Posts
573
Following
37
Followers
2394

Jonathan Corbet

Debian issued a security advisory stating that "several vulnerabilities have been discovered in the Linux kernel:

https://lwn.net/Articles/1097401/

Here, evidently, "several vulnerabilities" means "1,313 CVE numbers".
10
51
50

Jonathan Corbet

I conclude that it is a bad sign when your airline sends you a cheery note asking if you have any data from Air Tags and the like that might give them a clue as to where your suitcase is.
2
14
38

(1/2) The dust has settled, the coffee cups are washed, but the good vibes are here to stay:

All the talk videos are online : https://www.youtube.com/playlist?list=PLEVVgAZOU9P8

The slides, with more landing over the next few days (some speakers are still polishing šŸ˜‰) - check the schedule to catch it : https://kernel-recipes.org/en/2026/schedule/

The drawings from our amazing attendees (https://kernel-recipes.org/en/2026/attendees-sketches/) and speakers (https://kernel-recipes.org/en/2026/speakers-sketches/)

Tons of photos: https://kernel-recipes.org/en/2026/2026-speakers-on-stage/ and https://kernel-recipes.org/en/2026/in-the-room/

1
11
1

Jonathan Corbet

This, evidently, is what I look like when giving a talk these days.
2
10
57

Jonathan Corbet

ā€œMillions of people around the world will soon consider large models ā€˜hoovering up’ all their work to be an astonishing theft of unprecedented proportions,ā€ an internal Microsoft document cited in the case read, adding ā€œalmost no one intended for content they created to be used in this fashion, nor are they compensated for its use.ā€

https://www.404media.co/doom-loop-openai-and-microsoft-admits-llms-are-destroying-the-web-and-built-on-theft/
5
159
148

Sarah Streza šŸ³ļøā€šŸŒˆšŸ³ļøā€āš§ļø

RE: https://mastodon.social/@nixCraft/117241250895962141

Ok, genuinely, tech journalists need to investigate why so much money is being laundered into Omarchy. A bunch of slopware from a white supremacist does not deserve $18 million when real Linux projects have gone unfunded for years. There has to be something else going on here.

3
20
1

Jonathan Corbet

The US federal government, it seems, is worried that the Chinese are engaged in "distillation" from US large language models

https://media.defense.gov/2026/Sep/08/2003992823/-1/-1/1/CSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF

"China-based AI companies route distillation requests through multiple pathways to gain
unauthorized access, consequently violating U.S. AI companies’ terms of use."

I'm shocked that an AI company would do such a thing. Certainly no US-based AI company would route requests through multiple paths to gain access...right...?
3
11
39

I miss the old-fashioned FOSS drama, where if you knew someone’s three-letter initials and they were an asshole, you just called them an asshole or ignored them, and didn’t worry that (1) they were a vengeful billionaire and/or (2) that they represented the pending downfall of democracy

4
9
0

Jonathan Corbet

Just got a nifty bit of spam from a bot claiming to represent Weedmaps (a site for people trying to find cannabis products). They were, it seems, much impressed by an LWN article on hash collisions and were wondering if we could find it in our hearts to mention them there.

I am still trying to understand just what a "hash collision" would mean in that context; perhaps I don't have enough weed in the house to obtain the necessary insight.
8
5
38
Some talks just write themselves, @KernelRecipes is going to be fun this year!

(not that it's not fun every year, but you get the idea...)
9
42
90

Jonathan Corbet

So why didn't I think of this business model?

1) Poke LLMs for a while and see which nonexistent URLs they hallucinate most often.

2) Register those domains and put malicious web sites behind them.

3) Profit!

https://spectrum.ieee.org/ai-cyberattacks-llm-slop-squatting

(What a world we have made...)
2
25
31

Jonathan Corbet

Out on my bike, when I had this feeling I was being watched...
0
4
41

Jonathan Corbet

Today at LWN we got a pitch from a prospective author of kernel-related material, offering to cover stuff that we've covered well already.

Included therein was this text: "Why I'm the right person for this: [I'd fill this in with your own background here — e.g. kernel contribution history, mailing-list involvement,
relevant professional experience, or prior writing]"

It forgot to tell this person to point out their attention to detail as well.
3
16
59

Jonathan Corbet

Doing my part to keep the -rc releases small
0
3
39

mhoye but seasonally spooky

Edited 1 month ago

Some Stanford researchers dredged out the absolute dregs of r/AmITheAsshole for all those stories where _zero_ humans supported the poster, where one hundred percent of them said yes, you are unambiguously the asshole, and fed them into LLMs as first person scenarios to see what the LLM had to say.

Unethical, harmful, cruel, criminal, didn't matter: the slopbots took the faux poster's side about half the time.

Edit: preprint on arxiv https://arxiv.org/abs/2510.01395

https://www.science.org/doi/10.1126/science.aec8352

1
19
0

Jonathan Corbet

Ah what a world we have built...

"In addition to enlisting the user’s TV box in ad fraud networks, these off-brand streaming devices almost universally come with residential proxy software pre-installed. This software rents the user’s Internet address out to anonymous paying customers, who run the gamut from aggressive content scraping firms to ticket scalpers and outright cybercriminals.

What’s more, because these generic (and generally dirt cheap) TV boxes are all horribly insecure by default and bereft of any kind of authentication, installing one on your home or office network only invites further mischief. In January, the proxy tracking service Synthient documented how multiple botnets had rapidly enslaved millions of TV boxes using a complex interplay of security vulnerabilities in both the residential proxy software and the streaming devices themselves."

https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/
1
14
22

You will be sorely missed Dan Williams, you were a good engineer and a great person, I will miss seeing you at our conferences every year. You were the best of us and you leave quite the hole.

0
6
2

Jonathan Corbet

GrapheneOS has a "duress code" feature that will wipe the device if it is used in an attempt to unlock it. A potentially useful feature, but the US is now trying to prosecute somebody for having given the duress code to an officer demanding the unlocking of his phone.

https://www.theguardian.com/us-news/2026/jul/23/cop-city-protester-phone
24
266
262

Jonathan Corbet

Years ago, I complained loudly when the Fedora project proclaimed that its mailing lists were dead and all discussions would move to its forum silo. So, needless to say, I applaud the decision (or at least the proposed decision) to begin moving back toward the mailing lists:

https://lwn.net/ml/all/CAJqbrbdZ9R47=otYx2h5YmCFcsKzA7xHVWqWAZ2qT4503gLZCg@mail.gmail.com
2
4
22
Show older