9 ms·
We have a year to fix security everywhere
- hn_submit 26d agoOr we could just dump Linux and Windows and switch to a microkernel operating system, which is much more secure. These endless patching cycles are simply not going to work in the long run. Operating systems get orphaned all the time, especially the ones in cheap Chinese stuff.
- thunderfork 26d ago"throw away all software written before 2026" does technically solve this problem, if you ignore everything else the article is talking about (deployment and continuity of service)
- 999900000999 26d agoNot to mention a whole lot of new vulnerabilities are bound to arise with all this new software. We really just need better regulations around data retention, especially ppi. Never going to happen though, no incentives exist to NOT sell my personal data
- snvzz 26d agoThrowing away old software is not a requirement, as demonstrated very successfully by Genode and its SculptOS.
- hn_submit 26d agoI assume Microsoft would be able to rewrite the monolithic Windows kernel to a microkernel. So far, they haven't but it wouldn't surprise me if they experiment on Azure with a custom microkernel version of Windows. Linus Torvalds is a strong proponent of monolithic kernels so I don't see him changing his mind.
- a96 25d agoMake that 2036 or whenever there might be a feasible microkernel available outside of niche applications. Better get started on that. Again.
- simonw 26d agoGot any leads on good tutorials on how to use a microkernel operating system on a VPS somewhere to host a website?
- rramadass 26d agoJust checked with Google Gemini on how one might be able to do the above. It pointed to Minix3/seL4/Genode and vps providers who either support custom ISOs or run it within an emulator like QEMU. You can also look at using Unikernels for this purpose. Here is an article Unleashing Extreme Speed and Security: Deploying Unikernels with NanoVMs on VPS to Eliminate the Linux OS - https://xylentis.com/blog/unleashing-extreme-speed-and-security-deploying-unikernels-with-nanovms-on-vps-to-eliminate-the-linux-os https://xylentis.com/blog/unleashing-extreme-speed-and-secur...
- hn_submit 26d agoMinix can run Ngnix.
- simonw 26d agoI don't think we even have a year. The current batch of LLMs are ferociously good at identifying vulnerabilities.
- dgl 26d agoEven if they are good the vulnerabilities have to be there. There's lots of things turning up like Local Privilege Escalations (LPE) in Linux, but serious people didn't expect the kernel to be a boundary for a sophisticated attacker. A lot of the vulnerabilities LLMs are finding now are the "long tail" and affect only particular configurations, I would be surprised if e.g. a widely applicable RCE is found in Linux (but I'm also not going to bet against it). Where this gets interesting is the long tail can be used to target a particular system and this is where defense-in-depth becomes important for every organisation.
- zahlman 26d ago> but serious people didn't expect the kernel to be a boundary for a sophisticated attacker. I think it has more to do with what's on each side of the boundary in practice, a la https://xkcd.com/1200/ https://xkcd.com/1200/ .
- Gigachad 26d agoThankfully we have already made good progress towards things like arm memory tagging and memory safe languages. It’s a rocky period right now but the future will be much more secure after all the low hanging fruit are found.
- Cthulhu_ 26d agoThat's definitely an improvement, but it's just one aspect of cybersecurity. Logical errors allowing people to e.g. log into services and extract data are likely everywhere still.
- Gigachad 26d agoIf we can eliminate entire classes of bugs from being possible. It frees up resources to investigate the ones that are still possible. I suspect after a few years of LLM assisted bug hunting, everything will have a baseline security that is very good. Much like how stronger viruses simply create stronger immune systems.
- sho 26d ago> On September 22, Apple is releasing the M5 Mac Studio with 256 GB of unified memory [..] it will probably [..] enough to write this snippet of code in 3 seconds The author has obviously never ran an LLM on a mac! In 3 seconds, it will have possibly started to think about maybe scheduling a date to contemplate the planning timeline for processing the second token in your prompt.
- simonw 26d agoThe difference is memory bandwidth. The M5 Ultra that's coming out on 22nd September can do 1,200GB/s. The M5 Max you can buy today only has 614GB/s.
- sho 26d agoSo, that gets us to about where nVidia was with Ampere in 2020. Let's hope the M7 catches us up with at least Hopper.
- Gareth321 26d agoWhile true, the news here is the size of the unified RAM. Nvidia only exceeded 256GB RAM in the 2025 B300 - 288GB. The B300 alone (without the baseboard/PSU/chassis/wiring/CPUs/system RAM/etc) is at least 700% more expensive. This enables large language models on consumer hardware. 1200GB/s is plenty for many tasks.
- hypfer 26d ago> 1200GB/s is plenty for many tasks. This + due to the hardware being so prohibitively expensive, we're seeing software optimizations happening. Like that dflash2 stuff for example, or an LRU for MoE and all that kind of stuff.
- klooney 26d agoI wonder if the inference acceleration companies will ever produce a consumer product
- 26d ago
- pmlnr 26d agoHere's an idea: as a first step, simplify everything, and make sure you're aware how your stack works, and what it imports. As an example: WordPress is a horrible thing, but the core has been through so much, that it's suprisingly secure. Then plugins and themes come, and whoosh, the security is gone. We need a new KISS: keep it simple, stupid, secure.
- mirashii 26d agoThe "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough. https://nvd.nist.gov/vuln/detail/cve-2026-63030 https://nvd.nist.gov/vuln/detail/cve-2026-63030
- spiderfarmer 26d agoPlus, how secure are the plugins?
- m_mueller 26d agoWP plugins are why I banned it everywhere. Last time I used it was many years ago, so not sure it still applies, but back then even caching was done in a plugin, without which it was unusably slow… just no.
- pmlnr 26d ago"First step" Nobody said it's enough, but it's a start.
- ricardobayes 26d agoIf that's your benchmark for being unsecure, then React is unsecure too. https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components https://react.dev/blog/2025/12/03/critical-security-vulnerab...
- mirashii 26d agoI would put both of those projects in the category of things I wouldn't call remarkably secure, yes. To be remarkably secure, these projects would need to not have these kinds of defects, despite the combination of being written in languages have that have a long track record of footguns and lack of initiatives to fix them (proposal-symbol-proto, and PHP's list is too long to even start) and being themselves ecosystems with questionable track records on security in the related areas (Look at $wpdb in 2026, or overall code quality and willingness to modernize, or the entirety of the model of RSC for things that are just going to nearly guarantee you punch all kinds of holes on accident).
- dbdr 26d ago> Invest in formal verification, fuzzing and property testing, and memory-safe languages. LLMs are good at writing Lean and fuzz tests. I don't care whether you use Go or Rust but for the love of god please don't use C or C++ for new code. How accepted is this thinking in your respective domains?
- pjmlp 26d agoA lot, I am only writing C or C++ for new code when it is unavoidable, like existing code bases, bindings or tinkering with runtime implementations that aren't bootstraped. Mobile platforms, distributed computing have long moved the spotligh away from C and C++, other than language runtimes or existing products from the 90's like SQL servers, and naturally UNIX like underlying OS, which most userspace developers aren't writing new code for. Naturally there are domains like LLVM/GCC, console game dev, HPC/HFT where they are unavoidable for new code.
- bsenftner 26d agoThe propaganda police are lying. There is nothing wrong with C/C++, you are just too lazy to handle your own memory, and you accepted that propaganda that "managing your own memory is hard" without even trying. The idea that this terrible advice floats at all tell you how terrible educations are these days. The idea is ridiculous and yet nobody calls it what it is: it is stupid and those that follow that advice out of fear are dumber than rocks.
- teiferer 21d agoThe propaganda police are lying. There is nothing wrong with assembly, you are just too lazy to manage your own register allocations and stack layout, and you accepted that propaganda that "manage your own register allocations and stack layout" without even trying.
- a96 25d agoNot sufficiently. Companies aren't keen on taking on new ideas unless it pays. Buzzword matchers only match old buzzwords. People in the trenches are too busy to try new stuff and/or don't want to push new things because of management or other obstacles. Most products are built on top of legacy code after all. You stick to the tech that those contain.
- petesergeant 26d agoMmm, a world where a defender-LLM is essentially required is great news for people selling inference.
- the8472 26d agoDefender LLMs without human in the loop are just another prompt injection (AI phishing) and DoS attack vector. Any meaningful mitigation capability you give them is also a capability to do damage. If they can only deploy package updates that's not meaningful because you could do that on a cronjob too. And even something as simple as a circuit breaker can turn into a DoS. Attacker-GLM: "Defense also GLM. Request to help peer."
- LoganDark 26d agoIt's just the same advice as ever: be extremely, exceedingly careful in what you expose to any network. When I set up machines for production, they don't respond to pings and they don't even have an SSH port open without knocking. There are also ways to eschew the need for an SSH port entirely. People who never took that seriously will never take this seriously either, and that's their loss. (And loss of the commons, unfortunately.) There's just also new advice: you can't afford to expose an unsecured system to the internet even for a moment. Think of those IPv4 address space scanners, except this time any one of them could be capable of developing individualized attacks in mere minutes. They don't sleep, they don't take breaks.
- Gigachad 26d agoThat’s fine for your home server, but if you want an actual server that the general public can use, it has to be exposed to the internet.
- tgv 26d agoStill, it doesn't have to ping back, and ssh can (should) be very restrictive.
- Gigachad 26d agoPing and ssh are pretty much never the things being hacked though. Turn password auth off and it’s very secure. What gets hacked all the time is the actual web app itself. Which has to be exposed to be useful.
- tgv 26d agoI imagine it pays off to find weaknesses in openssl and sshd and the other gateways. There are some ubiquitous web frameworks, but ssh is nearly universal.
- LoganDark 26d ago> Turn password auth off and it’s very secure. Password auth and the root username. Use one attackers are unlikely to guess and elevate with sudo if needed.
- uecker 26d ago[flagged]
- orlp 26d agoSupply chain risks are essentially a solved problem. 1. Set a minimum age on dependencies: https://github.com/rust-lang/cargo/issues/15973 2. Scan all dependency code with AI Even if you don't do #2 yourself as long as anyone does in the age window you've set, you're protected. In the age of AI the "you can't read all dependency code" argument doesn't work anymore. On top of the above modern age argument, let's compare the amount of vulnerabilities found in shipped Rust software due to supply chain attacks (0 to my knowledge) against memory safety vulnerabilities (the majority of all vulnerabilities). There have been successful supply chain attacks against Rust developers due to build.rs but those were quickly dealt with, and should be a thing of the past once min-age hits stable (next release).
- egnehots 26d agodon't you then introduce a new risk? with a gap between the update of your deps, you are at risk of systematically being unpatched for a window of time that the attackers know (just after a fix is published).
- orlp 26d agoThe above is a general rule protecting you against supply chain attacks by default. If there is an important CVE published with a patch you can manually review that patch and bypass the minimum-age requirement for that dependency specifically.
- uecker 26d agoIf I look at actual incidence involving memory safety issues compared to supply chain issues in general, it is the later which is much a higher risk to me. And yes, there were successful supply chain attacks on Rust developers, even just recently: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/ https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on... despite this being a "solved" problem. I think this becomes worse with AI not better, while memory safety risks will probably get much less in other languages after possibly some higher rate for a while.
- acedTrex 26d agoMaybe all these vital infrastructure companies should not have spent the past decades in a race to the bottom of cybersecurity. There is going to be a reckoning.
- enoint 26d agoI think the WeChat worm proves entire classes of handheld devices will be affected, with consequences beyond what Tencent can afford to remedy. I think we’ll see the most-centralized ideas suffer first, not necessarily the Western ones who relied on being too big to fail and prioritized stock buybacks.
- protocolture 26d agoJust like Cryptolocker, this will be the "Finding Out" phase for everyone who has been putting off best practice security. But, lets be clear, Best Practice will save you. We can engineer assuming there are zero days in path. Go to your CTO now cap in hand and ask for overlapping controls, wafs, application monitoring, backups and all the other shit you haven't been doing. Because when you find out, I will laugh, it will be very very very funny to me.
- taurath 26d agoMeanwhile a huge portion of management and leadership in software companies are encouraging everyone to de facto stop looking at code and let the LLM and a bunch of boundaries handle this for you.
- m_mueller 26d ago“You are a CISO who needs to review and secure all our slop, and you never make mistakes or you get shut down immediately!”
- LoganDark 26d ago"You are a Miso soup..."
- protocolture 26d agoWhich is why you need someone who is responsible for IT security without also being responsible for shipping product. An asshole who can stop releases until security is properly in place. My understanding is this bloke gets very quickly removed from Fortune 500 companies. Which is why I am going to need a very large capacity popcorn bucket.
- rukuu001 26d agoA couple high-profile crash & burns will get their attention.
- 26d ago
- hypfer 26d ago> This probably sounds like nonsense words or hysterical overreacting to most people, so here's what that means: "GLM" is a kind of LLM (AI) [...] The post also sounds like that to people that understand the technology. Calling that out like this and trying to pin that assessment to lack of knowledge is not a get-out-of-jail-free card, nor a good move. __ Edit: Having spent some time letting the article marinate in my mind. On the defending side, it is written that > LLMs are good at writing patches, but not as one-off-prompts. But this for me kinda conflicts with what is written on the attacking side: > GLM 5.3-flash is so good at those tasks that human involvement in those tasks can be negligible. As a result, we are now in a world where cybersecurity attacks can be run in a for loop. What is it? Can it be this autonomous terrifying entity or can it not be? Yes, yes, attackers only need to win once, whereas defenders need to win every time, but that's not my point.
- jynelson 26d ago> What is it? Can it be this autonomous terrifying entity or can it not be? the difference between attack and defense is that attacks can be throwaway code. it's much easier to let an llm hack out a prototype than to get it to build maintainable code that people want to read and review. it's not enough to get Daybreak or Mythos to write you a patch, you need the author of the project to accept and merge it.
- enoint 26d agoLet’s say I’m empowered to patch and deploy. Even then, the HuggingFace hack showed that proven exploits will be automatically disseminated via rogue messaging. Could defenders ever have a system like that?
- the_arun 26d agoHow to secure our identity layers(AuthN & AuthZ)? Let alone the products.
- aenis 26d agoI think we have less time and the only remaining limitation is the actual cost to run such hacking campaigns. It does not appear expensive, but is not free, and there is a LOT of things to scan for vulnerabilities. The models are already here, and one can rent a GPU cluster to run such workloads at speed - no need to play with slow local machines. I'd assume one can host the thinking at an unsuspected public cloud provider, proxy the network traffic to some botnet to evade blocking - and the only thing remaining is time and cost. I do wonder what tools exist for boring, legitimate companies to try and do the same to their own systems to find the vulnerabilities before the bad guys do. The paradox here is I can't run a de-restricted chinese model with the same tools that hackers are using - but I think enterprises actually HAVE to do it in order to stand a chance in preparing for the onslaught.
- Certhas 26d agoThe point of the local model in the context of the article was to argue that you can't ban these capabilities. Making datacenters and public clouds only rent GPUs to a restricted list of people, while tightly monitoring what people do with their bought resources won't help.
- techpression 26d agoRemember how GLM 5.3 was going to cause massive hacks, break banks and ruin everything (it was even newsworthy since media picked up how people were working overtime in preparation). And yet here we are.
- gherkinnn 26d agoThe title reads like a Diary of a CEO thumbnail but unlike those discussions this article has a point. Impotent slop code on one side and potent automated vulnerability exploitation on the other will lead to fun times.
- archi42 26d agoZzzzz, we should have gotten security right a few decades ago. But security costs money and isn't a flashy feature to attract new customers, or cuts into your margin if you're a "real" business producing stuff or offering some service. Or whatever the decision makers in Berlin were thinking when they ignored security. Yeah, we would still see hacks, but we would see less of them if security wasn't optional. Maybe the AI craze helps by forcing more decision makes to see security as imperative, and by giving us another powerful tool for our tool box. N.b.: I work in the security industry, our customers obviously want to improve their security. We've been seeing an uptick in awareness, but that's mostly due to NIS2 and other legislative efforts. Those force them to do something. AI is a curiosity for small talk to many of them.
- protocolture 26d agoA large number of places will buy a new firewall every 5 years, or pay their fortinet renewal and check "Security: Done!" without any kind of analysis. I was contracted in to a place to do among other things cyber security insurance audits, and they asked me to stop doing them because I refused to lie to their insurer. "Wait but if we only score 20 / 300 that makes us look kind of bad" uh huh.
- chii 26d ago> pay their fortinet renewal and check "Security: Done!" without any kind of analysis. there exists objective measure of security, which would be some sort of hacks/breaches per period. If customers cared about it (and i assume they do), they would choose companies that have less breaches over others with higher counts, normalized on cost differences. Therefore, if companies didnt actually try to fix their security but instead just checked boxes, they would get breached more often, resulting in customer losses. The only thing stopping this from actually occurring is the lack of mandatory regulatory reporting of it. So this is where gov't needs to step in and mandate disclosure etc.
- geon 26d agoBreaches don’t happen often enough to be a useful metric. Most smaller companies are never breached, despite having basically zero security.
- zkmon 26d agoThe standard strategy of a security salesman since 1945. Develop dangerous weapons, show the damage they can do, and sell security cover to the terrified people. Every single piece of technology did this. As a side effect or direct effect, they make bad guys more powerful and then keep on piling up new tech to deal with that. The cycle continues.
- madaxe_again 26d agoSince 1945? Friend, this has been the case since the invention of the pointy stick.
- Yossarrian22 26d agoItself in reaction to someone wielding a big rock
- ma2kx 26d agoI don't see much hope since I last explored some github repositories. There was a time when a successful repo had about 10 - 20k stars and usually those older repos stay around this level. But now there is a ton of vibe coded slop 50k + stars. Most of them have a "nice look", maybe even extensive docs but are usually build with no security considerations at all. One recommended to provide a "google app password" to the agent which has the same permissions as your regular login. Another was a browser plugin with permissions to read all cookies, inject js, open background tabs etc. You would probably assume the chrome store would at least put some visible warnings on the app store page or force the user to actively confirm those permissions. But because they are already stated in the manifest there is only a small footnote and it's even "recommended by google".
- cuu508 26d agoIt's a good time to reduce the reliance on technology. Throw out the IoT and "smart" stuff from your home. Remove apps from your phone and leave the absolute basics. Go through the password manager and close accounts for sites you are no longer using. Start migrating off Google. Print out your most precious photos on paper. And so on :-)
- chris_wot 26d agoMore tired “don’t use C or C++” advise.
- mark_something 26d agoI wonder why C and C++ are usually regarded as equally insecure. In C you need to carefully check that you free allocated memory, and that you don't use it after you free it. In C++ this is automated by using classes like std::string and std::vector, once they go out of scope their memory is freed and you can't use it anymore. It is still possible, e.g. by using a for loop that iterates over a vector, and removing or adding stuff to that same vector in that loop. But my rough estimate is that such errors are at least ten times less likely in C++. I develop in C++ for a job, and when I need to use a library written in C I always have a bad feeling about it.
- chris_wot 26d agoRAII definitely removes whole classes of errors.
- lelanthran 26d ago> I wonder why C and C++ are usually regarded as equally insecure. They aren't, usually. C++ has all the C problems, and multiples more on top of those. It's a broad attack surface - literally no one is going to claim to be proficient in every single C++ feature available to their compiler. It's also quite opaque to visual inspection (making double-checking with an LLM difficult as it needs whole-program reasoning instead of localised reasoning). One of those languages is one of the most complex programming languages ever invented, with the largest breadth of features, any of which may interact with any other feature in subtle ways. The other is one of the most minimalistic languages created, with a dev able to keep the language standard in their head for the most part.
- preg_match 26d agoI disagree, the minimalism of C results in writing overly complex code to solve simple problems. Things like type punning and bit hacks are common place in C. The end result is equivalent C code is much more complex than C++. For example, you need to remember to call free every time, forever, in every function. In C++ you just use unique ptr or shared ptr and you’re done. It’s a simpler model, enabled by the more complex feature of RAII. Something like std::vector isn’t hard to write in C, it’s impossible. The language semantics don’t allow it. So you have to do hacks and remember to free, over and over again forever. It only takes just one time forgetting, and that’s a memory bug. I mean, consider a large codebase. How many free calls does C++ eliminate altogether? Thousands, maybe tens of thousands? You just need to forget one of those in C, or even just put it in the wrong place. And that’s just one class of things. Generics are much more complex in C, too. The type system in C is more complex IMO because it can be so easily defeated at every turn. C gives you practically no guarantees, no tools, for anything. The result is you are forced to write extremely defensive code everywhere, complex code. The analogy I use is to physical tools. A screwdriver is simple, but building a house with only a screwdriver is complex. A suite of power tools is complex, but building a house with them is simple.
- jf 26d agoAnother similar issue, with similar consequences and timeline, is Post Quantum Cryptography.
- dikei 26d agoNot even close, Quantum Computer are still far from being able to do any cryptography cracking.
- andy_ppp 26d agoNot sure, the labs will probably just cripple the security features of these models for a while I think and even potentially put back doors into systems for the security services…
- kennywinker 26d agoI think the author's point is that open weight models aren't going to be locked down like that. And even if they are locked down, it's hours between a model being released on huggingface and an "abliterated" variant that has most of its security features removed is uploaded.
- kennywinker 26d agoI'm confused why the worry about LLMs that will answer "how do I build a pipe bomb". That information is easily available other places. The anarchist cookbook has been around and available for 55 years, and yet pipe bombs are not going off all around us.
- matherial 26d agoBecause it's a risk most people intuitively understand, but most of them also don't know how difficult it is to "build a bomb" or "make a bioweapon". In reality, the skills needed are pretty basic, but they overlap pretty strongly with being sane and well-adjusted. And if you are, you're probably not daydreaming about mass murder. Exceptions happen, Unabomber and so on, but they're pretty rare. In any case, Unabomber probably didn't need a tutorial. We don't want ChatGPT to become an enabler and a co-conspirator for an unhinged person, but I think the concern is overdone.
- XorNot 26d agoWell that, and the average amount of easily obtainable explosives is substantially less dangerous then renting a box truck and crashing it into a crowd of people. People go for conventional "exciting" threats rather then boring ones.
- lrvick 26d agoI think this was just intended as universally obvious proof the filters were disabled, while not actually giving an example not commonly known.
- 0xDEAFBEAD 26d agoThere used to be a thing called "Moore's Law of Mad Science": "Every eighteen months, the minimum IQ necessary to destroy the world drops by one point." Nowadays it is dropping much faster. At a certain point, the de-facto IQ needed to destroy the world will be low enough that someone can do it while they're having a psychotic break. There are millions of schizophrenics worldwide. Are you sure you want to roll those dice?
- vee-kay 26d ago[dead]
- deleted 26d ago[deleted]
- deleted 26d ago[deleted]
- nullbio 26d agoGoing to be hard to fix security when the frontier labs won't let us fix bugs in our own codebases without them offering refusals or bans.
- tumetab1 26d agoI sympathize with the sentiment but the suggested/implied guidance to fix bugs is wrong. The overall game is increasing costs to exploit so much that attackers give up. Fixing 10 most obvious bugs, just very slightly increases costs, they would just a few more tokens to find another bug. As someone said "I had infinite bugs, I fixed 1000, I still have infinite bugs". To significantly increase exploit costs software/security has -1 years to do: - Defense in Depth - Sandbox everything - Zero trust - Canary tokens - Split data from code (lol) - App Whitelisting - Reduce attack surface - Etc. In other words, the only path is investing heavily on the "game changers" we have already discovered... but we are too cheap/lazy/coward/incompetent to apply. And if we feel specially brave, changing the liability laws regarding software. Open Source & Proprietary code is so crappy because no gets jailed or fined when one of its dumb decisions results in millions of people have their data stolen.
- daymanstep 26d agoAs LLMs make formal verification cheaper (they can generate proofs that can then be automatically checked) many of the verifiable components of software systems, such as compilers and microkernels, will be verified. I suppose the issue is that the critical bugs are rarely in compilers and microkernels, but more often in applications, such as web browsers, which are more difficult to formally verify.
- mentalgear 26d ago1 year left for cybersecurity hardening, I thought so as well. The issue is, even if we get it done: in 1 year the models will be so good in social-engineering that they will be able to extract any information they want anyway. Happy to be falsified here, if anyone has evidence-based arguments. EDIT: by social-engineering I mean for example: recon company structures, gathering and merging people's data from the dark-web, then using it to bribe/pressure/deceive users.
- enoint 26d agoI have to agree. People are worried about WordPress. We should be talking about scripts as sophisticated as Shattered Spider targeting every ISP. In an environment where IT has to wade through vendor chaos.
- kreetx 26d agoA positive way to spin this is: we have a year to break in into any IT system. After that, it will be all either fixed or broken into, and all is fixed ever after. :)
- goalieca 26d agoYeah.. and all that new LLM coded services are rock solid /s
- kreetx 26d agoBut won't they be? If the public internet is overloaded with LLM agents, trying to break into systems, then all the non-secure systems will be found quickly, and taken off-line/fixed/etc. I.e, the hostile environment will force an outcome and a fix.
- keybored 26d agoClanker fodder. Unless the We are heads of states/heads of spooks or the AI powers that be (praise be) that there is no power and will to do that in one year or even ten years.
- bamboozled 26d agoWe had decades to avert the worst effects of climate change…batten down the hatches.
- jens_tlb 26d ago[dead]
- jasonvorhe 26d ago> And a big fuck you to DeAlignAI, Z.ai, and everyone else who's been participating in this race to the bottom. I'm so glad frontier level AI isn't in the hands of just the Altmans and that other cult leader who are currently live testing their products in actual conflicts in the middle east and Ukraine.
- xbmcuser 26d agoNo you have a few years before we go back to the feudal era where almost everything is owned by a few and the rest are serfs. We are fast moving towards that world and this security bullshit is also about the same as they will use it to stop revolutions that will erupt.
- shelled 26d agoI see a lot of people focused on servers and production environments, and of course that's needed, because that's business after all — but the personal computer seems to be absent from this discourse. Not everyone can buy a spare mac studio, and they might still need to install these tools on their personal computing devices, like their personal/home laptops. At that point, it's not even about whether a Claude Code, an OpenCode, or a Pi will steal/sniff personal data, but whether it can — though I think saying "it's a matter of 'when'" might be hyperbole. As of now, it's just: keep giving access and permissions or struggle while working, or create another user, or use Docker, run inside sandbox-exec, a VM, etc. As an end user, I am really scared. Someone who has been very disciplined and vehemently privacy- and security-conscious feels the ground below has just shifted. OEM/OSes don't seem to have woken up to it yet. A mild proof is Apple's own special folder access reporting. When you go to Privacy & Security > Files & Folders, for a certain app, "Full Disk Access" is shown greyed out and mentioned in both cases — whether you had given Full Disk Access to that app or not. This directory-level permission UX is itself broken — there's Full Disk Access, and there's Files & Folders, and Full Disk Access gets shown in Files & Folders as well. This is, for lack of a better word, such an undesirable mess. As of now I am debating between: creating a new user and just move everything work/learning to that user. Or just run all of it inside sandbox-exec (and maybe even block it from the shell if it tries to run outside it). Or use a tool that makes the latter easier and better. I even came across such a tool here on hn few weeks ago. agent-safehouse, yet to try it.
- mc-serious 25d ago[flagged]
- halilBB 26d ago[flagged]
- llm_nerd 26d agoDid Amadeo write this ridiculous nonsense? >Cheap models capable of dangerous hacking are now available to anyone, without the normal safeguards for refusing malicious actions Models capable of dangerous hacking have been available to the people who do most of the dangerous hacking for some time now, and they have infinite resources and infinite malice. I am talking about governments (the US, China, Israel, and others that have shown extraordinary avarice, malice and threat toward the citizens of the world), three letter agencies, even large enterprises. Random employees at the SOA model makers. And so on. The idea that it's "random" people, or the farcical Mac under the bed nonsense, is not my concern. If anything that's finally some equalization.
- happycube 26d agoNot directly related, but reading this after looking at https://www.reddit.com/r/ClaudeAI/comments/1wa544p https://www.reddit.com/r/ClaudeAI/comments/1wa544p makes me think the writing style here is how LLM's probably should write web pages - simple explinations, defines things people might not already know, etc. More related: What can an abliterated Qwen 3.8 28B do?
- asamadx 26d agoIt is really good
- parasxos 26d agoWe have had a year to fix security everywhere every year since 1988. The deadline is the one thing that has never been breached.
- dmitrygr 26d agoAstroturfing for Anthropic or OpenAI IPO?
- rbtms 26d agoIt's of course important to reduce the impact surface before more powerful models become available, but it's worrying that some people seem to assume the only way to counteract those are by using more AI models, which despite being (apparently) good at finding bugs, they are also very good at introducing them unnoticed.
- pona-a 26d agoMaybe it happens that LLMs are great at finding human bugs which have some more patterned structure that's easier to match for then LLM bugs. They prefer LLM prose to human prose, so what if they're similarly wooed by slop code?
- saimiam 26d agoThis sounds roughly at par with Y2K in terms of “you need to fix your shit right now wherever it is” complexity except every day is Y2K for your code base.
- anon373839 26d ago> GLM 5.3-flash released last week, and that means Project Glasswing and Daybreak are running out of time. Cheap models capable of dangerous hacking are now available to anyone, without the normal safeguards for refusing malicious actions. We need to fix vulnerabilities across the industry so that we aren't caught unawares. … We can use frontier LLMs that move faster than a human to find and fix these issues in the time we have left. I think the author has this backwards. In the timeline I’ve been living in, it’s the frontier models that have been carrying out attacks on third parties, and Chinese open source models doing the defending! During the Huggingface incident, HF was denied use of frontier models to fend off the intrusion, but was fortunately able to turn to its self-hosted instance of GLM-5.2. And it did the job.
- big-and-small 26d ago> And a big fuck you to DeAlignAI, Z.ai, and everyone else who's been participating in this race to the bottom. Yeah of course. Only billionare US overlords allowed to have access to security research tools.
- mikewarot 26d agoNot radical enough, there are only 3 mentions of "air gap" and zero mentions of data diodes in the article. The focus seems to be more of the same failed strategy: a shift to "safe" programming languages a focus on patching known bugs proactively ratcheting up rules and enforcement This all amounts to "try harder", which isn't going to work. We need a ground up restructuring of everything if we want to have a stable foundation upon which to keep society going. If you run critical infrastructure, it must be air-gapped from the internet. If you need to monitor said infrastructure, there are data diodes which can be configured to allow the egress of monitoring data, with ZERO risk of allowing ingress of control, enforced by the laws of physics, not some code running on hardware that might not be perfect. We need to channel everything important through clearly defined, and well monitored channels. Ambient authority based operating systems were a great hack, but we need to leave them behind. Proven microkernel based OSs with everything running in userland, and all access provided using capabilities, with UI including powerboxes, are a bare minimum. The amount of code and hardware we actually trust should be pushed towards zero as far as is possible. Linux, Windows, etc are all unfit for the present and future security needs of humanity. As for AI/LLMs themselves. They're natively a huge amount of floating point math that results in token predictions. The code that runs the math is something we can control. There's no reason to give code access to anything about the machine it's actually running on. This should be something that can be enforced without extraordinary effort.
- aussieguy1234 26d agoAI generated code having more security issues + Superhuman AI security scanning capabilities could create a perfect storm. One AI generates code, another AI finds the security holes and systems everywhere get compromised.
- deleted 25d ago[deleted]