Hacker Newsnew | past | comments | ask | show | jobs | submit | akerl_'s commentslogin

So if I get a 9.8 that doesn't apply to my usage, what is the CVSS score doing for me?

Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.

CVSS is impossible to communicate effectively. We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.

This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.


> We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.

Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?


Yes. I believe that using CVSS scores as a first pass to decide which vulnerabilities to review is risky.

The most boring reason, even if you take CVSS scores at face value, is that in many cases it is possible to leverage multiple "low" severity vulnerabilities into a massive impact.

But the bigger reason is that CVSS scores are all over the place, and the people operating roulette wheel that generates them do not have any insight into any specific person's systems.


Yes. It's amazing how supposedly security professionals only take the base score "as is" and never adjust.

Many GUI CVSS calculators exist just for this, it takes a minute to requalify a vuln and adjust its CVSS based on your specific environment.

This one for example is pretty basic but works well: https://www.first.org/cvss/calculator/4.0

> These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary/alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.


You need to reason about both probability and impact, not one or the other. In your example, it just means that the probability is very low, perhaps even down to 0 in your specific case. But even at a low probability, the impact of the vulnerability remains very high so it helps you reason about it.

For example, you might react differently to these scores:

- <8/10: check that your systems are indeed secure

- 8.6/10: check that your systems are indeed secure and tell your junior analyst to train on creating a custom monitoring rule for that attack and follow-up with you

- 9.8/10: double-check that your systems are indeed secure, ensure that if you had a hole another security layer would have caught it (if not, that's a problem!), set up a honeypot to get some info on the assholes that have repeatedly attacked you lately and will undoubtedly try to 0-day you in the next few hours, etc.


Who?

I have no idea about the claim of a backdoor. But here is the source:

Matt Mackall: "It's worth noting that the maintainer of record (me) for the Linux RNG quit the project about two years ago precisely because Linus decided to include a patch from Intel to allow their unauditable RdRand to bypass the entropy pool over my strenuous objections. "

https://cryptome.wikileaks.org/2013/07/intel-bed-nsa.htm?utm...


That doesn’t read like a backdoor or like the community pushing somebody out.

The fact that Intel Bull Mountain (code name for Secure Key Technology), and NSA's BULLRUN program share the name "bull" is a complete coincidence. I'm sure.

You know there are people who actually reason this way.

On many systems like Raspberry Pi the <v5.6 kernel /dev/random or /dev/urandom lacked sufficient entropy to properly deploy wifi hostapd WPA2/WPA3 services.

Instead, people used haveged to workaround the issue. Not a conspiracy by some dude, but rather just more budget hardware limitations.

Don't worry about it, there are lots of real dubious things people do already. =3


Did you mean to comment this somewhere else? It doesn't really seem connected to this comment branch.

No, the recollection of /dev/random having an issue was correct, but attributing it the some malicious dude is wrong.

I don't like piling on people that engage in good faith. Best regards =3


Nobody in this thread has attributed anything to "some malicious dude".

You don't recall asking boltzmann64 for any details akerl_ ?

Perhaps it is time to get outside for a walk to lower stress levels. =3


I think you've pretty significantly misread the thread.

You forgot: =3

Given that the overwhelming majority of Linux distros have moved to systemd, it's not clear why the pro-systemd camp would need to be finding or making opportunities to rally.

They're spending their time build and improving systemd's set of building blocks.


The drift, the gap between the advanced guard of seasoned enjoyers and the rest of the world that doesn't know what their missing feels like material that deserves coverage to me?

Just stay heads down and keep doing the world, don't share, dont socialize has been the plan so far in a lot of open source. And I think the outcomes would be better if we tried methodologies other than this. Freaking weird that this is just accepted.


What criminal enterprise does getting private OpenAI repos fit into?

You’re already using a computer to automate massive amounts of what used to be manual human effort.

Why is using AI tools self-debasing or degrading?


I dont know how you can work in this discipline, use AI, and also ask that question.

almost every developer i know is fully aware, we are degrading every aspect of our skills.

The code writing, code reviewing, code understanding.

The more "time" passes and the more the code base grows, the more disconnected we become.


I guess I'm an outlier then.

AI has radically improved my ability to parse and understand new codebases, to validate my hypotheses, and to work in complex systems.

I wish I knew what I was doing differently than almost every developer.


You're not an outlier. The anti-AI stance is likely to be vocal online. They're quite incentivised to talk about it. Most programmers have adopted AI assisted programming (my own assertion) and most will feel like you and I, that it is useful. I know of a few programmers personally who hate it, but even they use it. There is no going back.

It is pretty obvious that when you come into a large incomprehensible codebase (which most are), AI will be able to reason about it more quickly and guide you through it.

I switched away from my work for a few minutes, but at the very moment I'm using AI to summarise some spaghetti code in a particular area in our codebase, so I can refactor it.

And that is my style of working at the moment. AI coding is useful, sometimes amazing, but sometimes irritating, and from experience I think just telling it to refactor this area would result in something I'm not happy with. So instead I'm getting a handle on it, I'll form the design I want, then tell it to do it. I have a feeling a lot of complaints are from people who won't bother to do that.


You are not an outlier. 40+ years of hobby and pro coding experience here and I absolutely love Claude Code. It enables me to dramatically increase code quality, performance, and features while still doing the fun parts and letting the LLM do the boring parts.

Not getting distracted by water-cooler talk about how AI is going to take your job and that the end times are around the corner, presumably.

Our horse riding skills have degraded even more.

Jokes aside, I think this gets at the core of it.

If you really loved horseback riding, or you really loved breeding and training horses, or you were really good at it, I'm sure that cars fucked up your day, and that it sucked to see cars replace horses.

I'm sure there were plenty of people who said that cars were horrible and that we should stick with horses. I'm equally sure there have been C programmers looking derisively at Python programmers, Python programmers looking derisively at Node programmers, etc etc.

But there's a pretty big gap between the feeling of unhappiness that something you liked is no longer as in-demand / profitable / common / whatever, and saying that cars aren't useful and we're all worse off for letting our horse-riding skills degrade.


Lots more people die in car crashes than horse accidents. Good analogy!

Do they? Horses aren't particularly safe, there's just way fewer of them and they don't travel as many miles.

Normal people didn't ride horses everywhere. They weren't used like cars. I'm so sick of this analogy. People walked places. If it was too far to walk you used a horse drawn bus/tram. If you had to much to carry you used a horse drawn truck. Every single person wasn't riding an individual horse ten minutes each way to buy groceries every day like that do now with cars. Cars unquestionably kill drastically more people than horses ever did or even could. Tens of thousands a year in this country alone! The leading cause of death for children and young adults!

We're pretty off track given that ya'll are nitpicking the metaphor rather than the actual topic, but claiming that horses were never common doesn't really have any connection to the claim that per-mile-moved / per-human-carried, horses are also dangerous.

Never use analogies when arguing online. It only ever results in exactly this, people nitpicking the metaphor. You've essentially given them a way to "be correct", about something irrelevant.

I'm not nitpicking, it's just a bad metaphor, entirely, on its face. No nits about it

Do you have something you want to discuss about the actual point I’m making, or are you acting strictly on behalf of the metaphor police?

They are nowhere close to cars


This does not get to the core of it, LLMs are not equivalent to cars.

All of your analogies (in other posts) discount that: - LLMs are not deterministic - they do not produce high quality/expert level output. - They are not easy to control consistently.

Once again, and i mean this in the nicest way possible. You do not sound like you understand how things operate at an expert level of engineering. I do not know of any senior engineer who thinks LLMs can consistently produce quality output.

You are way too invested in your argument and refusing to see other perspectives


It seems really convenient for you to speculate about my level of expertise so that then you can make claims that no senior engineers think something.

Because AI removes you from analytical thinking, and the brain is a muscle. The less you think, the less you are able to think.

Programming is inherently analytical and logic-driven. It’s a great brain exercise, even if the code has no value. When you use AI, you lose that exercise. What replaces it isn’t the same.

I mean, consider. I can solve a crossword, or I can ask AI to solve the crossword. AI will do it perfectly, and faster too. But which one is better for my brain? What was my goal with solving the crossword, anyway? On the surface it was to find a solution to the crossword. But, maybe, deeper down, the goal was to improve myself in some way.

People conflate the improvement of products with the improvement of self. Maybe it’s a result of our consumerist mindset. But the truth is the product can improve greatly, and you can be making it, while you yourself degrade.

We write better and better code, at a faster rate, but are we better programmers than before? Maybe, maybe not. I’m leaning maybe not.

It’s not new or unique. The assembly line is the same. Sure, I can build better furniture faster at the factory than by hand. But what is the goal here? Is it to make the best furniture, or to become the best carpenter?

If it’s to make the best furniture, the best product, then I’ve won. If it’s to become the best carpenter, then I’ve lost heavily.


The best carpenter obviously doesn't use any power tools. Are they allowed to use hand tools, or do they need to split the wood with their bare hands?

It's not clear to me why programming is inherently analytical and logic-driven but prompting and iterating with an AI is not. What about Applescript, where it's programming but in something closer to natural language?

The core of this seems to be that there are people who assume that users of AI turn their brains off the moment they open a Claude prompt. There are surely some people who are doing that, but there were also plenty of people who were shipping sloppy code before. There are far more people for whom this another tool in their toolbox.


> But, maybe, deeper down, the goal was to improve myself in some way.

Or, you know, to pass some time in an enjoyable way. To have fun.


Am I missing something? You posted that you wanted to be hired, some job placement firms reached out, referencing your post.

> Readers: please only email these addresses to discuss work opportunities.

Yes, you are missing the ground rules.


How is a hiring platform reaching out to you not related to work opportunities?

There is a not so thin line between "direct job offer" and "spam from job boards".

I'd be in favor of a more updated rule saying "direct job offer". But the post as it currently exists seems to not make that distinction.

How is an invitation to participate in a job board SaaS a "work opportunity"? Let's get real here; it's crystal clear.

It doesn't "work adjacent topics". It says "work opportunities". AKA, a JOB.


There are people commenting parallel to you saying they are upset about AI companies scraping the web.

Because of the request load though. The ethical thing is separate.

Yeah I dont think they know why they think that.

Copyright, patent, and trademark law. The LLM firms misappropriated $9Tn of FOSS community work, ignored the license terms, and resell isomorphic plagiarism tokens to people getting farmed for more data.

If you still don't understand, than you don't understand how LLM are made.

Just because something is publicly accessible doesn't mean it is Public Domain. Having hosting people pay for the bots stolen bandwidth (or DDoS), is also theft of service under the law. =3


Are they distilling?

Distilling isn’t copying and redistributing, for the same reason that you reading a story and then writing your own story based on ideas you learned is different from you reading a book, writing all the words down verbatim, and then publishing it as your own.


Distilling is reverse engineering. It is literally copying someone else.

That's not what distilling is either. Distilling is training your AI to exactly copy someone else's AI.

> Who do I call if I think Flock is stalking me

Your local representative who signed a contract with Flock to install and operate the cameras?


So, complain to the stalker?

At a certain scale, the relative complexity (both in terms of inventory management and dealing with upgrade requests / approvals / etc) tends itself towards picking a baseline spec that can work for the overwhelming majority of your fleet.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: