Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release



Interesting perspective.  

> setting up and running a criminal 
> enterprise, or setting up and running a spy agency, is real work.
[...]
> Also, only some targets can be squeezed for lots of money or valuable 
> intelligence, and there is little point in attacking the others.

I partly agree about criminal enterprises, but not really about spy agencies. 
 

Crime: Criminals do put a lot of effort into lucrative attacks against 
airlines, hospitals, banks, etc, so many of the most talented cybercriminals 
go after these big targets.  But at every point in the history of crime, 
there has been a steady stream of criminal attacks against targets at every 
economic level, including against people who are far from wealthy (and 
against even the smallest businesses).  If more people go into cybercrime, 
some will start specializing in small-time crime, including attacks from less 
wealthy countries against people in more wealthy countries.  On another note, 
I think we are probably more or less at the point where cybercriminals will 
develop an illegal tool that can be used by seducers to hack into a target's 
phone, analyze their behavior using AI, and recommend ways to seduce them.

Spy agencies: For major spy agencies, the incentives are different.  A major 
spy agency does want to get into everyone's system, both domestically and 
internationally.  They want to understand the population's behavior and how 
views develop and spread, and they want to find ways to influence all of that 
along lines their nations' policymakers want.  Some of this can be done 
"legally" using data brokers and the business services offered by social 
media platforms, and when corporations try to influence the public they do it 
largely in that way.  But hacking helps do it on a bigger scale.  If you 
don't want to be personally spied on by your own country's and other 
countries' spy agencies, you do have an interest in using systems that are 
secure against hacking.

I suppose the best systems now for protecting against spy agencies are ones 
like OpenBSD and Qubes, but I haven't looked into that recently.  I guess I 
should.

Linux may not be particularly helpful for protecting against spy agencies, 
but I would say that using Linux or another open-source OS is an essential 
part of the solution for protecting against manipulation and surveillance by 
corporations.

Beyond spy agencies, there is also the military use of hacking.  In a major 
war, nations have an interest in doing harm to the population of their 
adversary nations, and hacking can certainly help with that.  I don't feel I 
understand whether it's more strategic from a military perspective to harm a 
nation's population by attacking utilities etc or, instead, to do some 
attacks against the population's personal devices.  In any case, mutual 
deterrence, including nuclear deterrence, is what currently puts a limit on 
this.  

But in all these areas (crime, spy agencies, intrusion by corporations, 
military use) we would be better off if we can switch as soon as possible to 
an open-source OS that was developed in a less vulnerable way than Linux is 
with its C code, and preferably this should be a formally verified OS.

On Sat, Sep 5, 2026, at 10:13 AM, Kent Borg wrote:
> An interesting thing about the flood of new vulnerabilities is 
> :crickets:.? There does not seem to be a flood of new attacks.
>
> I think it is because computer systems are so poorly cobbled together, 
> with so many vulnerabilities, that discovering a few more 
> vulnerabilities doesn't much matter, having a vulnerability isn't the 
> blocking item for cyber attackers.
>
> It seems that a bigger problem is that setting up and running a criminal 
> enterprise, or setting up and running a spy agency, is real work. 
> Finding a vulnerability isn't the hard part.
>
> Also, only some targets can be squeezed for lots of money or valuable 
> intelligence, and there is little point in attacking the others.
>
> Yes, *some* targets are hard (ios being the prime example), but even a 
> new vulnerability there isn't worth much unless it can be chained 
> together with other vulnerabilities to make a working exploit.
>
>
> Most systems are Swiss cheese, and a fancy new tool for finding a news 
> hole isn't the big deal we expected.
>
>
> kb
>
> _______________________________________________
> Discuss mailing list
> Discuss at lists.blu.org
> https://lists.blu.org/mailman/listinfo/discuss



Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org