| ▲ | Fordec 2 hours ago |
| This is great, more access did provide more eyes on these problems. But, does that all of these being found now call into question, not the open source model logic itself, but the ability of human eyes to find security issues? These vulnerabilities have been sitting here for however long, but how many thousands of humans did not find them before AI? |
|
| ▲ | spoaceman7777 an hour ago | parent | next [-] |
| The threshold for Microsoft and Apple to actually report vulnerabilities is MUCH MUCH higher than for Linux, and open source as a whole. They generally only disclose issues in Windows and macOS that are quite serious and impactful. For Linux, the threshold is nearer to the point of it being questionable whether a bug is even exploitable on a real production distro, compiled and run with any sort of sane configuration. |
|
| ▲ | SchemaLoad 2 hours ago | parent | prev [-] |
| Even before AI we have known that no one is smart enough to write bug free C. And with every bug being a launch platform for a full exploit it's become a big deal. |
| |
| ▲ | 1over137 2 hours ago | parent | next [-] | | No one is smart enough to write bug free in any language. | | |
| ▲ | zakisaad an hour ago | parent | next [-] | | This is the reason why performant and "safe" systems languages are on the rise and being accepted into foundational areas of our operating systems (such as the kernel). When the attack defense surface is tighter (language, tooling, compiler instead of the actual code itself), the smart folks can stay at that layer, while the masses can write more code at a level of abstraction that nullifies many of these vulnerabilities by default. | |
| ▲ | catlifeonmars an hour ago | parent | prev | next [-] | | Clearly it’s because people never got the memo: https://www.rfc-editor.org/rfc/rfc9225.html | |
| ▲ | SchemaLoad 2 hours ago | parent | prev | next [-] | | That's why we designed better languages that can block the compilation if memory hasn't been handled properly. | |
| ▲ | wat10000 an hour ago | parent | prev [-] | | The difference is that C casually makes common everyday bugs into security vulnerabilities. |
| |
| ▲ | 0c3ca83 an hour ago | parent | prev [-] | | AI levels the playing field; it's incredibly good at finding the bugs. |
|