惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

LWN.net comments

Nonsense [LWN.net] This isn't just anti-ai, it's also anti-gui [LWN.net] Revealing [LWN.net] Nonsense [LWN.net] Just 12 vulnerabilities? [LWN.net] Nonsense [LWN.net] Editing session recording as a throttling mechanism [LWN.net] Privacy [LWN.net] Surprising [LWN.net] Speedruns do require this [LWN.net] Nonsense [LWN.net] Loss of words Nonsense [LWN.net] This isn't just anti-ai, it's also anti-gui [LWN.net] This seems unwieldy [LWN.net] Proprietary vs open source models [LWN.net] This seems unwieldy [LWN.net] Revealing [LWN.net] Surprising [LWN.net] Just 12 vulnerabilities? [LWN.net] Just 12 vulnerabilities? [LWN.net] Revealing [LWN.net] Revealing [LWN.net] Just 12 vulnerabilities? [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Revealing [LWN.net] Generate assembly language directly with -S [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Deriving Documentation and Specifications [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Good, bad and probabilistic [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Proprietary vs open source models [LWN.net] Surprising [LWN.net] "Tokens per second" may not be the measure you think it is. [LWN.net] Surprising [LWN.net] Surprising [LWN.net] Surprising [LWN.net] Fundriser there [LWN.net] With hindsight, it was a code smell anyway [LWN.net] Shift in public's attitude [LWN.net] Thought I was the only one [LWN.net] Generate assembly language directly with -S [LWN.net] Opposite of -stable maintainers requests? [LWN.net] Thought I was the only one [LWN.net] Thought I was the only one [LWN.net] Thought I was the only one [LWN.net] Opposite of -stable maintainers requests? [LWN.net] Browser [LWN.net] Browser [LWN.net] Data structures and overhead [LWN.net] With him on this one [LWN.net] With hindsight, it was a code smell anyway [LWN.net] With hindsight, it was a code smell anyway [LWN.net] Be careful what you wish for [LWN.net] Be careful what you wish for [LWN.net] Red Hat are what they are... [LWN.net] Browser [LWN.net] schism status [LWN.net] With hindsight, it was a code smell anyway [LWN.net] Be careful what you wish for [LWN.net] schism status [LWN.net] Bluetooth fixed on my Yogabook [LWN.net] Megapatch [LWN.net] With hindsight, it was a code smell anyway [LWN.net] About isolation and memory errors [LWN.net] With hindsight, it was a code smell anyway [LWN.net] Be careful what you wish for [LWN.net] Browser [LWN.net] Complete opposite [LWN.net] A hurdle for the attacker? [LWN.net] important thing With hindsight, it was a code smell anyway [LWN.net] Intel bug workaround Browser A hurdle for the attacker? [LWN.net] Browser [LWN.net] schism status [LWN.net] PQC signing for distros relying on OpenPGP? [LWN.net] Browser [LWN.net] Browser [LWN.net] Browser [LWN.net] Better off keeping it vague [LWN.net] Browser [LWN.net] Complete opposite [LWN.net] A hurdle for the attacker? [LWN.net] Better off keeping it vague [LWN.net] Better off keeping it vague [LWN.net] Under 10 [LWN.net]
Revealing [LWN.net]
demiguru · 2026-05-26 · via LWN.net comments

Revealing

Posted May 26, 2026 15:38 UTC (Tue) by demiguru (guest, #176724)
In reply to: Revealing by gmprice
Parent article: Stenberg: The pressure

I could not agree more. That being said, how many less active open source projects can now be more easily maintained by LLM like platforms?


to post comments

Revealing

Posted May 26, 2026 15:50 UTC (Tue) by pizza (subscriber, #46) [Link]

Revealing

Posted May 26, 2026 15:50 UTC (Tue) by gmprice (subscriber, #167884) [Link] (2 responses)

Revealing

Posted May 26, 2026 17:04 UTC (Tue) by rgmoore (✭ supporter ✭, #75) [Link] (1 responses)

I.e.: "What do we want this software to do" and more importantly "What do we want this software to *not* do".

It depends on where the project is in its lifespan. "What do we want this software to do/not do" is mostly a question for a project that's still adding features. If the project isn't adding features- and a lot of the kind of projects that are chronically short on developer time aren't- it's mostly made up its mind about what it will and won't do. In that case, the main job is dealing with bugs and maintaining compatibility with any changes in dependencies. There is some question about what exactly classifies as a bug- it does require judgment about whether the alleged behavior is intended or not- but even that is less of an issue with security bugs.

Getting back to the original question, I suspect most less active projects will find LLM bug finding to be a bad thing overall. They're less active either because they're in maintenance mode or because the developer just doesn't have time to do more. Either way, a sudden flood of bug reports is likely to be overwhelming. Meanwhile, the developer wasn't doing a whole lot with the project already, so being able to spend a little less time on it once the flood of bugs is dealt with won't be much consolation.

Revealing

Posted May 26, 2026 20:17 UTC (Tue) by gmprice (subscriber, #167884) [Link]