Live data from Hacker News

Open Source Isn't Dead

strix.ai

41–50 of 200 posts

Re: Open Source Isn't Dead

#41
I decided to not open source my latest project but it has nothing to do with security concerns. My code is perfectly secure and bug-free.

My concern is mostly financial. Most people would be in a better position to monetize my software than I am... Using AI to obfuscate the origin while appropriating all the key innovations. I wouldn't get any credit.

Also, I'm not really interested in humans anymore. I have human fatigue.

Re: Open Source Isn't Dead

#42

All content is going to go behind paywalls. There is zero incentive or reason for content creators to let AI slurp their content for free and distribute it and get all the money from it. Everything new will be licensed and if AI companies want access to it, they will need to pay for it, just like we will.

I don't think this will happen. If most content goes behind a paywall, releasing content for free will again become a valuable source of attention. It used to be so before the web got filled with so much free content that it lost any value.

I disagree. AI will slurp their content so quickly that no one will notice.

Re: Open Source Isn't Dead

#43
post #20
post #3

I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.

given what the clankers can do unassisted and what more they can do when you give them ghidra, no software is 'closed source' anymore

Which models have you had good luck with when working with ghidra?

I analyze crash dumps for a Windows application. I haven't had much luck using Claude, OpenAI, or Google models when working with WinDbg. None of the models are very good at assembly and don't seem to be able to remember the details of different calling conventions or even how some of the registers are typically used. They are all pretty good at helping me navigate WinDbg though.

Re: Open Source Isn't Dead

#44
post #12

a lot of the vulnerabilities in web-apps are people trying to be too smart for their own good. use battle-tested frameworks such as Rails, Django then you won't make rookie security mistakes.

Except that Django got so many criticals we can't even list them on a thread here, but yeah, using known and ancient frameworks is generally smart.

Re: Open Source Isn't Dead

#45

cofounder here going closed source does not mean we are not fighting fire with fire we are using a handful of internal AI vulnerability scanners for months now being open source simply reduces risk by 5x to 10x according to several security researchers we are working with https://cal.com/blog/continuous-ai-pentesting-vulnerability-...

I've always used and advocated for Cal.com because it's open source. I understand you need to make money and this is no longer the GTM, but don't lie about it.

Re: Open Source Isn't Dead

#46
Strix was so close to being the hero we deserve. I think these blue torches like strix should offer their services for free to open source ships out at sea. There are 3 wins here, GLOBAL GOOD WILL, testimonial and reviews, and market loyalty reward.
Post reply on HN