|
|
Log in / Subscribe / Register

Security quote of the week

So this brings us to Linus's Law. It seems pretty clear now that nobody was in fact looking at the code. If they were, they would have found vulnerabilities in everything. But the number of people finding and reporting vulnerabilities was pretty small. It is hard to find security vulnerabilities as a human, but the whole point wasn't that a few very smart people were looking for bugs, the point was a sort of infinite monkey theorem of bug finding.

It would be easy to proclaim LLMs as our infinite eyeballs, but it's more complicated than that. While LLMs might be able to find vulnerabilities, the real challenge is going to be reporting and coordinating all of these new findings. Even without an LLM the disclosure process was always a thousand times more work than finding the security vulnerability.

The new version of Linus's Law should read something like

With enough LLMs, you're going to be disclosing this stuff forever

The next few years are going to be wild. Anyone telling you they know how to deal with this is full of crap. Nobody knows what to do and this is a human problem, we can't technology our way out of this.

Josh Bressers



to post comments

I don't think we will...

Posted May 1, 2026 12:45 UTC (Fri) by alex (subscriber, #1355) [Link]

It's certainly the case that LLMs are proving increasingly useful for code review but I suspect it will be like the introduction of fuzzers, static analysers and sanitizers. There will be a wave of reports, things will get added to CI loops and eventually things will settle down to a new baseline of safety.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds