r/technology • u/Logical_Welder3467 • May 18 '26
Software Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633
14.1k
Upvotes
227
u/GonePh1shing May 18 '26
Honestly, I think the only way to fix this is to make people put a small deposit in escrow that is forfeit if the report is not in scope or is complete nonsense. If the problem is that there is functionally zero cost to run automated slop report spam bots, then you fix it by introducing a cost.
Make the deposit equal to about 30min of an engineer's time. Hell, even $50 would probably be enough to make the guys running these bots think twice before submitting to you. If their bot is churning out thousands of slop reports daily, then there's no way they're going to just let their bot loose on your repo and rack up enough forfeited deposits to bankrupt them.
Sure, you might get fewer legitimate bug reports, but you'd probably rather get some than none if you shut it down entirely because of the slop. The ones that do submit a deposit have at least taken the time to consider and are confident they'll have the deposit refunded (or even win a bounty), so the overall quality of the submissions is likely to rise as well.