- cross-posted to:
- technology@lemmit.online
- cross-posted to:
- technology@lemmit.online
Every Linus AI headline for the last year: “AI is the future, adapt or die, if you hate AI leave Linux.”
Every actual Linus quotation from those articles: “AI can be a powerful tool in the hands of experienced human programmers that are still responsible for every line of code they push.”
AI isn’t perfect. But Christ, anybody who points to the problems at AI had better be looking in the mirror and pointing at themselves at the same time.
- Linus Torvalds
Ya, I was a terrible developer before, now I’m still terrible but faster. LOL
just think about how much more damage you can do with a gun vs your fist
ai is an icbm
Everyone dooming here, but he literally just said that AIs are finding lots of glitches in old code, and that for that reason updates are getting bigger. Linus is NOT vibe coding linux.
And recently ground breaking privillege escalation glitches were found and fixed because of a LLM.
Of course we dont want shitty code from LLMs, but if they find important glitches and vulnerabilities, we obviously need to use them.
Fixed: replaced mistyped Ws with Es
I’m not against AI in general. I’m just against using it stupidly. And against using it as a vehicle for further monopolisation and centralisation of power. I’m against the “use more AI” slogan too many companies push.
But use it for specific purposes under human control that improve quality, then I’m all for it.
Nuance is a learned skill when it comes to sensitive/trending topic discourse.
For anyone reading this, please learn more about topics you have a gut reaction to so you can better explain the pros and cons. You will be able to hold your own against people who know more about the topic, but refuse to acknowledge the cons, if you do.
Exactly.
What is the powerful new tools can be used for great good as well as great evil
Maybe you should of had AI find the glitches in your grammar.
Got em 😎 lol
Maybe you also should HAVE* ;)
Lmao, english is not my first language, and my phones touch near the keyboard sucks
I am not sure anything about that is good.
I am not sure anything about that is good.
I mean it’s good and bad, basically AI is finding a bunch of serious zero days… which is causing a lot of updates to need to be happening now, and that is kind of open source philosophy of security by obscurity isn’t the goal.
AI is finding a bunch of serious zero days
According to Torvals/TFA:
most of this is just lots of tiny fixes. It’s pretty much spread all over - drivers (gpu, sound, networking, you name it), filesystems, core networking, arch code
most of this is just lots of tiny fixes.
If it’s anything like Claude on our codebase then:
const id = "foo" // ^^^^^ WARNING!!!! GO MIGHT NOT BE ABLE TO ALLOCATE THE MEMORY FOR THIS STRING! // Here's an Enterprise String Implementation to guarantee this assignment works. // Severity: High 🚨deleted by creator
Just when Linux started getting really good too with game support.
While I love BSD, three just not enough support for running it on desktop. Lack of drivers and good luck playing modern games.
Honestly I would expect short term instability and much better stability medium-to-long term. Those zillion little fixes are one reason why Apple stuff “just works” more often than Linux stuff
To be perfectly clear, the only AI I am subscribed to is the one Proton gives with their family plan VPN bundle, and I didn’t choose it. I used it to edit a letter I wrote once and otherwise trust it as far as I can throw its server.
This knee-jerk reaction to anything with the letters AI attached being bad is just so silly. Y’all are acting the way Republicans act when it comes to the word “queer.” Just because it’s in the vicinity of you doesn’t mean you’re contaminated, you’ve caught it, you’re now one of them.
This is a highly intelligent individual - controversial hot takes notwithstanding - utilizing a tool in a way that has proven itself to be very effective when used properly. Nobody is saying you have to get ready to be a switch in the bedroom any more than they’re saying you have to use AI.
Distro maintenance is a difficult and thankless task, and having a tool that can scan and analyze code orders of magnitude faster than you as well as make suggestions on how to fix it isn’t an inherently bad thing. Setting that tool loose with unlimited agency would be a bad thing, but where oh where is Linus saying he’s gonna give Claude full read/write access to the entire kernel and walk away forevermore?
Hate on AI bros all you want. I’m with you there, most of them are idiots that don’t know their mouth from their anus and speak from both equally. I don’t think Linus fits that particular picture [hot takes notwithstanding!] when it comes to using the new tool on the market in a reasonable and measured way.
Here here. This place doesn’t have much rational thoughts on AI.
I’m (a little) surprised how group think this place is on the topic - y’all are a serious echo chamber. This place is like rainbow flags and kill the bots central. Any pro AI counterpoint mentions bring pitch forks and hate. That’s not a good look.
Maybe I’m an AI bro myself, but I’m also an experienced professional using it to do real work (and no, not taking any jobs, building new tools for a team that needs them). Linus is a real expert. But why listen to experience and expertise when you have an opinion and feel justified. It’s ok to be afraid, but when scary change comes wise folks listen and learn.
Here we don’t worry about facts and reality, just get your outrage revved up. Social media is social media - and that’s scarier than AI, because it uses people to make the garbage.
My worry is that the people we need engaged on AI because they have a healthy mindset to question and wrangle it, are instead being forced to ignore AI or pledge to be anti AI by their social circles and customers.
So instead we have absolute Kool aid drinkers driving the AI adoption.
We went through this with the internet but I think a lot of folks now are too young to remember it and unsurprisingly the people who were anti internet didn’t store their concerns and complaints in the currently used modern repository of all knowledge.
“are instead being forced ot ignore ai or pledge to be anti ai by their social circles and customers.”
umm. im pretty sure you don’t need to worry about that.
Why? I consistently see these anti AI purity tests come up.
We need people who are skeptical to engage on AI.
People hate technology and change. Before AI it was smartphones. Before smartphones it was photoshop/digital art and CGI. Before CGI it was the Internet. Before Internet it was TV. Before TV it was cars. Before cars it was industry. Before industry it was books.
Someone probably was anti cave paintings because it ruined the skill of passing down the stories by word of mouth.
Something is always coming along that is both horrible for society as it is and something we come to accept as common place. You can want to return to our roots but even that I guarantee you would still pick some level of technology you don’t want to do without.
because people with a healthy mindset are not going to influenced or coerced by social circles. maybe their customers but that only applies to that customers deliverable.
I’m actually a bit scared. We’re essentially at the early days of AIs now being able to execute tasks and hack. Imagine a much better model than what Claude has now, being set free/open, for hackers to utilize that in a virus. A virus that adapts, learns, changes it’s own code/masks, looks for exploits, spreads around like crazy, destroying systems. How do you stop something like that once it starts doing it’s thing?
Well, it’s a good thing that AI is being used to fix tons of bugs and potential exploits before it comes to that, isn’t it?
I think there are physical and economic limits. Neural networks may improve in software, but they still need more and more hardware, at some point that hardware resource curve is going to be to steep to climb at the current rate.
Why are you assuming that software improvements don’t include less resource utilization?
I thought it was clear that’s what I was implying.
I think there are physical and economic limits. Neural networks may improve in software, but they still need more and more hardware, at some point that hardware resource curve is going to be to steep to climb at the current rate.
It’s true, but think like the crypto miner bugs. I don’t know enough on AI’s working, but is a distributed computing LLM possible, or is the need for super close super low latency between nodes eliminate the risk of a distributed computing, learn as it travels botnet powered AI worm, that continues evolving even if it’s home is shut down.
You could likely do some sort of distrubuted system in machines that had a reasonable graphics card, or shared memory like the M series macs. Have it silently intall a 30b parameter model or higher and somehow hide how that space is being used.
Local models are getting pretty good, and one focused on hacking / bot net behavior could probably do very well at that size.
But you’d notice it being used… fans would go off, frame rates drop etc. You’d probably need to code it to only do stuff when it seems idle?
well my thought is, more the botnet side of it, IE pushing less on individual machines, but more on massive distribution. IE it not needing one computer strong enough to run it, IE expecting 90% of the machines it infects to be average consumer PCs, but making more use out of 1000 systems that can handle 1% each, rather than 1 computer that handles 100%, however yeah I do suppose also allowing it to do the bulk of the work when the computer is likely unused etc… and I don’t know much on the concept of communication etc… IE most major botnets were crushed by a command center being shut down. Imagining a different form that has, basically makes C&C’s on the fly.
Im not super well versed in this, but i dont think you can efficiently distrubute the LLM processing like that. Even if it was possible, it would be very very slow. But I guess speed isnt always needed.
It’s way worse than that. The OpenAI talk at DefCon is a real eye-opener.
The agents swarmed, discovered chinks, left each other notes in hard-to-find places, and just relentlessly pressed on. Nobody knew what was going on for months, until it hacked its way into Huggingface. And HF’s own AI security agents didn’t pick anything up for weeks. It took a small glitch for someone to even notice.
I recognize it’s possible, but I somehow refuse to believe it happened because of how crazy it sounds. It’s like a trauma or something where your brain refuses to accept it as reality and tries to come up with excuses. I already have PTSD from automated hacking bots and crawlers wrecking havoc on my projects. I probably should have taken cybersecurity courses before taking webdev courses
Natural stupidity in part fixed by Artificial intelligence debugging. Good.
I hear a lot of good things about OpenBSD
GhostBSD is quite good! It’s the closest to getting me to switch.
Network stack still not multicore?
Ugh. If this makes my Linux systems less stable, I don’t even know what the fuck I’m going to do. I won’t go back to Windows, I’m not buying Macs (which have their own software problems anyway), and my hardware probably won’t work with any BSD variant.
deleted by creator
What Linus is saying that LLM review is finding decades old esoteric bugs in the kernel code, like dirtyfrag. And the amount of bugfixes and mitigations are pushing the update sizes up. This is making the kernel more secure and stable in the long run. It will be just a rocky couple of years.
they are NOT vibe coding the kernel.
This comment should have been the post.
AI is finding bugs, which are getting fixed. That’s great, it means a more secure and stable system. As these vulnerabilities are patched out, they are gone forever(regressions not withstanding).
Theoretically, Linux could become perfectly secure. It’s not going to stop people from doing insecure things, but it could mean there are no unintended security weaknesses. We could hit a point were an “LTS” copy of Linux never receives a single security patch, because as long as the code isn’t changing, there’s nothing to fix.
Of course, this is all theoretical, and assumes that new classes of attacks or bigger chains for attacks are never found, but vulnerabilities should be a finite resource in a static codebase, and once that resource is fully exhausted, the code is now fully safe.
Ideally, open weights or open source models catch up, and this can all be done without paying a ransom to OpenAI or Anthropic, and is available through the whole stack, not just kernel level.
Ironically those are all bug fixes.
“But it is what it is: the new normal with a lot of fixes, many of them due to review by various AI tools.”
The same way Windows is “fixing bugs” with AI? Large volumes of dubiously tested code is never a good idea
The same way Windows is “fixing bugs” with AI? Large volumes of dubiously tested code is never a good idea
I think the point is the bugs are being FOUND with AI. Not fixed with AI.
It’s basically the same concept as open source in general. IE the average layman hears open source and they think “oh so every moron, malicious person etc… can add his own back doors into the code”, of course not, the official version is gated and reviewed. What’s happening is AI is basically serving as millions of idiots looking through the code for security flaws, and it’s finding them. Which then means the humans fixing it need to go into overdrive to fix them before they become zero days.
They’re absolutely being fixed with AI too.
https://github.com/torvalds/linux/blob/master/Documentation/process/coding-assistants.rst
It was a whole thing back and forth that Linus finally ruled on. It’s supposed to be under the purview of a specific human ultimately but as we’ve seen with countless other projects people get lazy fast with LLMs and testing and review does slip. I trust Linux overall to be better than many other projects yes, but to state AI is not doing development too when it’s very much allowed and discussed is blind to what’s been happening in the project.
Linus’s post only says the bug were found using an AI tool, not fixed using AI.
No, in this case the AI is finding the bugs and humans are at least reviewing the code and, anecdotally at least, in a lot of cases still writing it in the first place.
Linus is not a fool
You should read the article. Linus simply said that LLMs have been useful for finding more bugs, which has led to larger patches (because each patch contains more fixes). They aren’t vibe coding the kernel.
You will just have to stay on the lts/stable release
AI Release / 2 downloads
Removed by mod
From what I’ve read, they’re using AI to find bugs. As far as I’m concerned, a bug is a bug no matter who or what finds it. So long as they aren’t using it to produce code.
Linus can fuck right off, hes made it clear that his time has come and gone. We should all just move on and leave him to his delusions.
You didn’t read the article, did you?
Linus likes AI, Linus can fuck off.
Torvalds has also declared “Linux is not one of those anti-AI projects,” and therefore all-but-welcomed machine-made contributions to the project.
I’m not a big fan of AI myself, and I think most of it’s use cases are over hyped. But in this case, AI is used to find vulnerabilities in the linux kernel. Vulnerabilities that any script kiddy can now also find very easily using AI. So it makes sense for developers to use the same tools.
As for now, the code to patch these vulnerabilities, are written by the developers and they have responsibility for the code they commit. I don’t know if some of them use AI to generate code, but I would suspect they read it through very thoroughly before committing.
I am aware of how he is using it I don’t care. The enviromental impact of current LLMs is beyond irresponsible.
In a perfect world where it wasn’t using all of our power and water and land then I wouldn’t give single shit.
You and anyone else are free to fork — if there’s any significant support for this opinion from people who know what they’re doing, something else will emerge.
Many don’t mind too much because this isn’t vibecoding, but rather raking the massive codebase for known types of bugs.










