Live data from Hacker News

Open Source Isn't Dead

strix.ai

91–100 of 200 posts

Re: Open Source Isn't Dead

#91
post #88

All content is going to go behind paywalls. There is zero incentive or reason for content creators to let AI slurp their content for free and distribute it and get all the money from it. Everything new will be licensed and if AI companies want access to it, they will need to pay for it, just like we will.

Of course this neglects why mostly free things that were posted on the internet generally won. Take Microsoft for example. All their money makers are licensed, yet at the same time you can download almost every single one for free and install it. The people that go behind paywalls don't realize how much they'll have to spend on marketing to catch up to those that are open. And that's only frames the current state, wh…

Why would I create content that I don't get paid for and I don't even get credit for? Everyone who creates free content right now is simply doing the work of AI companies to make them more useful for free.

Search engines will cease to exist, so no one will search your content and then click on your link. AI will simply regurgitate your content and take the money for tokens or subscription and not acknowledge you at all.

Re: Open Source Isn't Dead

#92
post #60
post #3

I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.

I don't follow. It seems obvious that there's more to gain for attackers using AI agents to exploit open source repositories, than there is for good samaritan defenders. In this new closed-source world (for Cal.com), there's nothing stopping them from running their own internal security agent audits, all whilst at least blocking the easiest method of finding zero-days - that is, being open source. This really just se…

> It seems obvious that there's more to gain for attackers using AI agents to exploit open source repositories, than there is for good samaritan defenders.

Actually the opposite is obvious - the comment you replied too talked about an abundance of good Samaritan reports - it's strange to speculate on some nebulous "gain" when responding to facts about more then enough reports concerning open source code.

> In this new closed-source world (for Cal.com), there's nothing stopping them from running their own internal security agent audits

That's one good Samaritan for a closed source app vs many for an open source one. Open source wins again.

> any open-source business stands to lose way more

That doesn't make any sense - why would it lose more when it has many more good Samaritans working for it for free?

You seem to forget that the number of vulnerabilities in a certain app is finite, an open source app will reach a secure status much faster than a closed source one, in addition to also gaining from shorter time to market.

In fact, open source will soon be much better and more capable due to new and developing technological and organizational advancements which are next to impossible to happen under a closed source regime.

Re: Open Source Isn't Dead

#93
post #60
post #3

I have an open source project and started receiving a lot of security vulnerability reports in the last few months. A lot of them are extremely corner cases, but there were some legit ones. They're all fixed now. Closed source software won't receive any reports, but it will be exploited with AI. So I definitely agree with the message of this article.

I don't follow. It seems obvious that there's more to gain for attackers using AI agents to exploit open source repositories, than there is for good samaritan defenders. In this new closed-source world (for Cal.com), there's nothing stopping them from running their own internal security agent audits, all whilst at least blocking the easiest method of finding zero-days - that is, being open source. This really just se…

A new user is much more likely to scan the codebase and report vulnerabilities so they can be fixed than illegally exploit them since most people aren't criminals

Re: Open Source Isn't Dead

#94

cofounder here going closed source does not mean we are not fighting fire with fire we are using a handful of internal AI vulnerability scanners for months now being open source simply reduces risk by 5x to 10x according to several security researchers we are working with https://cal.com/blog/continuous-ai-pentesting-vulnerability-...

Don’t get me wrong but if virtually all modern software infrastructure lives on top of open source and they’re mostly fine then I’d imagine that you can make a scheduling webapp secure independent to if it’s OSS or not. It’s OK if there’s another reason for this transition, just be transparent about it and don’t treat your users as children.

They don’t owe you a complete list of reasons why they’re close sourcing their software. They are not a publicly traded company and no one (customers) actually cares if the product is open source or not.

Re: Open Source Isn't Dead

#95

I have a large open source project and noticed the number of LLM generate PR is making it unmanageable. Every two weeks, I go in, kill all of them and when someone complains or asks why, I realize it was a real person and then I merge it. is anyone else seeing this / fixed this problem ?

Yes, I "fixed" it by disabling pull requests on the repository. I'm still happy to pull from other people's branches (and do say so in CONTRIBUTING.md)

Re: Open Source Isn't Dead

#96
post #6

> The reasoning provided by their CEO, Bailey Pumfleet, is that AI has automated vulnerability discovery at scale, That sounds like an excuse. The real reason is probably that it's hard to make a viable business out of developing open source.

Exactly. I respect their decision to go closed source if that's what they need to do to make it a viable business, but just be honest about it. Don't make up some excuse around security and open source.

[flagged]

Re: Open Source Isn't Dead

#97
post #59

Brilliant piece of content marketing: 1) Pulls you in with a catchy title, that at first glance seems like a dunk on Cal.com (whatever that is). 2) Takes the "we understand your pain" approach to empathize w/ Cal.com, so you feel like you're on the good vibes side. 3) Provides a genuine response to the actual problem Cal.com is dealing with. Something you can't dismiss out of hand. 4) But in the end of the day, the r…

Is it good marketing though? I mean personally I do not use AI, and I don't think this opinion of mine will change. I can't look into the future, but right now I don't use nor do I depend on AI. I guess it may work for some people, but even then I am unsure whether that is really good marketing. Riding on a hype train (which AI right now still is) is indeed easier, so that has to be considered.

They are in HN front page, therefore it’s good marketing.

Re: Open Source Isn't Dead

#98
> The real solution: fight fire with fire

Which works if you assume that AI can find 100% of your bugs.

It can't. So this is a complete waste of your time and will hide actual bugs behind a layer of confidence _and_ obscurity.

You're going to actually have to sit down and figure out how to provide real security in your product while earning profits. This is called "work." I understand Silicon Valley would like to earn money and not work. I am eager for these people to get their comeuppance.

Re: Open Source Isn't Dead

#99
post #60

Earlier quoted context omitted.

I don't follow. It seems obvious that there's more to gain for attackers using AI agents to exploit open source repositories, than there is for good samaritan defenders. In this new closed-source world (for Cal.com), there's nothing stopping them from running their own internal security agent audits, all whilst at least blocking the easiest method of finding zero-days - that is, being open source. This really just se…

A new user is much more likely to scan the codebase and report vulnerabilities so they can be fixed than illegally exploit them since most people aren't criminals

Exactly. Who even hacks stuff? Most people will report the issue to earn xp and level up than actually exploit it.

Re: Open Source Isn't Dead

#100
post #88

Earlier quoted context omitted.

Of course this neglects why mostly free things that were posted on the internet generally won. Take Microsoft for example. All their money makers are licensed, yet at the same time you can download almost every single one for free and install it. The people that go behind paywalls don't realize how much they'll have to spend on marketing to catch up to those that are open. And that's only frames the current state, wh…

Why would I create content that I don't get paid for and I don't even get credit for? Everyone who creates free content right now is simply doing the work of AI companies to make them more useful for free. Search engines will cease to exist, so no one will search your content and then click on your link. AI will simply regurgitate your content and take the money for tokens or subscription and not acknowledge you at a…

>There isn't a rule of economics that says better technology makes more, better jobs for horses. It sounds shockingly dumb to even say that

--Humans need not apply.

It's kind of funny that you think you're going to be making money writing software. If you lock up your software who exactly are you selling it to anyway? It's like you're thinking 25% through the situation then going "I can stay where I am and I don't have to change anything", and then crying later when it doesn't work.

What are you going to do, advertise in BYTE magazine (dead). On Instagram? With a sandwich board on a Seattle street corner? What does the software market even look like in the AI age.

And much like how Google and Amazon eat your lunch now whenever they way, successful AI companies will buy up some software ideas and feed them to their models (which will be stolen later by other models). Anyone that sees your software will mock up a useful clone of it pretty quick the first time they see it. And foreign AI companies will just right out steal it.

You're right you won't create content that you don't get paid for, you just won't be creating anything while competing with the other unemployed masses for strawberry picking jobs.

Post reply on HN