frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Significant Raise of Reports

https://lwn.net/Articles/1065620/
49•stratos123•3h ago

Comments

stratos123•3h ago
"On the kernel security list we've seen a huge bump of reports. We were between 2 and 3 per week maybe two years ago, then reached probably 10 a week over the last year with the only difference being only AI slop, and now since the beginning of the year we're around 5-10 per day depending on the days (fridays and tuesdays seem the worst). Now most of these reports are correct, to the point that we had to bring in more maintainers to help us."
sevg•42m ago
Is there a reason you’ve copy pasted the first paragraph from the link? It doesn’t add anything to the discussion, and also doesn’t help as a tl;dr because it’s literally the first paragraph. Genuine question!
nayroclade•1h ago
> I don't know how long this pace will last. I suspect that bugs are reported faster than they are written, so we could in fact be purging a long backlog

Hopefully these same tools will also help catch security bugs at the point they're written. Maybe one day we'll reach a point where the discovery of new, live vulnerabilities is extremely rare?

Sharlin•1h ago
Around 70% of security vulnerabilities are about memory safety and only exist because software is written in C and C++. Because most vulnerabilities are in newly written code, Google has found that simply starting writing new code in Rust (rather than trying to rewrite existing codebases) quickly brings the number of found vulnerabilities down drastically.
glimshe•1h ago
The last paragraph is interesting: "Overall I think we're going to see a much higher quality of software, ironically around the same level than before 2000 when the net became usable by everyone to download fixes. When the software had to be pressed to CDs or written to millions of floppies, it had to survive an amazing quantity of tests that are mostly neglected nowadays since updates are easy to distribute."

Was software made before 2000 better? And, if so, was it because of better testing or lower complexity?

psyklic•1h ago
> Was software made before 2000 better?

At the time of release, yes. They had to ensure the software worked before printing CDs and floppies. Nowadays they release buggy versions that users essentially test for them.

dspillett•44m ago
Also in terms of security, there was generally a much smaller potential attack surface and those surfaces were harder to reach because we were much less constantly connected.
LatencyKills•1h ago
I was a developer at Microsoft in the 90s (Visual Studio (Boston) and Windows teams). I won't claim that software back then was "better," but what is definitely true is that we had to think about everything at a much lower level.

For example, you had to know which Win32 functions caused ring-3 -> ring-0 transitions because those transitions could be incredibly costly. You couldn't just "find the right function" and move on. You had to find the right function that wouldn't bring your app (and entire system) to its knees.

I specifically remember hating my life whenever we ran into a KiUserExceptionDispatcher [0] issue, because even something as simple as an exception could kill your app's performance.

Additionally, we didn't get to just patch flaws as they arose. We either had to send out patches on floppy disks, post them to BBSs, or even send them to PC Magazine.

[0]: https://doar-e.github.io/blog/2013/10/12/having-a-look-at-th...

empath75•16m ago
> Was software made before 2000 better?

Literally the moment everyone got on the internet, pretty much every computer program and operating system in the world was besieged by viruses and security flaws, so no.

Xenoamorphous•11m ago
Just think of 8 and 16 bit video console games. Those cartridges were expensive so just how sure they had to be they were bug free before making millions of them?
1970-01-01•5m ago
It was a simpler time. Not better. Not worse. Programs still had bugs, but they weren't sloppy UI bugs, they were logic bugs and memory leaks. If software was better back then, we'd still be using it!
themafia•1h ago
An AI enthusiast having a breathless and predictive position on the future of the technology? No way! It's almost like Wall Street is about to sour on the whole stack and there is a concerted effort to artificially push these views into the conversation to get people on board.

Then again, I'm a known crank and aggressive cynic, but you never really see any gathered data backing these points up.

dieulot•56m ago
Could you back up your assertion that Willy Tarreau — who used to maintain the Linux kernel — is “an AI enthusiast”? I can’t find anything about it.
logicprog•1m ago
Anyone who says anything good about AI must be an AI shill from the start, not someone who is genuinely observing reality or had their mind changed, don't you know?
logicprog•2m ago
> but you never really see any gathered data backing these points up.

https://www.anthropic.com/news/mozilla-firefox-security

?

Shank•1h ago
Important to note that this is a comment on this article: https://lwn.net/Articles/1065586/.
adverbly•1h ago
Anecdotally, I've been seeing a higher rate of CVEs tracked by a few dependabot projects.

Seems supported by this as well: https://www.first.org/blog/20260211-vulnerability-forecast-2...

Interesting that it's been higher than forecast since 2023. Personally I'd expect that trend to continue given that LLMs both increase bugs written as well as bugs discovered.

siruwastaken•53m ago
It's interesting to hear from people directly in the thick of it that these bug reports are apparently gaining value and are no longer just slop. Maybe there is hope for a world where AI helps create bug free software and doesn't just overload maintainers.
HAMSHAMA•52m ago
Probably related to this (genuinely interesting) talk given by an entropic researcher https://youtu.be/1sd26pWhfmg?si=j2AWyCfbNbOxU4MF
throwatdem12311•13m ago
Reports being written faster than bugs being created? Better quality software than before the 2000s?

Oh my sweet summer child.

This is some seriously delusional cope from someone who drank the entire jug of kool-aid.

I’d love to be proven wrong but the current trajectory is pretty plain as day from current outcomes. Everything is getting worse, and everyone is getting overwhelmed and we are under attack even more and the attacks are getting substantially more sophisticated and the blast radius is much bigger.

IBM Announces Strategic Collaboration with Arm

https://newsroom.ibm.com/2026-04-02-ibm-announces-strategic-collaboration-with-arm-to-shape-the-f...
122•bonzini•3h ago•72 comments

Sweden goes back to basics, swapping screens for books in the classroom

https://undark.org/2026/04/01/sweden-schools-books/
137•novaRom•1h ago•63 comments

Bringing Clojure programming to Enterprise (2021)

https://blogit.michelin.io/clojure-programming/
91•smartmic•4h ago•19 comments

Artemis II Launch Day Updates

https://www.nasa.gov/blogs/missions/2026/04/01/live-artemis-ii-launch-day-updates/
971•apitman•19h ago•821 comments

Leaked IRGC manual shows systematic use of civilian sites as missile cover

https://www.iranintl.com/en/202603319302
5•ukblewis•21m ago•1 comments

Lemonade by AMD: a fast and open source local LLM server using GPU and NPU

https://lemonade-server.ai
12•AbuAssar•1h ago•1 comments

Significant Raise of Reports

https://lwn.net/Articles/1065620/
49•stratos123•3h ago•20 comments

Gone (Almost) Phishin'

https://ma.tt/2026/03/gone-almost-phishin/
69•luu•2d ago•30 comments

Inside Nepal's Fake Rescue Racket

https://kathmandupost.com/money/2026/03/27/inside-nepal-s-fake-rescue-racket
8•lode•51m ago•0 comments

Mercor says it was hit by cyberattack tied to compromise LiteLLM

https://techcrunch.com/2026/03/31/mercor-says-it-was-hit-by-cyberattack-tied-to-compromise-of-ope...
74•jackson-mcd•1d ago•21 comments

Email obfuscation: What works in 2026?

https://spencermortensen.com/articles/email-obfuscation/
185•jaden•8h ago•59 comments

Enabling Codex to Analyze Two Decades of Hacker News Data

https://modolap.com/publication/hn-analysis-1
11•ronfriedhaber•1h ago•2 comments

Reinventing the Pull Request

https://lubeno.dev/blog/reinventing-the-pull-request
18•bkolobara•6d ago•16 comments

Quantum computing bombshells that are not April Fools

https://scottaaronson.blog/?p=9665
204•Strilanc•12h ago•66 comments

Steam on Linux Use Skyrocketed Above 5% in March

https://www.phoronix.com/news/Steam-On-Linux-Tops-5p
475•hkmaxpro•9h ago•229 comments

Telli (YC F24) is hiring engineers, designers, and more (on-site, Berlin)

http://hi.telli.com/join-us
1•sebselassie•5h ago

EmDash – A spiritual successor to WordPress that solves plugin security

https://blog.cloudflare.com/emdash-wordpress/
598•elithrar•20h ago•447 comments

Order and Tension

https://slab.org/2026/03/22/order-and-tension/
6•surprisetalk•3d ago•0 comments

New laws to make it easier to cancel subscriptions and get refunds

https://www.bbc.co.uk/news/articles/cvg0v36ek2go
74•chrisjj•3h ago•25 comments

Built a cheap DIY fan controller because my motherboard never had working PWM

https://www.himthe.dev/blog/msi-forgot-my-fans
42•bobsterlobster•2d ago•13 comments

Subscription bombing and how to mitigate it

https://bytemash.net/posts/subscription-bombing-your-signup-form-is-a-weapon/
191•homelessdino•8h ago•121 comments

A new C++ back end for ocamlc

https://github.com/ocaml/ocaml/pull/14701
199•glittershark•12h ago•18 comments

DRAM pricing is killing the hobbyist SBC market

https://www.jeffgeerling.com/blog/2026/dram-pricing-is-killing-the-hobbyist-sbc-market/
510•ingve•14h ago•452 comments

Fast and Gorgeous Erosion Filter

https://blog.runevision.com/2026/03/fast-and-gorgeous-erosion-filter.html
181•runevision•2d ago•17 comments

ReactOS Shows Improved Stability and 64-Bit Support at Chemnitz Linux Days 2026

https://old.reddit.com/r/reactos/comments/1sa26yu/back_from_chemnitz_linux_days_2026/
9•jeditobe•43m ago•1 comments

Show HN: Git bayesect – Bayesian Git bisection for non-deterministic bugs

https://github.com/hauntsaninja/git_bayesect
293•hauntsaninja•4d ago•42 comments

What Gödel Discovered (2020)

https://stopa.io/post/269
71•qnleigh•2d ago•11 comments

AI for American-produced cement and concrete

https://engineering.fb.com/2026/03/30/data-center-engineering/ai-for-american-produced-cement-and...
198•latchkey•19h ago•114 comments

A.I. Helped One Man (and His Brother) Build a $1.8B Company

https://www.nytimes.com/2026/04/02/technology/ai-billion-dollar-company-medvi.html
18•jbredeche•1h ago•5 comments

Reverse Engineering Crazy Taxi, Part 2

https://wretched.computer/post/crazytaxi2
57•wgreenberg•2d ago•5 comments