Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That analysis would seem smart but let's try a game of Mad Libs:

The Linux Kernel just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

KDE just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

Firefox just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

Chrome just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

Windows just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

Photoshop just racked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

All CPUs just rucked up another CVE, so I kinda feel that its severely under-designed nature will always haunt it.

What's the theme? Racking up CVEs is something all software & hardware does. Mistakes can happen in design and in implementation and no one is immune. Using presence of CVEs as an indication of immaturity / fundamental design flaw isn't helpful. In fact, it's probably the opposite. Software that has no CVEs probably just means no one is paying attention to it. Sure, in a theoretical case maybe you've built a formal proof and translated that into a memory safe language somehow (& you assume you've made no mistakes modelling your entire system in your proof), then maybe. However, that encompasses 0% of all software.

> The idea that you can just hand off infinite amounts of work for the kernel to do on your behalf is pretty fundamentally broken. It is a concrete implementation of wishful thinking

How is that any different from a file descriptor? The kernel is free to setup limits on how much work you can have outstanding at any given time (now maybe those bits are missing right now, but it doesn't feel like an intractable problem).



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: