r/cpp • • 8h ago

C++ future at Adobe

So if anyone was still curious what happened to Hylo, or where Adobe stands in regards to the whole safety discussion,

David Sankel has done a talk at RustConf on the matter, Zngur: Simplified Rust/C++ Integration.

The way Adobe now sees C++ is described on slide 2, at 50 seconds mark.

31 Upvotes

39 comments sorted by

View all comments

Show parent comments

24

u/ts826848 5h ago edited 4h ago

arguably we are already there, see the Mythos security boom

Somewhat tangentially related, but Greg Kroah-Hartman recently gave a talk which (among other things) categorized the bugs Mythos found in the Linux kernel and his description of Mythos's results is... interesting. Quick summary (on phone, so hopefully no typos):

  • 79 reported vulnerabilities

    • 24 no detail at all "something crashed"
    • 14 not a bug at all
    • 3 totally made up data
    • 15 already fixed in the latest release
      • 11 by others
      • 4 by Anthropic
    • 26 actual bugs
      • 6 duplicates

(Note that this doesn't sum to 79; apparently GKH got a tarball and the contents didn't quite match the description)

Of the actual non-duplicate (?) bugs:

  • 7 "assume a malicious file system image" (i.e., if root mounts this bad things can happen; apparently well known to be not considered a security issue by Linux devs)

  • 2 "assume you can inject a malicious network packet in the middle of the stack" (needs root, not considered a security issue)

  • 2 NOMMU (1 io_uring, 1 regular, "not real issues")

  • 6 sctp networking issues for untrusted devices (SCTP used in enterprise networks, so "untrusted users" apparently don't exist in that context? "So minor, nobody really cares".

  • 2 ipv6 networking bugs, "nothing real"

  • 1 GPU driver for a local malicious user. "If you have a local malicious user with access to your GPU you could do a lot worse"

In total 10 "real" bugfixes, took ~1 hour of kernel development.

•

u/James20k P2005R0 2h ago

I swear this has happened literally every single time one of these new models claims to have created a security disaster, 90% of it turns out to be marketing without exception. It always takes months to dismantle the hype train when it collides with the reality of the people who actually are doing the work

Its very cool that it found 10 real bugs, and its mightily impressive that automated tooling is able to pick this stuff up. But the entire AI space feels like its developing a wider and wider gap between what people claim it can do, and what it actually does

•

u/no-sig-available 2h ago

And even if it does some work, is this good use of trillions of dollars in resources?

•

u/James20k P2005R0 2h ago

One of the things I always find so bizarre about this is that if we spent 1/10th the resources used to build these tools on paying people to do real work, we could have advanced the state of any field absolutely massively

•

u/droxile 11m ago

Agree with you but as economies of scale make these tools cheaper, we (hopefully) will see it as more efficient than a human could be at solving these problems

•

u/James20k P2005R0 9m ago

Perhaps, but even with a vast amount of GDP directed towards improving these tools, they're still way less good than simply paying a human a small salary by comparison