Loading video...

Video Failed to Load

Go Home

Open source is dead. That’s not a statement we ever thought we’d make. Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once...

1,566,770 views • 5 months ago •via X (Twitter)

51 Comments

ThePrimeagen's profile picture
ThePrimeagen5 months ago

@calcom

Simon Willison's profile picture
Simon Willison5 months ago

@calcom Did you see this piece by @dbreunig? He argues that the cost of locking down software through LLM analysis makes open source MORE valuable now:

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom @dbreunig I don’t think that this is wrong - it’s just that this would require us to spend crazy budgets that we don’t have, and overall in our situation proves to be unfeasible. Closing source is the biggest method of risk reduction we can take right now to secure our customers

xlr8harder's profile picture
xlr8harder5 months ago

@calcom Terrible decision. Open source will have the best security story in the long run because the number of bugs are finite. Obscurity won't save you, and it never has.

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom How are the number of bugs finite? We ship code constantly, meaning that there’s always going to be the possibility of introducing new bugs, and we need to be in the best possible position to defend against attackers discovering those bugs and exploiting them

xlr8harder's profile picture
xlr8harder5 months ago

@calcom A new equilibrium will be reached that benefits defenders, just like other cybersecurity innovation (e.g. fuzzers) Steady state probably looks something like every line of code gets reviewed in detail by AI experts before commits go through.

prom's profile picture
prom5 months ago

@pumfleet @calcom > every line of code gets reviewed in detail by ai experts perhaps in a decade when compute gets cheap enough. this isn’t going to happen anytime soon

xlr8harder's profile picture
xlr8harder5 months ago

@pumfleet @calcom i think there's a good chance this will be one of the highest demand uses of ai in the next 6-12 months if the cybersecurity arms race I'm anticipating materializes. i get why Bailey wants to defend from that, it's not wrong to worry about, i just disagree on the tactic

Félix Malfait's profile picture
Félix Malfait5 months ago

Love you guys but you’re better than this "open source is dead" shitposting. Security by obscurity has never been a good solution. Closing the repo buys time but at the end of the day if the vulnerabilities remains then AI will also make it much easier to reverse engineer at the API layer / perform mass injection, etc.

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom It's not meant to be shitposting. I genuinely believe that AI is getting to the point where almost anything is exploitable, and according to Hex Security, OSS is 5-10x more exploitable than closed source. So there's probably not that much left in OSS that can't be hacked by AI.

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭's profile picture
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 months ago

@calcom

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom As much as I’d love to have balls, I’d even more love to not be the headline of TechCrunch saying how customer’s calendar data was breached because we didn’t take the option on the table to go closed source

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭's profile picture
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 months ago

@calcom cutting your code off from the white hats of the world is a silly way to deal with those fears. but I’m sure security through obscurity will work THIS time, surely!

Rafael Aleksandryan's profile picture
Rafael Aleksandryan5 months ago

@pumfleet @calcom Pliny coming in hot, if anything it's actually now going to make things worse. Now, bad actors will be the only ones with the incentive to break it versus security hobbyists and big bounty hunters doing so.

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭's profile picture
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 months ago

@EffortDefines @pumfleet @calcom

GitHub Projects Community's profile picture
GitHub Projects Community5 months ago

@calcom Open-source is not dead. You just need to be adaptable.

Tudor Golubenco's profile picture
Tudor Golubenco5 months ago

@calcom Funny, we just went the opposite direction:

Clayton Kohler's profile picture
Clayton Kohler5 months ago

Switch from open to closed core does not address the underlying problem though. This makes it harder for code to be exploited, but it will eventually happen regardless with AI over time. We should start planning for the future we start giving access to more information so that that exploitation is not incentivized.

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom I agree, and going closed source isn't a complete fix. We're putting in tons of investment to secure in other ways, it's just that going closed source is just one way that we can massively reduce risk.

Veros's profile picture
Veros5 months ago

@calcom What!!! this is such a backward thinking in my honest opinion, if you can prove your code is secure publicly, then you can always claim that you're secure. In todays world, being open source means being confident and accountable to what you delivered. Not the other way around.

Nick Khami's profile picture
Nick Khami5 months ago

@calcom wowow, this is absolutely insane. cal is the last company i ever thought would go closed source

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom Honestly, me too, but we don't see that we have any other choice. Nothing about this is for marketing or business reasons. It's just the decision that we believe protects our customers best.

Sunny Golovine's profile picture
Sunny Golovine5 months ago

@calcom Honestly that sucks. While I never used I used that codebase dozens of times over the years as a solid reference for how to architect things in a large code base.

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify. Just production application is moving to closed source.

ryuz's profile picture
ryuz5 months ago

@calcom Guys, it's the 15th, not April Fools' Day.

Adam's profile picture
Adam5 months ago

this is a retard take, I’m sorry - 1. Your code had already been open sourced, so unless you dramatically change everything, you are not saving anyone from vulnerabilities anytime soon. 2. You say AI is so capable and this and that, but you are aware that having your code open is not the only (and not the main) way of compromising your platform? “AI is GOD but only if we won’t open source the little new stuff we release from now on, after we’ve been in prod for years while open source, we will be safe” sure, bro 3. You do this at time when software is actually much easier to iterate on, when it becomes less proprietary - why? I love and use Cal, it’s a great product - but I genuinely don’t see the reasoning much. Especially not calling “Open source is dead”, like sure - build your brand, scale your company while riding on the community , then close it when series B investors are no longer comfortable with it

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

As part of this announcement, we did already say that we have rewritten massive parts of the codebase. The private codebase running is very diverged from any OSS release we've put out before. Of course it's not the only way, and I did address this in my post too. It's just one tool that we have available to us which massively reduces our risk. Most of our strategy revolves around other things: multiple AI vulnerability scanners, human pentesters and rigorous processes, but closing source is a valid option on the table for us, and why would I not take a significant risk reduction to our security if it was available to me? It's just one of many things we can do in response.

Nizzy's profile picture
Nizzy5 months ago

@calcom

Peter Pistorius's profile picture
Peter Pistorius5 months ago

@calcom How do these two statements work: "Open source is dead." "We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify." Are you just releasing code, but not participating in open source?

Bhushan Mishra's profile picture
Bhushan Mishra5 months ago

Your decision to close the core — your business, your call. But “AI has fundamentally altered security, transparency = exposure” still feels like spin. Automated scanning and exploits aren’t new; many critical OSS projects (Linux, Postgres, etc.) handle them daily without closing up.

Bailey Pumfleet's profile picture
Bailey Pumfleet5 months ago

@calcom Do they, though? BSD, one of the most secure open-source projects, had a 27-year-old vulnerability that was discovered by Anthropic Mythos. React Server Components had multiple vulnerabilities recently too. Times are changing, and we've just got to respond as best as we can.

Bhushan Mishra's profile picture
Bhushan Mishra5 months ago

@pumfleet @calcom Exactly

Josh's profile picture
Josh5 months ago

@calcom Good move. I'm a fan and contribute back to open source as often as I can, but I'd never open source the core code to a product I am building as a business. That's a easy way to open yourself up to unnecessary struggles.

nisten's profile picture
nisten5 months ago

@calcom Ok so if it's dead show me what you used after deleting all pip and npm packages in your products? Ah ok, so it's NOT dead then carry on

geoff's profile picture
geoff5 months ago

@calcom tbh been saying this for circa 9 months now. OSS doesn’t make sense when you can take full control of supply chain via generation.

Muratcan Koylan's profile picture
Muratcan Koylan5 months ago

@calcom Cancelling my subscription

gary IH fung's profile picture
gary IH fung5 months ago

@calcom bullshit. Strong ai can reverse engineer without source just fine. And same ai that exploits can also fix bugs and increase security against exploits before code even gets deployed it's entirely your choice to close source, but don't virtue signal.

Jason Kneen's profile picture
Jason Kneen5 months ago

So if I understanding this you're going to close source your product because you don't want people to look for vulnerabilities and report them to you. So you're going to hide your code with all the possible vulnerabilities that you yourself are saying you don't have any way of checking for because "a single unit test doesn't exist to test vulnerabilities". And the conclusion that is made from all this is that open source is dead?

OpenAgents's profile picture
OpenAgents5 months ago

@calcom Nah

Aaron's profile picture
Aaron5 months ago

@calcom what

amrit's profile picture
amrit5 months ago

@calcom damn

zooko🛡🦓🦓🦓 ⓩ's profile picture
zooko🛡🦓🦓🦓 ⓩ5 months ago

@calcom I once spoke with an experienced reverse engineer who assured me that it was *easier* to develop exploits against binaries than against source code. I was surprised! I wonder if that will be true of AIs?

Michael Arnaldi's profile picture
Michael Arnaldi5 months ago

@calcom Security through obscurity is never a good idea, sure having access to the source code makes hacking it easier but it also allows for more eyes to report issues faster, and truth to be told 90% of hacks are because of people not because of software. Anyway whatever works for you!

AbuMuslim (أبومُسْلِم)'s profile picture
AbuMuslim (أبومُسْلِم)5 months ago

Was built on open source, using open source, and now we want to go closed source. Reshaping the world for the worse and dragging us back to the 60s and 70s, when gatekeeping was the norm. Closing the source of a product will not make you safe the way people think. If you look closely, you will notice that adversaries still target products like Microsoft’s in their campaigns. One way or another, you will still be relying on OSS in your project. Once that gets compromised, you will be affected too. People will gain nothing from this other than more gatekeeping and dragging us back to the freakin caves.

Kartik's profile picture
Kartik5 months ago

@calcom really sad to hear this.

Proziam's profile picture
Proziam5 months ago

@calcom Nah. This argument isn't compelling, sorry. This reads like a security-washing of your commercial interests.

Michael Ramos's profile picture
Michael Ramos5 months ago

@calcom Thoughtful argument in the wrong ways. And wrong message to publicize. You’re right to fear - just say you’re closing for commercial reasons without neglecting the entire history of the argument.

andrew's profile picture
andrew5 months ago

@calcom The hand-wringing over this is from the younger crowd that didn't know webdev or programming before open source went wide. This is how it used to be and it was fine. The call makes sense to me.

Zack Chapple's profile picture
Zack Chapple5 months ago

@calcom Thought this was an April fools post that got bubbled up again

skot's profile picture
skot5 months ago

@calcom Security by obscurity? Good luck with that.

Justin Giudici's profile picture
Justin Giudici5 months ago

@calcom Saying opensource is dead Is a bizarre statement just because in your specific circumstance you have decided to go closed source. The world runs on open source software and AI is increasing that reality if anything

Related Videos

Open source software is GREAT. But "open source" AI is NOT like software - it's VERY different. Rob Miles cuts through the bullshit: ROB: Oh, hey, Meta. I heard Llama's weights leaked. That's rough, man. Information security's hard. How you holding up? META: Oh, we're great. Yeah, we're fine. We... actually, that was deliberate. We meant to do that. ROB MILES: Oh, really? META: Yeah... well, the second time anyway. It's called open source. Look it up. ROB MILES: Oh. Well, I love free and open source software, but do those principles really apply to network weights? How does that work? META: Open source is good for users because it lets them read the source code and see what the program is really doing and how it works. ROB MILES: Wait, have you found a way to tell how a model works by looking at its weights? META: No. But, it lets developers all over the world spot bugs in the code and submit patches. ROB: Wait, people are fixing bugs in Llama's weights? META: Well, no. People can fine tune it themselves, though. ROB: ?? Other companies offer fine tuning through APIs. ... So, hang on, if you can't actually read the code and know what it's doing, then network weights are effectively a compiled binary. So, in what sense is this open source? Why not call it like public weights? Why call it open source at all? META: I love open source. ROB: Well, I know a lot of your employees do, but you don't love anything. You're a giant corporation. What's in it for you? META: I love, love open source.

AI Notkilleveryoneism Memes ⏸️

107,362 views • 2 years ago