is little point in attacking the others. > > Yes, *some* targets are hard (ios being the prime example), but even a > new vulnerability there isn't worth much unless it can be chained > together with other vulnerabilities to make a working exploit. > > > Most systems are Swiss cheese, and a fancy new tool for finding a news > hole isn't the big deal we expected. > > > kb > > _______________________________________________ > Discuss mailing list > Discuss at lists.blu.org > https://lists.blu.org/mailman/listinfo/discuss
- References:
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: kentborg at borg.org (Kent Borg)
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- Prev by Date: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by Date: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Previous by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Index(es):
