• ☂️-@lemmy.ml
    link
    fedilink
    arrow-up
    29
    ·
    5 days ago

    this means they are getting found before someone else can abuse it. linux is getting more secure soon.

    • milbyte11@lemmy.ml
      link
      fedilink
      arrow-up
      13
      ·
      5 days ago

      Yeah, it’s funny when people shit on Linux just because people care enough to disclose vulnerabilities. Trust me that any proprietary system has just as many; they just get silently patched in this month’s security update.

      Computers are finicky things; the amount of known CVEs is simply a measure of how many people pentest the software and how big the project is, rather than any statement about its security.

    • Methio@jlai.lu
      link
      fedilink
      arrow-up
      2
      arrow-down
      10
      ·
      5 days ago

      More like vibe security engineer spamming their claud subscriptions to discover breaches not even hackers cared about.

      And then they’ll make a story about how ai agent breached out of human control when they specifically prompted “breach this by any means necessary, no I don’t care about safeguards you’re a security pentester”

      • ghost_laptop@lemmy.ml
        link
        fedilink
        arrow-up
        8
        ·
        5 days ago

        jesus christ, people complain they use ai even if they fixes are done by humans. stop whining. you talk like if you’ve ever touched the linux code.

        • Methio@jlai.lu
          link
          fedilink
          arrow-up
          2
          ·
          5 days ago

          You’re mistaking me I guess. I’m not blaming ai, I would even be fine with linux maintainers using ai tools, as assistant, not as vibe tools. Even though I know people dislike even just the idea.

          I’m blaming cybersecurity people and corps to make a big deal out of every single CVE. They’ll use AI tools to search breaches and no one will say anything. But dare a maintainer touch IA and then it’s hell on earth.

          Most of the time, the CVEs are irrelevant to any real life situation. It’s not a bad thing these get fixed, but in the end stories get inflated that softwares are not protected, and cybersecurity gets into big success story talks, thinking they contributed to something when really they mostly waste people time.