this post was submitted on 27 Aug 2026
661 points (99.1% liked)
Technology
87624 readers
4453 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I hate ai as much as the next person, but I'd have a different mandate. I would require all code to be fully reviewed and understood by a human. Let's call it quality control.
This is the way. Cat is out of the bag now so need to figure out responsible usage.
Fortunately we have a method for that for a long time now: PRs. If you approve it, you are responsible for that approval.
Agreed. It's not sensible or practical to ban AI, and Linus is right. Why is Linus right? Take a look at the number of Linux CVEs being patched over time. In 2022-23, that was about 300 per year. Last year it was 5530. This is almost entirely as a result of AI scanning tools, including Copy Fail priv escalation that was there for 8 years. The security apocalypse is just about arrived, and the most recent round of cyber models coming out do this way better than before. The Hugging Face incident story was truly unbelievable if you read / watch the details, a historic event. Everything is about to get hacked. So it'll be all about maintainers being reactive to this new reality and burden for some time to come
It didn't really seem that way? Leaving containment seemed more like a configuration oversight than a skill on the part of the model. Accessing HF involved an 0-day but the commentary I saw didn't indicate that it was a next generation hack.
Given that AI exists, and can scan or otherwise find vulnerabilities, maintainers must do so because threat actors inevitably will.
It remains to be seen whether the whole race will improve security generally? I imagine not?
If you placed me in the position of those models in that sandbox, I wouldn't have been able to escape the sandbox to save my life. Let alone hack hugging face.
Have you read all the code on the planet?
If not, don't feel bad about it.
Nah, it was like:
Open weights models will catch up soon enough, and then it'll be totally fucking wild
You are believing a notorious bunch of liars.
Much more probably: they developed a cyberweapon and tested it in the wild. The victim caught them so they invented a cyberpunk history to increase the interest of potential buyers for that weapon.
I basically just don't believe you, and can't be bothered looking.
You're anthropomorphizing a statistical model. It's laughable to suggest they "elected a CEO and power structure".
When/if we meet aliens, they will have evolution. And they will organize themselves in social power structures. Both are examples of basic emergent complexity properties of any such system.
So it is completely believable that AIs would form a power structure, with some form of CEO. That is just how reality works, such systems are more efficient so they happen.
Why are you even using the term CEO?
AI learned from humans, and humans texts use the term CEO. Why wouldn't the AI's also use the term CEO?
Because a CEO is a specific thing with a specific meaning that just isn't relevant here. It's laden with human meaning that is irrelevant to a statistical model.
Really you're trying to say that the bots coordinated their efforts, and perhaps one of them was delegating tasks.
This type of structure is very common in tech, in load balancers or queues of service workers, containers and hypervisors, et cetera.
Power structures that seem logical and efficient to humans are not so for a gen AI model. If everyone knows what needs to be done and no one has any ego or character traits to manage, then everyone can simply perform the next task as it arises.
Its absolutely absurd to suggest that the bots elected a CEO.
But the ai could generate text to that effect, if it was statistically likely.
What?
Typo, fixed
Still lost sorry.
Which part is confusing?
What are you trying to say?
That the ai could produce text claiming that it has elected a ceo. I don't know how else to restate it. Throw me a rope here.
That doesn't make it true though, obviously.
Yeah, obviously not. It's all just statistical auto correct.
There is a difference between using AI scanning tools and generating code for production
Yes and no. The ability to "understand" code that makes AI capable of finding security bugs, is correlated with AI's ability to write code. AI is just really good at code related tasks, and categorically banning all AI usage is shooting yourself in the foot.
And also have high readability standards, ideally higher than before LLMs.
How would you enforce that?
How do you enforce code is not AI generated? I don't see how one is more easily enforceable than the other.
I mean how do you enforce someone doesn't copy code from proprietary repos? You just try your best, and only come down on the cases where it's obvious.
LLM users are lazy so they inevitably just copy+paste something asinine without reading it.
Well it depends who you are. An employer could enforce it.
But it was serious question. If you're going to have a rule then there should be a way to enforce it, otherwise it means nothing.
It's a fair question. I think out of the two proposed rules: enforce no AI generated code, and enforce human reviews, enforcing human reviews is actually more feasible, and in fact most companies already do that. Pull requests need human reviewers to approve them.
It's harder to enforce no AI generated code. A developer can always, at the very least, Google a problem they are having on their phone and retype the code from the AI answer into their work computer.
Read the article, that is one of the two options they are voting on.