Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Remember Linus's Law?

Remember Linus's Law?

Scheduled Pinned Locked Moved Uncategorized
8 Posts 5 Posters 11 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • joshbressers@infosec.exchangeJ This user is from outside of this forum
    joshbressers@infosec.exchangeJ This user is from outside of this forum
    joshbressers@infosec.exchange
    wrote last edited by
    #1

    Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE

    While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with

    What happens if we have a million CVEs every year?

    https://opensourcesecurity.io/2026/04-linus-law-vulns/

    liw@toot.liw.fiL hyc@mastodon.socialH fennix@infosec.spaceF haliphax@hachyderm.ioH 4 Replies Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    • joshbressers@infosec.exchangeJ joshbressers@infosec.exchange

      Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE

      While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with

      What happens if we have a million CVEs every year?

      https://opensourcesecurity.io/2026/04-linus-law-vulns/

      liw@toot.liw.fiL This user is from outside of this forum
      liw@toot.liw.fiL This user is from outside of this forum
      liw@toot.liw.fi
      wrote last edited by
      #2

      @joshbressers https://blog.liw.fi/posts/2022/04/07/linus-law/

      joshbressers@infosec.exchangeJ 1 Reply Last reply
      0
      • liw@toot.liw.fiL liw@toot.liw.fi

        @joshbressers https://blog.liw.fi/posts/2022/04/07/linus-law/

        joshbressers@infosec.exchangeJ This user is from outside of this forum
        joshbressers@infosec.exchangeJ This user is from outside of this forum
        joshbressers@infosec.exchange
        wrote last edited by
        #3

        @liw hi5!

        1 Reply Last reply
        0
        • joshbressers@infosec.exchangeJ joshbressers@infosec.exchange

          Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE

          While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with

          What happens if we have a million CVEs every year?

          https://opensourcesecurity.io/2026/04-linus-law-vulns/

          hyc@mastodon.socialH This user is from outside of this forum
          hyc@mastodon.socialH This user is from outside of this forum
          hyc@mastodon.social
          wrote last edited by
          #4

          @joshbressers maybe.... fix them slowly, and write new code more slowly, carefully, and deliberately?

          joshbressers@infosec.exchangeJ 1 Reply Last reply
          0
          • joshbressers@infosec.exchangeJ joshbressers@infosec.exchange

            Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE

            While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with

            What happens if we have a million CVEs every year?

            https://opensourcesecurity.io/2026/04-linus-law-vulns/

            fennix@infosec.spaceF This user is from outside of this forum
            fennix@infosec.spaceF This user is from outside of this forum
            fennix@infosec.space
            wrote last edited by
            #5

            @joshbressers

            A million CVEs is gonna look like rookie numbers in 3-5 years. The quantity of vulnerabilities will increase with the quantity of code and that's ballooning now.

            Thing is, any pentester or appsec person could have told you this stuff is there and has been forever. It's occult knowledge basically; hidden because nobody's actually been looking.

            The reckoning here isn't that this is creating some unbeatable tide of new problems, it's that for years people have refused to foundationally build in secure design and development practices in our education for any kind of programmer, developer, or architect. Pushing left is the only reliable way to turn this tap off - prevent the mistakes as or before they're made. Instead, the industry has collectively decided to build tap opening automation at grand scales.

            "Oh no we've defended our appsec program" is basically where loads of companies are.

            Look to climate change for how well we're goanna handle this.

            #InfoSec #AppSec

            joshbressers@infosec.exchangeJ 1 Reply Last reply
            0
            • hyc@mastodon.socialH hyc@mastodon.social

              @joshbressers maybe.... fix them slowly, and write new code more slowly, carefully, and deliberately?

              joshbressers@infosec.exchangeJ This user is from outside of this forum
              joshbressers@infosec.exchangeJ This user is from outside of this forum
              joshbressers@infosec.exchange
              wrote last edited by
              #6

              @hyc While I would love to see this, I suspect that ship sailed a long time ago

              1 Reply Last reply
              0
              • fennix@infosec.spaceF fennix@infosec.space

                @joshbressers

                A million CVEs is gonna look like rookie numbers in 3-5 years. The quantity of vulnerabilities will increase with the quantity of code and that's ballooning now.

                Thing is, any pentester or appsec person could have told you this stuff is there and has been forever. It's occult knowledge basically; hidden because nobody's actually been looking.

                The reckoning here isn't that this is creating some unbeatable tide of new problems, it's that for years people have refused to foundationally build in secure design and development practices in our education for any kind of programmer, developer, or architect. Pushing left is the only reliable way to turn this tap off - prevent the mistakes as or before they're made. Instead, the industry has collectively decided to build tap opening automation at grand scales.

                "Oh no we've defended our appsec program" is basically where loads of companies are.

                Look to climate change for how well we're goanna handle this.

                #InfoSec #AppSec

                joshbressers@infosec.exchangeJ This user is from outside of this forum
                joshbressers@infosec.exchangeJ This user is from outside of this forum
                joshbressers@infosec.exchange
                wrote last edited by
                #7

                @fennix Agreed!

                It's going to be a very silly couple of years

                1 Reply Last reply
                0
                • joshbressers@infosec.exchangeJ joshbressers@infosec.exchange

                  Remember Linus's Law? While it was never really true, there are now A LOT of people looking for vulnerabilities with LLMs, and they're finding vulnerabilities EVERYWHERE

                  While Linus's Law was clearly nonsense, this is creating an increase in vulnerabilities the world is completely unprepared to deal with

                  What happens if we have a million CVEs every year?

                  https://opensourcesecurity.io/2026/04-linus-law-vulns/

                  haliphax@hachyderm.ioH This user is from outside of this forum
                  haliphax@hachyderm.ioH This user is from outside of this forum
                  haliphax@hachyderm.io
                  wrote last edited by
                  #8

                  @joshbressers What if most of them are bullshit?

                  Link Preview Image
                  The Boy That Cried Mythos: Verification is Collapsing Trust in Anthropic | flyingpenguin

                  favicon

                  (www.flyingpenguin.com)

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups