9 comments

  • usernomdeguerre 18 hours ago
    Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

    From his Kernel Recipes 2026 slide on Mythos

    ```

      Mythos's 79 vulnerabilities:
      24 - no detail at all "something crashed"
      14 - not a bug at all
      3 - totally made up data
      15 - already fixed in latest release
        - 11 by others
        - 4 by anthropic
      20 - fixes were needed
        - 7 "assume a malicious filesystem image"
        - 2 "assume you can inject a malicious network packet into the middle of the stack"
        - 2 "NOMMU"
        - 6 sctp networking issues for untrusted devices
        - 2 ipv6 minor network issues 
        - 1 gpu driver for local malicious user
    
    ```

    GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

    • OtherShrezzing 2 hours ago
      We’ve seen this in a few open source repos we voluntarily manage security on. They’re not massive repos, but big enough they get attention from security researchers.

      Most of the real low hanging fruit was picked up by humans years ago. When doing automated scanning, the majority of stuff is overly-verbose nonsense which takes hours of expert human labour to understand, test, and discard.

      Reading through a Claude generated false positive is absolutely excruciating, because it is absolutely determined that what it’s found is justified. Often you’ll receive very long accompanying “proof of concept” code which demonstrates absolutely wild scenarios. It’s especially frustrating when you’re volunteering your time for a project, and a well-meaning contributor submits the report without the technical nous to understand why you’re rejecting it.

      • b112 53 minutes ago
        Right now, all top tier LLMs are as eager, bright 20ish year old interns.

        Very gung ho, full of energy, loads of book learning, no real world experience or understanding of why things are as they are.

        Leave them to their own devices at your peril. Trust nothing they do.

        Yet directly guide them, monitor everything they do, some value emerges.

        • charcircuit 37 minutes ago
          Have you used a frontier model since 2025? You are underplaying their strength.
          • fc417fc802 26 minutes ago
            Okay so now they're like a top percentile fresh grad on meth. Still a lack of real world experience plus some bizarre failures that illustrate gaping holes in the mental model. Does that description work for you?
          • 12376 20 minutes ago
            Kroah-Hartmann has used the closed frontier++ model, and it made up 37 out of 76 vulnerabilities.
    • FLeXMurphy 15 minutes ago
      Tightening molecular vortices...

      Zip-zapping the bouzouki...

      Exfiltrating nuclear arm codes...

      Thought for 76 seconds.

      You're right to push back on that. That's on me.

    • p-o 2 hours ago
      It also adds up to 76, which he made fun of in the video. LLM can't count, his words, not mine. Although, I tend to agree with him!
    • Betelbuddy 45 minutes ago
      Or the people of Anthropic, just really suck at coding, and are scared or their own models due to ignorance.
    • gregw2 1 hour ago
      What a great excerpt; thank you! It reminds me of what I find when I look at CVEs handed out by scanners at places I've worked for actual impact to systems I've owned... there are a lot of slop/false positives. (And that's even without "AI".)

      That said, I remember trying to weigh the hype at the time of the announcement reading/skimming the papers Anthropic published, recognizing that bugcount alone wasn't super-relevant but also remember being impressed by an NFS bug and a kernel bug that struck me as relevant at the time. So where did that NFS issue show up in GKH's list you showed so nicely above?

      It turns out, AFAICT, it's not on his list, but the reasons are perhaps interesting to others so I will post here. It turns out there were two NFS issues this past year conflated a bit in my memory:

      * The Linux CVE-2026-31402 NFS heap overflow that could allow unauthenticated memory reads over the network isn't in that list of 79, presumably because it was found by Claude Code, not Mythos months earlier. (I am guessing it's not his "malicious network packet into the middle of the stack" and is a stronger attack being a remote attack.)

      * And the CVE-2026-4747 NFS stack buffer overflow that allowed gaining full unauthenticated remote root access didn't show up in GKH's list of 79 because despite being Mythos-caught, it wasn't Linux, it was FreeBSD.

      I guess this does match my memory now that I think about it, that there weren't any smoking Linux guns caught by Mythos.

      * (I guess there was also a longstanding 27-year old OpenBSD TCP SACK-handling stack integer overflow than enabled remote crashes / Denial of Service found by Mythos.)

      There is definitely Mythos hype, but just because it hit the BSD code base more than the GKH-managed Linux code base doesn't mean it was inappropriate to raise eyebrows from Mythos, in particular since "attacks only get better".

    • cyanydeez 50 minutes ago
      AI and Police have essentially the same journalists who, in lieu of any research or fact checking, just report verbatim their press releases and interviews.
  • devy 1 hour ago
    At 3m19s Greg KH revealed what Mythos did in "revealing" 79 CVEs - pure pattern matching the previous decades of kernel developer's patches, and applying those mechanisms elsewhere to see if they have been universally patched. And Anthropic didn't cite Kernel Developers who original fixed/patched the CVEs like a decent human being would do. So yeah, Anthropic has the same problem OpenAI had for citing original work.
  • Aissen 27 minutes ago
    Nice to see Kernel Recipes covered again on HN. Shameless plug: I do the live blog: it's incomplete, imperfect and has typos; but it's written and published during the presentations. On this talk : https://kernel-recipes.org/en/2026/2026/09/22/live-blog-day-...
  • sriram_sun 1 hour ago
    He also said that it all boiled down to just one hour of kernel development work.
    • Betelbuddy 41 minutes ago
      Sam Altman said GPT-3 was too scary to release, a crappy old internal version of Gemini was "conscious", Mythos had Amodei going to see the Pope...

      Wake me up when Raspberry Pis start refusing to open doors saying : "I'm sorry, Dave. I'm afraid I can't do that."

      • tamimio 15 minutes ago
        No no, the word wasn’t conscious, it was “sentient”, and google fired the employee because he uncovered the top secret crazy scary AI!!!!

        It’s all just pr stunts, fear spread fast and it’s very effective in marketing and spreading the word, which is effective, when I talk to some normal people they immediately bring the scary AI cyber attacks, kinda good as now all are willing to fund the industry!

  • blinkingled 2 hours ago
    It's great to hear about $topic from someone no-nonsense and in-the-know like Greg KH. You can verify all of this too - since, well Linux kernel. (As opposed to what Microsoft or Apple claims to fix as far as LLM finds.)

    Mythos may not be great today but it is not far fetched to imagine bug discovery, analysis and fixes can be made much quicker, accurate and even newly possible with specialized models trained on say Linux kernel specifics - with codemap/coding standards/threat models, good and bad coding patterns, tools to validate etc. an LLM can be much more relentless than humans and if it has the help to be accurate it will be worth the electricity burned. Oh and another model trained on triage data to validate the first one's findings would be good.

    (I think Microsoft is doing this internally - different models trained internally alongside Mythos - there was some talk about it on the tubes, don't recall where exactly.)

  • 1sgT15 1 hour ago
    Finally it is official. Mythos was overhyped and overrated.
  • FLeXMurphy 1 hour ago
    We've flagged this submission as off-topic. Please follow the submission guidelines. Topics around, for example, how Anthropic LLM escaped containment and will end the world are what hackers are curious about. The linux kernel on the other hand is not. Thanks.
  • IndiaInfraNotes 17 hours ago
    [dead]
  • sippingabonedry 1 hour ago
    [flagged]