The argument is that LLMs are making unikernels easier to work with, and having a whole OS stack leaves a big attack surface, as demonstrated by the scads of LPEs and other vulns we've been seeing in Linux over the past year+, right?
But you know what else is easier with LLMs? Properly hardening your Linux system. "Patch every week" is the recommendation from upstream because the kernel security team has to consider every possible deployment configuration and environment. If you implement all the KSPP recommendations, use a config and kernel command line that makes sense for your actual application, and use a properly configured MAC LSM, you would not have been affected by any of the big blockbuster vulns of the last year.
So if you can tell an LLM to port a library in a loop and feel confident in the results, surely you can feel equally confident telling the LLM to harden your Linux environment.
n.b.: I am not endorsing the idea that just throwing LLMs at security problems is actually a good answer, I'm just saying that the case the article makes isn't actually comparing like for like.
But you know what else is easier with LLMs? Properly hardening your Linux system. "Patch every week" is the recommendation from upstream because the kernel security team has to consider every possible deployment configuration and environment. If you implement all the KSPP recommendations, use a config and kernel command line that makes sense for your actual application, and use a properly configured MAC LSM, you would not have been affected by any of the big blockbuster vulns of the last year.
So if you can tell an LLM to port a library in a loop and feel confident in the results, surely you can feel equally confident telling the LLM to harden your Linux environment.
n.b.: I am not endorsing the idea that just throwing LLMs at security problems is actually a good answer, I'm just saying that the case the article makes isn't actually comparing like for like.