Re: [MAINTAINERS SUMMIT] Scaling our security process
Linus Torvalds <[email protected]> Mon, 27 Jul 2026 11:49:34 -0700
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <CAHk-=whzMRRtNNZ1zhdVj1-A=4DGOueo_ectuQbN-m0WKuRLSg@mail.gmail.com> |
On Mon, 27 Jul 2026 at 11:38, Sasha Levin <[email protected]> wrote: > > Does this asymmetry in effort between the fix and the reproducer/exploit code > really exists these days? Point your favorite LLM at a commit [..] I don't care. A bad policy that encourages bad behavior is stupid. They've apparently softened it - see Jiri's email - but it's still just midguided. I think the fix should be public. Not unnecessary stuff that can be harmful. We already have too many ambulance-chasing security researchers and tech journalists, I don't think we should do their work for them. If they use their LLM tokens for it, so be it, that doesn't change the basic premise. Linus