frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Linux kernel security work

http://www.kroah.com/log/blog/2026/01/02/linux-kernel-security-work/
32•chmaynard•2h ago

Comments

JCattheATM•1h ago
Their view that security bugs are just normal bugs remains very immature and damaging. It it somewhat mitigated by Linux having so many eyes on it and so many developers, but a lot of problems in the past could have bee avoided if they adopted the stance the rest of the industry recognizes as correct.
tptacek•1h ago
From their perspective, on their project, with the constraints they operate under, bugs are just bugs. You're free to operationalize some other taxonomy of bugs in your organization; I certainly wouldn't run with "bugs are just bugs" in mine (security bugs are distinctive in that they're paired implicitly with adversaries).

To complicate matters further, it's not as if you could rely on any more "sophisticated" taxonomy from the Linux kernel team, because they're not the originators of most Linux kernel security findings, and not all the actual originators are benevolent.

rwmj•1h ago
For sure, but you don't need to file CVEs for every regular bug.
Skunkleton•20m ago
In the context of the kernel, it’s hard to say when that’s true. It’s very easy to fix some bug that resulted in a kernel crash without considering that it could possibly be part of some complex exploit chain. Basically any bug could be considered a security bug.
SSLy•11m ago
plainly, crash = DoS = security issue = CVE.

QED.

JCattheATM•20m ago
> From their perspective, on their project, with the constraints they operate under, bugs are just bugs.

That's a pretty poor justification. Their perspective is wrong, and their constraints don't prevent them from treating security bugs differently as they should.

ada0000•14m ago
> almost any bugfix at the level of an operating system kernel can be a “security issue” given the issues involved (memory leaks, denial of service, information leaks, etc.)

On the level of the Linux kernel, this does seem convincing. There is no shared user space on Linux where you know how each component will react/recover in the face of unexpected kernel behaviour, and no SKUs targeting specific use cases in which e.g. a denial of service might be a worse issue than on desktop.

I guess CVEs provide some of this classification, but they seem to cause drama amongst kernel people.

beanjuiceII•1h ago
did you read it? because that's not their view at all
firesteelrain•42m ago
“A bug is a bug” is about communication and prioritization, not ignoring security. Greg’s post spells that out pretty clearly.
akerl_•15m ago
This feels almost too obvious to be worth saying, but “the rest of the industry” does not in fact have a uniform shared stance on this.
DebugDruid•5m ago
Sometimes I dream about a 100% secure OS. Maybe formal verification is the key, or Rust, I don’t know. But I would love to know that I can't be hacked.

How Dependabot Actually Works

https://nesbitt.io/2026/01/02/how-dependabot-actually-works.html
1•zdw•2m ago•0 comments

Show

1•wdpatti•3m ago•0 comments

Manifesto for a Disinterested Artistic Self

https://pablohelguera.substack.com/p/manifesto-for-a-disinterested-artistic
1•anarbadalov•4m ago•0 comments

The Rise of Computer Games, Part II: Digitizing Nerddom

https://technicshistory.com/2026/01/02/the-rise-of-computer-games-part-ii-digitizing-nerddom/
1•cfmcdonald•4m ago•0 comments

India issues stern notice to X, flags Grok targeting women with obscene content

https://www.indiablooms.com/news/india-issues-stern-notice-to-x-flags-groks-role-in-targeting-wom...
2•binning•9m ago•0 comments

Residues: Time, Change and Uncertainty in Software Architecture [video]

https://www.youtube.com/watch?v=D8qQUHrksrE
1•zdw•10m ago•0 comments

Lenovo ThinkBook Plus Gen 6 Rollable Display Laptop Review [video]

https://www.youtube.com/watch?v=1GsJi1KvHhA
1•xqcgrek2•10m ago•0 comments

Steadfast Self-Hosting, Auf Deutsch

https://selfhostbook.com/news/2026/01/deutsch/
1•meonkeys•14m ago•0 comments

How to open the Maclock retro Macintosh clock without breaking it [video]

https://www.youtube.com/watch?v=WEVMEvV_sOM
2•cleverbit•14m ago•0 comments

Certified Shovelware

https://justin.searls.co/shovelware/
2•8organicbits•24m ago•0 comments

Show HN: Runtm- open-source runtime and control plane for agent-built software

https://github.com/runtm-ai/runtm-coding-agent-runtime-control-plane
2•gustrigos•29m ago•1 comments

Why AI Agents Won't Just "Do Stuff" – Permissions Are the Ultimate Barrier

https://davefriedman.substack.com/p/why-ai-agents-wont-just-do-stuff
2•walterbell•31m ago•0 comments

When AI recreates the female voice, it also rewrites who gets heard

https://theconversation.com/when-ai-recreates-the-female-voice-it-also-rewrites-who-gets-heard-26...
2•binning•31m ago•0 comments

HTML Changes in ePub

https://www.htmhell.dev/adventcalendar/2025/11/
3•raybb•34m ago•0 comments

Non-consensual Grok deepfakes endanger women

https://unherd.com/newsroom/non-consensual-grok-deepfakes-endanger-women/
5•binning•35m ago•2 comments

Show HN: StretchBreak, a simple web app to solve planning time off

https://stretchbreak.netlify.app/
2•tha_infra_guy•41m ago•0 comments

California lawmaker wants to ban AI from children's toys

https://www.fastcompany.com/91468728/california-lawmaker-ban-ai-toys
5•geox•44m ago•0 comments

NY Fed cash transfers to banks increase dramatically in Q4 2025

https://www.dcreport.org/2025/12/29/ny-fed-unlimited-cash-infusions-bank-crisis/
4•scythe•45m ago•0 comments

Brand as Code

https://www.braingrid.ai/blog/brand-as-code
1•acossta•49m ago•2 comments

He Was a Supreme Court Lawyer. Then His Double Life Caught Up with Him

https://www.nytimes.com/2025/12/28/magazine/thomas-goldstein-supreme-court-gambling.html
2•ryan_j_naughton•50m ago•0 comments

LeCun calls Alex Wang inexperienced, predicts more Meta AI employee departure

https://www.businessinsider.com/yann-lecun-alexandr-wang-criticism-inexperienced-meta-ai-future-2...
13•_____k•51m ago•3 comments

The Lottery Ticket Hypothesis: finding sparse trainable NNs with 90% less params

https://arxiv.org/abs/1803.03635
1•felineflock•52m ago•0 comments

Economic inequality does not equate to poor well-being or mental health

https://www.nature.com/articles/d41586-025-03833-8
1•gmays•53m ago•0 comments

Glasses-free 3D display with ultrawide viewing range using deep learning

https://www.nature.com/articles/s41586-025-09752-y
2•PaulHoule•53m ago•0 comments

Show HN: Jot - Offline, source available notetaking/assistant app

https://jot-ai.app/blog/welcome-to-jot
5•robust-cactus•54m ago•1 comments

An unsolved question in sleep science

https://www.autodidacts.io/long-sleep-duration-and-mortality/
1•Curiositry•57m ago•0 comments

Mastodon Server Covenant

https://joinmastodon.org/covenant
3•doener•57m ago•0 comments

Ask HN: Is the window for local-first AI closing?

2•zerocool86•59m ago•1 comments

Capital in the 22nd Century

https://philiptrammell.substack.com/p/capital-in-the-22nd-century
2•thundergolfer•59m ago•0 comments

Foldy Bird

https://lyra.horse/fun/foldy-bird/
2•Groxx•1h ago•1 comments