> The reasoning provided by their CEO, Bailey Pumfleet, is that AI has automated vulnerability discovery at scale, That sounds like an excuse. The real reason is probably that it's hard to make a viable business out of developing open source.
Exactly. I respect their decision to go closed source if that's what they need to do to make it a viable business, but just be honest about it. Don't make up some excuse around security and open source.
Open Source Isn't Dead
11–20 of 200 posts
Re: Open Source Isn't Dead
#12use battle-tested frameworks such as Rails, Django then you won't make rookie security mistakes.
Re: Open Source Isn't Dead
#13Re: Open Source Isn't Dead
#14This is just an excuse to close source their project while blaming AI. Spineless bullshit excuse instead of owning your choices. Shame
Re: Open Source Isn't Dead
#15How long before LLM perform perfect disassembly exploitation...
Re: Open Source Isn't Dead
#16Re: Open Source Isn't Dead
#17I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.
> Closed source software won't receive any reports Not from the automated repo scanners, but bug bounty programs can generate a lot of reports in my experience. AI tools are becoming a problem there, too, because amateurs are drawn to the bounties and will submit anything the AI hallucinates. Closed source companies can (and should!) also run their own security audits rather than passively waiting for volunteers to s…
Re: Open Source Isn't Dead
#18Re: Open Source Isn't Dead
#19There is zero incentive or reason for content creators to let AI slurp their content for free and distribute it and get all the money from it.
Everything new will be licensed and if AI companies want access to it, they will need to pay for it, just like we will.
Re: Open Source Isn't Dead
#20I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.