<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Remember Linus&#x27;s Law?]]></title><description><![CDATA[<p>Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE</p><p>While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with</p><p>What happens if we have a million CVEs every year?</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://opensourcesecurity.io/2026/04-linus-law-vulns/" title="Linus's Law, but vulnerabilities">
<img src="https://opensourcesecurity.io/images/wide-microscope.jpg" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://opensourcesecurity.io/2026/04-linus-law-vulns/">
Linus's Law, but vulnerabilities
</a>
</h5>
<p class="card-text line-clamp-3">given enough eyeballs, all bugs are shallow
– Linus’s Law
A long time ago we thought Linus’s Law was a real thing and it was why open source was better than closed source. It seems pretty accepted now that Linus’s Law wasn’t ever really a thing. It’s far more likely the reason a lot of open source was pretty good is because the authors were worried someone WOULD look and judge them if the code looked like crap. We all have dark corners of private GitHub repos that are the code equivalent of a festering boil.</p>
</div>
<a href="https://opensourcesecurity.io/2026/04-linus-law-vulns/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://opensourcesecurity.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />









<p class="d-inline-block text-truncate mb-0">Open Source Security <span class="text-secondary">(opensourcesecurity.io)</span></p>
</a>
</div></p>]]></description><link>https://board.circlewithadot.net/topic/4584b493-32a5-413d-a8fd-5a102056b152/remember-linus-s-law</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 16:13:25 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4584b493-32a5-413d-a8fd-5a102056b152.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 12:27:39 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:47:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> What if most of them are bullshit?</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/" title="The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic | flyingpenguin">
<img src="https://www.flyingpenguin.com/wp-content/uploads/2026/05/flyingpenguin-header-bubbles.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>















<div class="card-body">
<h5 class="card-title">
<a href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/">
The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic | flyingpenguin
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://www.flyingpenguin.com/the-boy-that-cried-mythos-verification-is-collapsing-trust-in-anthropic/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.flyingpenguin.com/wp-content/uploads/2024/03/cropped-favico-32x32.jpg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />







<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.flyingpenguin.com)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/haliphax/statuses/116488067512342280</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/haliphax/statuses/116488067512342280</guid><dc:creator><![CDATA[haliphax@hachyderm.io]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:47:30 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:46:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/fennix%40infosec.space">@<span>fennix</span></a></span> Agreed!</p><p>It's going to be a very silly couple of years</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488065481264967</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488065481264967</guid><dc:creator><![CDATA[joshbressers@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:46:59 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:46:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/hyc%40mastodon.social">@<span>hyc</span></a></span> While I would love to see this, I suspect that ship sailed a long time ago</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488063712043809</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488063712043809</guid><dc:creator><![CDATA[joshbressers@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:46:32 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:42:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange" rel="nofollow noopener">@<span>joshbressers</span></a></span> </p><p>A million CVEs is gonna look like rookie numbers in 3-5 years. The quantity of vulnerabilities will increase with the quantity of code and that's ballooning now.</p><p>Thing is, any pentester or appsec person could have told you this stuff is there and has been forever. It's occult knowledge basically; hidden because nobody's actually been looking.</p><p>The reckoning here isn't that this is creating some unbeatable tide of new problems, it's that for years people have refused to foundationally build in secure design and development practices in our education for any kind of programmer, developer, or architect. Pushing left is the only reliable way to turn this tap off - prevent the mistakes as or before they're made. Instead, the industry has collectively decided to build tap opening automation at grand scales.</p><p>"Oh no we've defended our appsec program" is basically where loads of companies are.</p><p>Look to climate change for how well we're goanna handle this.</p><p><a href="https://infosec.space/tags/InfoSec" rel="tag">#<span>InfoSec</span></a> <a href="https://infosec.space/tags/AppSec" rel="tag">#<span>AppSec</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.space/users/fennix/statuses/116488047079088108</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.space/users/fennix/statuses/116488047079088108</guid><dc:creator><![CDATA[fennix@infosec.space]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:42:18 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:39:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> maybe.... fix them slowly, and write new code more slowly, carefully, and deliberately?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/hyc/statuses/116488034584742483</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/hyc/statuses/116488034584742483</guid><dc:creator><![CDATA[hyc@mastodon.social]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:39:08 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:34:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/liw%40toot.liw.fi">@<span>liw</span></a></span> hi5!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488014758014979</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/joshbressers/statuses/116488014758014979</guid><dc:creator><![CDATA[joshbressers@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:34:05 GMT</pubDate></item><item><title><![CDATA[Reply to Remember Linus&#x27;s Law? on Wed, 29 Apr 2026 12:32:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/joshbressers%40infosec.exchange">@<span>joshbressers</span></a></span> <a href="https://blog.liw.fi/posts/2022/04/07/linus-law/" rel="nofollow noopener"><span>https://</span><span>blog.liw.fi/posts/2022/04/07/l</span><span>inus-law/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://toot.liw.fi/users/liw/statuses/116488007304075045</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.liw.fi/users/liw/statuses/116488007304075045</guid><dc:creator><![CDATA[liw@toot.liw.fi]]></dc:creator><pubDate>Wed, 29 Apr 2026 12:32:11 GMT</pubDate></item></channel></rss>