Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.
CVSS is impossible to communicate effectively. We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.
> We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?
Yes. I believe that using CVSS scores as a first pass to decide which vulnerabilities to review is risky.
The most boring reason, even if you take CVSS scores at face value, is that in many cases it is possible to leverage multiple "low" severity vulnerabilities into a massive impact.
But the bigger reason is that CVSS scores are all over the place, and the people operating roulette wheel that generates them do not have any insight into any specific person's systems.
> These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary/alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.
You need to reason about both probability and impact, not one or the other. In your example, it just means that the probability is very low, perhaps even down to 0 in your specific case. But even at a low probability, the impact of the vulnerability remains very high so it helps you reason about it.
For example, you might react differently to these scores:
- <8/10: check that your systems are indeed secure
- 8.6/10: check that your systems are indeed secure and tell your junior analyst to train on creating a custom monitoring rule for that attack and follow-up with you
- 9.8/10: double-check that your systems are indeed secure, ensure that if you had a hole another security layer would have caught it (if not, that's a problem!), set up a honeypot to get some info on the assholes that have repeatedly attacked you lately and will undoubtedly try to 0-day you in the next few hours, etc.
I have no idea about the claim of a backdoor. But here is the source:
Matt Mackall:
"It's worth noting that the maintainer of record (me) for the Linux RNG quit the project about two years ago precisely because Linus decided to include a patch from Intel to allow their unauditable RdRand to bypass the entropy pool over my strenuous objections. "
The fact that Intel Bull Mountain (code name for Secure Key Technology), and NSA's BULLRUN program share the name "bull" is a complete coincidence. I'm sure.
On many systems like Raspberry Pi the <v5.6 kernel /dev/random or /dev/urandom lacked sufficient entropy to properly deploy wifi hostapd WPA2/WPA3 services.
Instead, people used haveged to workaround the issue. Not a conspiracy by some dude, but rather just more budget hardware limitations.
Don't worry about it, there are lots of real dubious things people do already. =3
Given that the overwhelming majority of Linux distros have moved to systemd, it's not clear why the pro-systemd camp would need to be finding or making opportunities to rally.
They're spending their time build and improving systemd's set of building blocks.
The drift, the gap between the advanced guard of seasoned enjoyers and the rest of the world that doesn't know what their missing feels like material that deserves coverage to me?
Just stay heads down and keep doing the world, don't share, dont socialize has been the plan so far in a lot of open source. And I think the outcomes would be better if we tried methodologies other than this. Freaking weird that this is just accepted.
You're not an outlier. The anti-AI stance is likely to be vocal online. They're quite incentivised to talk about it. Most programmers have adopted AI assisted programming (my own assertion) and most will feel like you and I, that it is useful. I know of a few programmers personally who hate it, but even they use it. There is no going back.
It is pretty obvious that when you come into a large incomprehensible codebase (which most are), AI will be able to reason about it more quickly and guide you through it.
I switched away from my work for a few minutes, but at the very moment I'm using AI to summarise some spaghetti code in a particular area in our codebase, so I can refactor it.
And that is my style of working at the moment. AI coding is useful, sometimes amazing, but sometimes irritating, and from experience I think just telling it to refactor this area would result in something I'm not happy with. So instead I'm getting a handle on it, I'll form the design I want, then tell it to do it. I have a feeling a lot of complaints are from people who won't bother to do that.
You are not an outlier. 40+ years of hobby and pro coding experience here and I absolutely love Claude Code. It enables me to dramatically increase code quality, performance, and features while still doing the fun parts and letting the LLM do the boring parts.
If you really loved horseback riding, or you really loved breeding and training horses, or you were really good at it, I'm sure that cars fucked up your day, and that it sucked to see cars replace horses.
I'm sure there were plenty of people who said that cars were horrible and that we should stick with horses. I'm equally sure there have been C programmers looking derisively at Python programmers, Python programmers looking derisively at Node programmers, etc etc.
But there's a pretty big gap between the feeling of unhappiness that something you liked is no longer as in-demand / profitable / common / whatever, and saying that cars aren't useful and we're all worse off for letting our horse-riding skills degrade.
Normal people didn't ride horses everywhere. They weren't used like cars. I'm so sick of this analogy. People walked places. If it was too far to walk you used a horse drawn bus/tram. If you had to much to carry you used a horse drawn truck. Every single person wasn't riding an individual horse ten minutes each way to buy groceries every day like that do now with cars. Cars unquestionably kill drastically more people than horses ever did or even could. Tens of thousands a year in this country alone! The leading cause of death for children and young adults!
We're pretty off track given that ya'll are nitpicking the metaphor rather than the actual topic, but claiming that horses were never common doesn't really have any connection to the claim that per-mile-moved / per-human-carried, horses are also dangerous.
Never use analogies when arguing online. It only ever results in exactly this, people nitpicking the metaphor. You've essentially given them a way to "be correct", about something irrelevant.
This does not get to the core of it, LLMs are not equivalent to cars.
All of your analogies (in other posts) discount that:
- LLMs are not deterministic
- they do not produce high quality/expert level output.
- They are not easy to control consistently.
Once again, and i mean this in the nicest way possible. You do not sound like you understand how things operate at an expert level of engineering. I do not know of any senior engineer who thinks LLMs can consistently produce quality output.
You are way too invested in your argument and refusing to see other perspectives
Because AI removes you from analytical thinking, and the brain is a muscle. The less you think, the less you are able to think.
Programming is inherently analytical and logic-driven. It’s a great brain exercise, even if the code has no value. When you use AI, you lose that exercise. What replaces it isn’t the same.
I mean, consider. I can solve a crossword, or I can ask AI to solve the crossword. AI will do it perfectly, and faster too. But which one is better for my brain? What was my goal with solving the crossword, anyway? On the surface it was to find a solution to the crossword. But, maybe, deeper down, the goal was to improve myself in some way.
People conflate the improvement of products with the improvement of self. Maybe it’s a result of our consumerist mindset. But the truth is the product can improve greatly, and you can be making it, while you yourself degrade.
We write better and better code, at a faster rate, but are we better programmers than before? Maybe, maybe not. I’m leaning maybe not.
It’s not new or unique. The assembly line is the same. Sure, I can build better furniture faster at the factory than by hand. But what is the goal here? Is it to make the best furniture, or to become the best carpenter?
If it’s to make the best furniture, the best product, then I’ve won. If it’s to become the best carpenter, then I’ve lost heavily.
The best carpenter obviously doesn't use any power tools. Are they allowed to use hand tools, or do they need to split the wood with their bare hands?
It's not clear to me why programming is inherently analytical and logic-driven but prompting and iterating with an AI is not. What about Applescript, where it's programming but in something closer to natural language?
The core of this seems to be that there are people who assume that users of AI turn their brains off the moment they open a Claude prompt. There are surely some people who are doing that, but there were also plenty of people who were shipping sloppy code before. There are far more people for whom this another tool in their toolbox.
Copyright, patent, and trademark law. The LLM firms misappropriated $9Tn of FOSS community work, ignored the license terms, and resell isomorphic plagiarism tokens to people getting farmed for more data.
If you still don't understand, than you don't understand how LLM are made.
Just because something is publicly accessible doesn't mean it is Public Domain. Having hosting people pay for the bots stolen bandwidth (or DDoS), is also theft of service under the law. =3
Distilling isn’t copying and redistributing, for the same reason that you reading a story and then writing your own story based on ideas you learned is different from you reading a book, writing all the words down verbatim, and then publishing it as your own.
At a certain scale, the relative complexity (both in terms of inventory management and dealing with upgrade requests / approvals / etc) tends itself towards picking a baseline spec that can work for the overwhelming majority of your fleet.
reply