frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Just the rumour of a bug is enough to find an exploit these days

https://anil.recoil.org/notes/rumour-is-the-exploit
59•avsm•1h ago

Comments

zb3•52m ago
Dario Amodei would not be happy about this.. listen, you're not the choosen one! You can't find vulnerabilities, even in your own code, you must politely apply for permission, but if it's not granted, you must accept your fate and stop developing software.

This is the only way forward, open weight models must be illegal. Thanks for understanding.

skybrian•46m ago
They were not happy about it and loudly warned everyone it was coming, but instead of listening a lot of people said LoL MaRkEtInG.
nickcw•51m ago
This describes my life as an open source maintainer at the moment!

In the first 10 years of the rclone project we received about 20 security disclosures through GitHub. We had to deal with over 40 in the last month! That has taken a huge amount of my time, even using AI tools to triage and come up with fixes for review.

The hit rate for those security disclosures is pretty good - about 75% of them have a nugget of something which needs looking at. The configurations for rclone have got increasingly unlikely so I'm hoping they will dry up eventually.

I was considering just merging the fixes straight to master just to make my life easier rather than holding a dozen independent security fixes on branches and merging them at the point release and hoping not to have too many conflicts to fix up. I've decided to stick with the process for the moment.

GitHub assigns CVEs for the advisories. Before the AI apocalypse they took 2-3 days for an assignment but now it they are running at 3-4 weeks so I have to send the point releases out with CVE-PENDING in the changelog which isn't ideal.

Not sure what the solution is, but it is definitely a problem for us.

Kubuxu•35m ago
As long as you are not running a paid bounty program. Otherwise now you are getting 40 per day.
zmgsabst•35m ago
I can’t comment on if it applies to your workflow, but one process I’ve used is to aggregate and land ~10 security patches at a time. Eg,

- grab a group of (related) bugs/defects/vulns

- fix them on a branch like bug-batch-XXX

- run that group through the verification, landing in main, CI/CD flow to amortize process cost

- repeat as needed to process backlog

My experience is that process often has irreducible time (eg, two days due to reviews by various parties); but that time slot can be shared between several bugs in a single PR — especially if you have several related to the same feature.

dataviz1000•13m ago
> even using AI tools to triage

Can you discuss this? I might be able to help.

dannyw•9m ago
Thank you for making and maintaining rclone. It is truly a blessing.
bri3d•47m ago
I don't think this is new with LLMs (finding an exploit based on a few words offhand has always been a fun part of exploit development), but it's scaled and democratized to mass exploitation of low value targets. Backing exploit PoCs out of patches, commit messages, and random overheard or over-read sentences is a practice as old as vulnerability research. The difference with LLMs is that an explosion in actors "skilled enough" (human or not) has enabled sloppy / low-skill "exploit the whole Internet" actors in a way they weren't previously enabled.

I do agree with the author's ideas, though; most of these are things that should have been done much sooner, and I suppose it's good in a sense that there is a forcing factor now.

happyopossum•21m ago
> Backing exploit PoCs out of patches, commit messages, and random overheard or over-read sentences is a practice as old as vulnerability research

True, but it used to take days or weeks of research, testing, and RE to get those PoCs.

Today the entire chain - reading commits, RE patch binaries, building exploit, scripting exploit scan, $profit - can be fully automated and happen in minutes or hours.

godelski•44m ago
It's easier to find bugs, fix them, yet there's less will than ever. My bosses just want speed and will give me a 30 minute lecture on why I don't need to solve a bug that Claude solved in 5 minutes, I've verified, and it's already in an open PR. All the while we're pushing out bugs faster and faster.

No matter how good AI gets at fixing bugs we'll never fix them when there's no will to fix things. Software will never be good if there's no will to make good software. The problem has always been about will. To many better products. It's insane that in a time where we can do better on speed and quality we still choose speed and tell ourselves it's velocity

yieldcrv•35m ago
My boss is a big yapper too

Very low signal information, preemptively trying to cover every rebuttal despite nobody ever planning on making one, in the few times someone does he plays devils advocate endlessly

Like bro just let us babysit these agents, everything’s going to happen

johnbarron•26m ago
You will see, they will change both laws and expectations, to say its normal for software to always have terrible bugs. You can always solve a problem by lowering your expectations. :-)
flanked-evergl•23m ago
What law says software may not have bugs?!
vasco•14m ago
If your boss asks for X feature and you split it into 4 PRs, 3 that implement X and a 4th that fixes a security bug, how would they know? Someone that uses those 30mins like that isn't reviewing your PRs themselves. Just fix it and be done with it. You only needed to argue with the boss when you needed to make time for it which would delay something else. If it just appears done they'll just react with clap emoji later when you announced you also fixed this extra thing.
loeg•7m ago
No mention of memory safe languages? Sure, it does not help existing projects, and sure, of course you can still have logic bugs (or memory bugs using escape hatches like unsafe). But they do help significantly in reducing the number of exploitable bugs.
ryandrake•12m ago
Most places I've worked have been infuriatingly uninterested in fixing bugs, and would release software with major known bugs and a vague plan to fix them later. Of course, when "later" came, there were more features to cram. No time to fix those bugs.

I'm hoping one of the unintended side effect of it being essentially free to find and exploit (and fix) software bugs is that companies become less cavalier about shipping bugs in their software. Unlike most of the industry I don't believe "bugs are inevitable." Bugs are a choice developers make when they're rushing and careless and when all of their incentives are to ship quickly. You can ship bug-free software but it takes (or used to take) a really long time and a lot of care, care that commercial software developers just don't ever seem to muster.

Maybe when their software is getting 0wned over and over and 30 security issues are published a day, they'll start caring and taking their time.

Bitcoin is great (for systemic theft of aid money)

https://www.ft.com/content/38d95298-8b9b-486a-96d3-0c6616972abb
1•JumpCrisscross•1m ago•0 comments

OpenAI: Luna Reserve

https://help.openai.com/en/articles/20001499-luna-reserve-in-codex-and-chatgpt-work
1•tosh•1m ago•0 comments

Freedom for Hacking!!1 - Renewing DMCA exemptions for software freedom

https://sfconservancy.org/news/2026/aug/27/dmca-renewal-submission-2026/
1•hn_acker•2m ago•0 comments

Show HN: Watermarks Remover: Clean LLM watermarks from text and files

https://github.com/guillaumemeyer/watermarks-remover
1•gmeyer•2m ago•0 comments

How Are You?

https://joshholtz.com/blog/2026/08/27/how-are-you.html
1•ricobecks•2m ago•1 comments

PerPageFax

https://www.perpagefax.com/
2•welsenesbros•7m ago•0 comments

Navigator n2: Frontier Computer Use at a Fraction of the Cost

https://yutori.com/n2
1•abhshkdz•7m ago•0 comments

South Korea leans toward military conscription for women

https://www.dw.com/en/south-korea-leans-toward-military-conscription-for-women/a-78547426
1•Teever•8m ago•0 comments

Narwhals document atlantification of East Greenland

https://www.science.org/doi/10.1126/sciadv.adr1424
2•croes•9m ago•0 comments

If you can't fix the models you use, fix your workflows

https://kolesnik.io/blog/fix-your-workflows
2•opwizardx•10m ago•0 comments

Single CRISPR Treatment Slashed LDL Cholesterol for a Year

https://www.nytimes.com/2026/08/28/science/an-experimental-single-time-treatment-slashed-choleste...
3•marojejian•10m ago•1 comments

The Machine Age Fund – Andreessen Horowitz

https://a16z.com/the-machine-age-fund/
2•thm•10m ago•0 comments

The teenage girls behind a $25 minimum wage fight in rural Alaska

https://19thnews.org/2026/08/nome-alaska-minimum-wage-november-ballot/
4•mooreds•10m ago•0 comments

The Download: a secretive antiaging drug and joining virtual power plants

https://www.technologyreview.com/2026/08/28/1143113/the-download-antiaging-drug-joining-virtual-p...
2•joozio•11m ago•0 comments

I Asked 100 Companies for My Data. I Got Deletion Notices Instead

https://www.wired.com/story/i-demanded-my-data-from-over-100-companies-deletion-notices-started-a...
3•speckx•11m ago•0 comments

PlaytestQuest – Discord Quests for indie game devs and players

https://playtestquest.com
1•firmgrove•12m ago•0 comments

Gobwas/glob: a complete engine rewrite and v1.0.0 is finally here

https://github.com/gobwas/glob
1•gobwas•12m ago•0 comments

I created an extensible JavaScript parser

https://github.com/xjslang/xjs
1•GonzaloCV•13m ago•0 comments

Columnist: OpenAI and Anthropic are ruining San Francisco

https://www.sfgate.com/local/article/open-ai-anthropic-ruining-sf-22404657.php
2•walrus01•13m ago•0 comments

Let's Talk Roadmap Planning: Can 9 Women Make One Baby in One Month?

https://honestroadmaps.substack.com/p/lets-talk-roadmap-planning-can-9
1•mooreds•13m ago•0 comments

How to Write a Good Requirement– Checklist

https://www.nasa.gov/reference/appendix-c-how-to-write-a-good-requirement/
1•sturza•13m ago•0 comments

Florida Attorney General: We're not settling with Meta, we're going to court

https://www.youtube.com/watch?v=xCoYVusz1U8
1•root-parent•13m ago•0 comments

From Designed to Evolved Software

https://eakman.dev/from-designed-to-evolved-software/
1•dayflyer•14m ago•0 comments

Su-śrotā – Scholar-grade Sanskrit ASR

https://huggingface.co/prathoshap/sushrota-sanskrit-asr
1•yarapavan•14m ago•1 comments

Show HN: ContextSwitch – Make your LLM chats provider agnostic

https://contextswitch-blue.vercel.app/
1•rajtilakjee•15m ago•0 comments

SambaNova's SN50 RDU for AI at Hot Chips 2026 – ServeTheHome

https://www.servethehome.com/sambanovas-sn50-rdu-for-ai-at-hot-chips-2026/
1•rbanffy•15m ago•0 comments

Show HN: Repobeats – self-hostable GitHub activity cards in Rust

https://repobeats.com/
1•AprilNEA•16m ago•0 comments

Nvidia's DLSS 5 has leaked, and modders are creating uncanny nightmares

https://www.xda-developers.com/nvidia-dlss-5-has-leaked-modders-are-already-creating-uncanny-vall...
2•kuuuzya•18m ago•0 comments

Show HN: The Million Dollar Homepage, but it gets printed on an iPhone skin

https://www.skinoftheyear.lol/
1•codemersdev•18m ago•2 comments

The cheapest accommodation in Paris is disappearing: Here's why

https://www.cnn.com/travel/paris-chambre-de-bonnes-heat-climate
2•mooreds•18m ago•0 comments