BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Subject: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- Date: Sat, 05 Sep 2026 13:18:53 -0400
- In-reply-to: <20260905123427.375ffb40.Richard.Pieri@gmail.com>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com> <20260411214838.56b593e0.Richard.Pieri@gmail.com> <mhAY9OfKywiwe5p9jbuWP4ZxR5fGgd7_uUqrqbjEws0md5d1BH7updt-DQ7IxVGAWZtMxIQEMFd_TyLwwGLDReULVRqU4GGGU_jnvKXUZOM=@cryptnet.net> <qh5h3x3w2kbe5voii3hcgo2vuapoxl7nrlvzgoug4nrsv2kr3v@mhmssfwu7rvo> <mFlzau6ezeaBP0gH7cGlxjM-oRrpyUc8glznQi72OZNepcPt-wIa5as8gnoeLwP9aUw6MPrmh3P8vutoMlhGvYQFdX4McXm4LKkiiX3RFoI=@cryptnet.net> <20260417142530.5ba22435.Richard.Pieri@gmail.com> <8f8940a4-6ef8-435f-85b4-684834f8b4b4@app.fastmail.com> <20260903203656.174df76c.Richard.Pieri@gmail.com> <f49ca5a7-3419-4509-90d5-ec219a25d589@app.fastmail.com> <20260904081559.0e8ae553.Richard.Pieri@gmail.com> <47b87f50-7632-4094-a197-dab54523d841@app.fastmail.com> <20260904140511.582fdbd0.Richard.Pieri@gmail.com> <beaccecd-bee0-4bec-bf6b-fcd825ca64c2@app.fastmail.com> <20260904151819.030790b7.Richard.Pieri@gmail.com> <c3e5aecd-ce1d-4d11-aaa8-1d559040f2ce@app.fastmail.com> <20260905123427.375ffb40.Richard.Pieri@gmail.com>
This isn't conclusive. You attempted to rebut only part of the "either/or" point from me that you quoted. I don't think we know for sure that kernel developers have access to AI models that are "only marginally behind" the best ones available to spy agencies. Some of what are called "frontier" models are under the same corporate roof as people who work on kernel development, but I am not certain that these Linux kernel people are given full access to the most advanced frontier models that other people employed by the same corporation are developing. The corporation allocates a certain amount of compute time to its most advanced frontier model, and I am not sure it would give an adequate amount of that compute time to the Linux kernel developers who happen to be employees of that same corporation -- from the corporation's perspective, there might be more lucrative uses for the compute time available on its most advanced frontier model. Perhaps more importantly, there have been many technologies where spy agencies are actually more technically advanced than the best models in the corporate world. So the models that you and I think of as "frontier" models from Google, Anthropic, Meta, etc. may not be the actual frontier at present. In a given technology, we often don't know whether spy agencies have advanced beyond what private corporations offer as the state of the art. A spy agency would prefer to develop the world's most advanced AI model in-house, if it's able to do so, and that is given plenty of encouragement when a company like Anthropic says it will refuse to use its AI for mass surveillance. I am certain that if spy agencies have developed an AI that's especially good at finding vulnerabilities and exploits (which need not be the same as the general-purpose AIs that companies like Google and Anthropic use), they do not spend much time in informing the Linux kernel community of the vulnerabilities they've found. > Talk to me when China develops the equivalent of a Culture Mind. Then > I'll panic. The idea of "China developing the equivalent of a Culture Mind" makes things way too specific; it doesn't have to be anywhere near the romanticized idea of a Culture Mind, and it doesn't have to be China developing it. I think you and I may be talking past each other because you frame this as whether it's time to panic, while I have simply been saying that there is a significant risk to be aware of. I don't believe in the dichotomy that says "Either it's time to panic or the risk can be dismissed." My preference is for looking at risks that may have become significant and recognizing that they remain uncertain, not acting as if they have become certain. On Sat, Sep 5, 2026, at 12:34 PM, Rich Pieri wrote: > On Sat, 05 Sep 2026 12:07:28 +0000 > "Randall Rose" <rrose at pobox.com> wrote: > >> --Possibly there is some risk to the Linux kernel's viability, if the >> number of AI-detected CVEs continues to increase and either >> adversaries have access to better AI than kernel developers do or the >> rate of kernel developers' detection of CVEs by using public AI and >> other means outstrips kernel developers' capacity to fix them. > > "Possibly" except the premise itself is demonstrably false. Just look > at the top kernel development organizations leaderboard: Intel, Red Hat > (IBM), AMD, Google, nVidia, Meta, Oracle. To name some. The biggest > companies behind Linux kernel development are also some of the biggest > names in frontier neural network models. And those which aren't have > direct access to those models. At WORST, Linux kernel development has > access to models only marginally behind the best China can bring to > bear, and that's not enough of an edge for Team LLM Apocalypse to win. > > Talk to me when China develops the equivalent of a Culture Mind. Then > I'll panic. > > -- > \m/ (--) \m/ > _______________________________________________ > Discuss mailing list > Discuss at lists.blu.org > https://lists.blu.org/mailman/listinfo/discuss
- Follow-Ups:
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- References:
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: rrose at pobox.com (Randall Rose)
- [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] With AI, 2,000 Vulnerabilities per Linux kernel release
- Prev by Date: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by Date: [Discuss] Linux command-line mystery: why does "cd" hang?
- Previous by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Next by thread: [Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release
- Index(es):
