Live data from Hacker News

Open Source Isn't Dead

strix.ai

11–20 of 200 posts

Re: Open Source Isn't Dead

#11
post #6

> The reasoning provided by their CEO, Bailey Pumfleet, is that AI has automated vulnerability discovery at scale, That sounds like an excuse. The real reason is probably that it's hard to make a viable business out of developing open source.

Exactly. I respect their decision to go closed source if that's what they need to do to make it a viable business, but just be honest about it. Don't make up some excuse around security and open source.

I don't know if I fully agree with this -- how many people were actually self-hosting cal infra? I def could be wrong though

Re: Open Source Isn't Dead

#12
a lot of the vulnerabilities in web-apps are people trying to be too smart for their own good.

use battle-tested frameworks such as Rails, Django then you won't make rookie security mistakes.

Re: Open Source Isn't Dead

#17
post #4
post #3

I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.

> Closed source software won't receive any reports Not from the automated repo scanners, but bug bounty programs can generate a lot of reports in my experience. AI tools are becoming a problem there, too, because amateurs are drawn to the bounties and will submit anything the AI hallucinates. Closed source companies can (and should!) also run their own security audits rather than passively waiting for volunteers to s…

Of course everyone should do their own due diligence, but my point is mostly that open source will have many more eyes and more effort put into it, both by owners, but also community.

Re: Open Source Isn't Dead

#18
Enshittification has come for VC backed open-source. As someone on Twittter said, open source has deemed commercial open source obsolete especially when users can point Calude Code to calcom on GitHub and ask it to make them scheduling features directly into their product. That’s what spooked Cal.

Re: Open Source Isn't Dead

#19
All content is going to go behind paywalls.

There is zero incentive or reason for content creators to let AI slurp their content for free and distribute it and get all the money from it.

Everything new will be licensed and if AI companies want access to it, they will need to pay for it, just like we will.

Re: Open Source Isn't Dead

#20
post #3

I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.

given what the clankers can do unassisted and what more they can do when you give them ghidra, no software is 'closed source' anymore
Post reply on HN