7 comments

  • usernomdeguerre 16 hours ago
    Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

    From his Kernel Recipes 2026 slide on Mythos

    ```

      Mythos's 79 vulnerabilities:
      24 - no detail at all "something crashed"
      14 - not a bug at all
      3 - totally made up data
      15 - already fixed in latest release
        - 11 by others
        - 4 by anthropic
      20 - fixes were needed
        - 7 "assume a malicious filesystem image"
        - 2 "assume you can inject a malicious network packet into the middle of the stack"
        - 2 "NOMMU"
        - 6 sctp networking issues for untrusted devices
        - 2 ipv6 minor network issues 
        - 1 gpu driver for local malicious user
    
    ```

    GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

    • OtherShrezzing 48 minutes ago
      We’ve seen this in a few open source repos we voluntarily manage security on. They’re not massive repos, but big enough they get attention from security researchers.

      Most of the real low hanging fruit was picked up by humans years ago. When doing automated scanning, the majority of stuff is overly-verbose nonsense which takes hours of expert human labour to understand, test, and discard.

      Reading through a Claude generated false positive is absolutely excruciating, because it is absolutely determined that what it’s found is justified. Often you’ll receive very long accompanying “proof of concept” code which demonstrates absolutely wild scenarios. It’s especially frustrating when you’re volunteering your time for a project, and a well-meaning contributor submits the report without the technical nous to understand why you’re rejecting it.

    • p-o 54 minutes ago
      It also adds up to 76, which he made fun of in the video. LLM can't count, his words, not mine. Although, I tend to agree with him!
  • sriram_sun 31 minutes ago
    He also said that it all boiled down to just one hour of kernel development work.
  • blinkingled 45 minutes ago
    It's great to hear about $topic from someone no-nonsense and in-the-know like Greg KH. You can verify all of this too - since, well Linux kernel. (As opposed to what Microsoft or Apple claims to fix as far as LLM finds.)

    Mythos may not be great today but it is not far fetched to imagine bug discovery, analysis and fixes can be made much quicker, accurate and even newly possible with specialized models trained on say Linux kernel specifics - with codemap/coding standards/threat models, good and bad coding patterns, tools to validate etc. an LLM can be much more relentless than humans and if it has the help to be accurate it will be worth the electricity burned. Oh and another model trained on triage data to validate the first one's findings would be good.

    (I think Microsoft is doing this internally - different models trained internally alongside Mythos - there was some talk about it on the tubes, don't recall where exactly.)

  • 1sgT15 24 minutes ago
    Finally it is official. Mythos was overhyped and overrated.
  • IndiaInfraNotes 16 hours ago
    [dead]
  • FLeXMurphy 21 minutes ago
    [flagged]
  • sippingabonedry 22 minutes ago
    Someone run to Costco and get Greg a pack of normal-sized shirts, please.

    It looks like he fished it out of the lost+found 5 minutes before the talk because he got mustard on his real shirt.