logoalt Hacker News

Greg Kroah-Hartman – Security in the LLM Age [video]

136 points • by usernomdeguerre • today at 2:51 AM • 29 comments • view on HN

Comments

usernomdeguerre • today at 3:01 AM

Greatly appreciated the candor. I've included a few slides into text that i thought were eye-opening to me:

From his Kernel Recipes 2026 slide on Mythos

```

  Mythos's 79 vulnerabilities:
  24 - no detail at all "something crashed"
  14 - not a bug at all
  3 - totally made up data
  15 - already fixed in latest release
    - 11 by others
    - 4 by anthropic
  20 - fixes were needed
    - 7 "assume a malicious filesystem image"
    - 2 "assume you can inject a malicious network packet into the middle of the stack"
    - 2 "NOMMU"
    - 6 sctp networking issues for untrusted devices
    - 2 ipv6 minor network issues 
    - 1 gpu driver for local malicious user
```

GHK called this "10 'real' bugfixes", which to me sounds like there's a wild hype machine around these companies and uncritical parroting of every press release they make that falls apart when you engage the affected real experts.

➕ show 8 replies
djoldman • today at 9:05 PM

> So what all of mythos; that whole big marketing issue of 79 bugs came down to one hour of kernel development.

If you're someone at OpenAI or Anthropic and you truly believe what you're making could destroy the world, this is the kind of thing that isn't doing you any favors when it comes to convincing the public. The dissonance here is stark:

  - widely proclaiming that your new model is so dangerous it needs to be released only to select people, for safety
  - widely proclaiming the model easily found 79 bugs in linux, except that GKH says it took 1 hour to fix all of them because most weren't bugs and the rest were almost all completely trivial, unimportant, and/or not severe
It doesn't mean the model isn't dangerous or super capable but wow this makes it realllll easy to doubt it and any future announcement.
➕ show 3 replies
devy • today at 7:57 PM

At 3m19s Greg KH revealed what Mythos did in "revealing" 79 CVEs - pure pattern matching the previous decades of kernel developer's patches, and applying those mechanisms elsewhere to see if they have been universally patched. And Anthropic didn't cite Kernel Developers who original fixed/patched the CVEs like a decent human being would do. So yeah, Anthropic has the same problem OpenAI had for citing original work.

Aissen • today at 8:35 PM

Nice to see Kernel Recipes covered again on HN. Shameless plug: I do the live blog: it's incomplete, imperfect and has typos; but it's written and published during the presentations. On this talk : https://kernel-recipes.org/en/2026/2026/09/22/live-blog-day-...

blinkingled • today at 6:58 PM

It's great to hear about $topic from someone no-nonsense and in-the-know like Greg KH. You can verify all of this too - since, well Linux kernel. (As opposed to what Microsoft or Apple claims to fix as far as LLM finds.)

Mythos may not be great today but it is not far fetched to imagine bug discovery, analysis and fixes can be made much quicker, accurate and even newly possible with specialized models trained on say Linux kernel specifics - with codemap/coding standards/threat models, good and bad coding patterns, tools to validate etc. an LLM can be much more relentless than humans and if it has the help to be accurate it will be worth the electricity burned. Oh and another model trained on triage data to validate the first one's findings would be good.

(I think Microsoft is doing this internally - different models trained internally alongside Mythos - there was some talk about it on the tubes, don't recall where exactly.)

➕ show 1 reply
sriram_sun • today at 7:11 PM

He also said that it all boiled down to just one hour of kernel development work.

➕ show 1 reply
asaiacai • today at 9:19 PM

cool to see a really grounded analysis of the "security" and LLMs. I use agents in on the day-to-day for generating implementation but this just furthers my belief that humans and especially human reviewers remain critical for the sustainability of software systems.

also, lol at "The bots are dumb - they want to please you line". LLMs have pretty much ruined technical collaboration between contributors. I get tilted every time an discussion has "but my claude said this..."

1sgT15 • today at 7:19 PM

Finally it is official. Mythos was overhyped and overrated.

➕ show 1 reply
0xbadcafebee • today at 9:42 PM

"Ignore the comments, look at the code" - 100% agree. The comments and "explanations" will end up confusing you and often being wrong. But the code doesn't lie.

"NEVER upload any non-public information" - He's talking about how if you give Claude/GPT some secret info (like research, credentials, etc), it will train on it and give the same info to someone else. This is 100% the case for the free and consumer versions of these models, which is what most people use. For Enterprise plans they're not supposed to be doing this, but it's possible they will screw up and do it anyway.

csmlab_notes • today at 9:16 PM

[dead]

IndiaInfraNotes • today at 3:05 AM

[dead]

sippingabonedry • today at 7:20 PM

[flagged]

FLeXMurphy • today at 7:21 PM

We've flagged this submission as off-topic. Please follow the submission guidelines. Topics around, for example, how Anthropic LLM escaped containment and will end the world are what hackers are curious about. The linux kernel on the other hand is not. Thanks.

➕ show 1 reply