Posts by corbet@social.kernel.org
(DIR) Post #AsaLOL5B9GQkZdmEqW by corbet@social.kernel.org
0 likes, 1 repeats
Today I got a cheery email from somebody who claims to be the "ethics and compliance" officer for a company called Bright Data. He wanted to have a "no pressure" conversation about the whole AI scraperbot problem. Looking at their web site, this company offers an API that, and I quote, "Bypasses anti-scraping mechanisms and solves CAPTCHAs, ensuring uninterrupted access to the most protected web sites".After careful consideration for several milliseconds, I have concluded that I really don't have anything to discuss with this person.But at least their claimed "100M+" of residential IP addresses that they use for their DDOS attacks are "ethically sourced".
(DIR) Post #B4BfcnZFLnZzCOaQOe by corbet@social.kernel.org
1 likes, 0 repeats
So somebody is really convinced that there is an SQL-injection vulnerability lurking in the LWN login form, and they have been employing a small botnet in a determined effort to find it. I'm not hugely worried about the attack, but I still find this kind of thing annoying.
(DIR) Post #B4NsPRASx2BdGQTRJ2 by corbet@social.kernel.org
0 likes, 0 repeats
@mhoye @azonenberg That part is true. I would never ban an address just for a 404 (though we do track such things in other ways). But if somebody is going for, say, /wp-anything, that's not a typo, that is seeing if a random doorknob is unlocked. Not the sort of reader we are writing for.
(DIR) Post #B4WyXxqTgkgn4mDH9s by corbet@social.kernel.org
1 likes, 0 repeats
As the number of LLM-generated patches in my inbox increases, I am starting to experience the sort of maintainer stress that has long been predicted. But there's another aspect of this that has recently crossed my mind.Just over a week ago, a new personality showed up with a whole pile of machine-generated patches claiming to fill in our memory-management documentation. A few reviewers had some sharp questions, the response to which has been ... silence. This person doesn't seem to have cared enough about that work to make an effort to get past the initial resistance.Once upon a time, somebody who had produced many pages of MM documentation would be invested enough in that work to make at least a minimal attempt to defend it.Kernel developers often worry that a patch submitter will not stick around to maintain the code they are trying to push upstream. Part of the gauntlet of getting kernel patches accepted can be seen as a sort of "are you serious?" test.When somebody submits a big pile of machine-generated code, though, will they be *able* to maintain it? And will they be sufficiently invested in this code, which they didn't write and probably don't understand, to stick around and fix the inevitable problems that will arise? I rather fear not, and that does not bode well for the long-term maintainability of our software.
(DIR) Post #B4eStmVAtxzczrHtGS by corbet@social.kernel.org
0 likes, 0 repeats
@ljs Interesting, I didn't see that this entity had graduated from wanting to be the lib/ maintainer to generating memory-tiering modules for DAMON. Quite the flexible guy! And here I was getting irritated because "he" thought that sending Acked-by responses to random typo-fix documentation patches was somehow helpful...
(DIR) Post #B4fFJmJwzcddlRV2G0 by corbet@social.kernel.org
1 likes, 0 repeats
I see on HN that John Bradley, the creator of xv, has died:https://news.ycombinator.com/item?id=47534086The real announcements, alas, come from sources that I am unwilling to link to.Xv, an image viewer/editor, is one of those tools that hit a peak of usability that really hasn't been matched since. It supports a wide range of image-manipulation functions, and has an interface that gets the job done quickly. I've sort of moved away from it over the years, but I still keep it around.RIP, John, you made something good.
(DIR) Post #B6MjOp23jmlvqOFDpg by corbet@social.kernel.org
0 likes, 1 repeats
Stuck watching my daughter's cats for a bit... There are worse fates.
(DIR) Post #B6lJm9BnhLrMWl0l5U by corbet@social.kernel.org
0 likes, 0 repeats
So, seemingly, somebody's Fedora and proprietary-forge credentials were compromised and used by some sort of LLM-driven bot to take over a lot of Fedora bugs:https://lwn.net/ml/all/bf38c0fd4537c2908a84b4a4b1fcec8083925918.camel@fedoraproject.orgThis person is now claiming to have regained access to the accounts, but it seems that not everybody is buying it.What a world we have made for ourselves...
(DIR) Post #B7nx5ZKhM9iU7ruJlY by corbet@social.kernel.org
1 likes, 1 repeats
The @lwn web site is currently under the most intense scraper attack I have seen yet. 1.3M unique IP addresses within the last couple of hours, and it's not done yet. The work we have done on defenses appears to be paying off, though; the server is holding up reasonably well — so far....just in case anybody wonders why I have a rather dim view of the whole AI industry...
(DIR) Post #B7yEyUUDU3V45Gzqsa by corbet@social.kernel.org
1 likes, 0 repeats
"More generally, liability concerns could mean that many current use cases for agents won’t be commercially viable. Companies may not be able to profitably operate AI lawyers, doctors and media influencers if they are held responsible for what they say and do.We’re OK with this outcome. There’s nothing in the law that requires us to accommodate AI systems if they are fundamentally untrustworthy, just as we don’t need to accommodate untrustworthy human systems."— Bruce Schneier https://www.schneier.com/blog/archives/2026/06/ai-and-liability.html
(DIR) Post #B817BmRHpZRZMwKdvM by corbet@social.kernel.org
0 likes, 1 repeats
The dog days of summer
(DIR) Post #B8OgvcjDvKoAsC7vea by corbet@social.kernel.org
1 likes, 0 repeats
I've been spending rather too much of my time reading the depressing threads on LLM use in the kernel. But I thought that this contribution from Lyude Paul worth the investment."For many people who need their jobs, guidelines around acceptable use of these tools beyond "a person needs to own the the code" may end up being the only thing allowing employees to be responsible with their contributions without repercussion from employers."https://lwn.net/ml/all/3a5d891b536588e8e4fc84d60a5c8af72091d852.camel@redhat.com
(DIR) Post #B8dbl5367NKH1RXkhM by corbet@social.kernel.org
0 likes, 1 repeats
GrapheneOS has a "duress code" feature that will wipe the device if it is used in an attempt to unlock it. A potentially useful feature, but the US is now trying to prosecute somebody for having given the duress code to an officer demanding the unlocking of his phone.https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
(DIR) Post #B9yLpVp63KAU7bAmm0 by corbet@social.kernel.org
1 likes, 0 repeats
Just got a nifty bit of spam from a bot claiming to represent Weedmaps (a site for people trying to find cannabis products). They were, it seems, much impressed by an LWN article on hash collisions and were wondering if we could find it in our hearts to mention them there.I am still trying to understand just what a "hash collision" would mean in that context; perhaps I don't have enough weed in the house to obtain the necessary insight.