Hi,

On Wed, May 20, 2026 at 03:55:00PM -0000, CGS wrote:
> I saw that Linus had complained on the kernel mailing list that there
> were multiple bug reports for the same vulnerability because people
> were using AI and deriving the same results.

Some thoughts on that.

Everyone who has access to one of the commercial LLMs has the ability to
find those security bugs.

There's no way to un-invent the LLMs or restrict access to them.

I'd rather the security issues be reported multiple times than no times.

I'm pretty sure that Linus and most other kernel developers agree with that.

I think the rate of discoveries will slow down soon, only to increase
again shortly after each release of an improved LLM.

We need to worry about the time between private LLM advances and their
public release, because that's when people have access to lots of "zero
day" security bugs.

Thanks,
Andy

-- 
https://bitfolk.com/ -- No-nonsense VPS hosting

Reply via email to