Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] With AI, 2, 000 Vulnerabilities per Linux kernel release



This isn't conclusive.  You attempted to rebut only part of the "either/or" 
point from me that you quoted.  

I don't think we know for sure that kernel developers have access to AI 
models that are "only marginally behind" the best ones available to spy 
agencies.  Some of what are called "frontier" models are under the same 
corporate roof as people who work on kernel development, but I am not certain 
that these Linux kernel people are given full access to the most advanced 
frontier models that other people employed by the same corporation are 
developing.  The corporation allocates a certain amount of compute time to 
its most advanced frontier model, and I am not sure it would give an adequate 
amount of that compute time to the Linux kernel developers who happen to be 
employees of that same corporation -- from the corporation's perspective, 
there might be more lucrative uses for the compute time available on its most 
advanced frontier model.

Perhaps more importantly, there have been many technologies where spy 
agencies are actually more technically advanced than the best models in the 
corporate world.  So the models that you and I think of as "frontier" models 
from Google, Anthropic, Meta, etc. may not be the actual frontier at present. 
 In a given technology, we often don't know whether spy agencies have 
advanced beyond what private corporations offer as the state of the art.  A 
spy agency would prefer to develop the world's most advanced AI model 
in-house, if it's able to do so, and that is given plenty of encouragement 
when a company like Anthropic says it will refuse to use its AI for mass 
surveillance.  I am certain that if spy agencies have developed an AI that's 
especially good at finding vulnerabilities and exploits (which need not be 
the same as the general-purpose AIs that companies like Google and Anthropic 
use), they do not spend much time in informing the Linux kernel community of 
the vulnerabilities they've found.

> Talk to me when China develops the equivalent of a Culture Mind. Then
> I'll panic.

The idea of "China developing the equivalent of a Culture Mind" makes things 
way too specific; it doesn't have to be anywhere near the romanticized idea 
of a Culture Mind, and it doesn't have to be China developing it.

I think you and I may be talking past each other because you frame this as 
whether it's time to panic, while I have simply been saying that there is a 
significant risk to be aware of.  I don't believe in the dichotomy that says 
"Either it's time to panic or the risk can be dismissed."  My preference is 
for looking at risks that may have become significant and recognizing that 
they remain uncertain, not acting as if they have become certain.  

On Sat, Sep 5, 2026, at 12:34 PM, Rich Pieri wrote:
> On Sat, 05 Sep 2026 12:07:28 +0000
> "Randall Rose" <rrose at pobox.com> wrote:
>
>> --Possibly there is some risk to the Linux kernel's viability, if the
>> number of AI-detected CVEs continues to increase and either
>> adversaries have access to better AI than kernel developers do or the
>> rate of kernel developers' detection of CVEs by using public AI and
>> other means outstrips kernel developers' capacity to fix them.
>
> "Possibly" except the premise itself is demonstrably false. Just look
> at the top kernel development organizations leaderboard: Intel, Red Hat
> (IBM), AMD, Google, nVidia, Meta, Oracle. To name some. The biggest
> companies behind Linux kernel development are also some of the biggest
> names in frontier neural network models. And those which aren't have
> direct access to those models. At WORST, Linux kernel development has
> access to models only marginally behind the best China can bring to
> bear, and that's not enough of an edge for Team LLM Apocalypse to win.
>
> Talk to me when China develops the equivalent of a Culture Mind. Then
> I'll panic.
>
> -- 
> \m/ (--) \m/
> _______________________________________________
> Discuss mailing list
> Discuss at lists.blu.org
> https://lists.blu.org/mailman/listinfo/discuss



Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org