Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

Open source is dead. That’s not a statement we ever thought we’d make. Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once...

1,566,770 Aufrufe • vor 5 Monaten •via X (Twitter)

51 Kommentare

Profilbild von ThePrimeagen
ThePrimeagenvor 5 Monaten

@calcom

Profilbild von Simon Willison
Simon Willisonvor 5 Monaten

@calcom Did you see this piece by @dbreunig? He argues that the cost of locking down software through LLM analysis makes open source MORE valuable now:

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom @dbreunig I don’t think that this is wrong - it’s just that this would require us to spend crazy budgets that we don’t have, and overall in our situation proves to be unfeasible. Closing source is the biggest method of risk reduction we can take right now to secure our customers

Profilbild von xlr8harder
xlr8hardervor 5 Monaten

@calcom Terrible decision. Open source will have the best security story in the long run because the number of bugs are finite. Obscurity won't save you, and it never has.

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom How are the number of bugs finite? We ship code constantly, meaning that there’s always going to be the possibility of introducing new bugs, and we need to be in the best possible position to defend against attackers discovering those bugs and exploiting them

Profilbild von xlr8harder
xlr8hardervor 5 Monaten

@calcom A new equilibrium will be reached that benefits defenders, just like other cybersecurity innovation (e.g. fuzzers) Steady state probably looks something like every line of code gets reviewed in detail by AI experts before commits go through.

Profilbild von prom
promvor 5 Monaten

@pumfleet @calcom > every line of code gets reviewed in detail by ai experts perhaps in a decade when compute gets cheap enough. this isn’t going to happen anytime soon

Profilbild von xlr8harder
xlr8hardervor 5 Monaten

@pumfleet @calcom i think there's a good chance this will be one of the highest demand uses of ai in the next 6-12 months if the cybersecurity arms race I'm anticipating materializes. i get why Bailey wants to defend from that, it's not wrong to worry about, i just disagree on the tactic

Profilbild von Félix Malfait
Félix Malfaitvor 5 Monaten

Love you guys but you’re better than this "open source is dead" shitposting. Security by obscurity has never been a good solution. Closing the repo buys time but at the end of the day if the vulnerabilities remains then AI will also make it much easier to reverse engineer at the API layer / perform mass injection, etc.

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom It's not meant to be shitposting. I genuinely believe that AI is getting to the point where almost anything is exploitable, and according to Hex Security, OSS is 5-10x more exploitable than closed source. So there's probably not that much left in OSS that can't be hacked by AI.

Profilbild von Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭vor 5 Monaten

@calcom

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom As much as I’d love to have balls, I’d even more love to not be the headline of TechCrunch saying how customer’s calendar data was breached because we didn’t take the option on the table to go closed source

Profilbild von Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭vor 5 Monaten

@calcom cutting your code off from the white hats of the world is a silly way to deal with those fears. but I’m sure security through obscurity will work THIS time, surely!

Profilbild von Rafael Aleksandryan
Rafael Aleksandryanvor 5 Monaten

@pumfleet @calcom Pliny coming in hot, if anything it's actually now going to make things worse. Now, bad actors will be the only ones with the incentive to break it versus security hobbyists and big bounty hunters doing so.

Profilbild von Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭vor 5 Monaten

@EffortDefines @pumfleet @calcom

Profilbild von GitHub Projects Community
GitHub Projects Communityvor 5 Monaten

@calcom Open-source is not dead. You just need to be adaptable.

Profilbild von Tudor Golubenco
Tudor Golubencovor 5 Monaten

@calcom Funny, we just went the opposite direction:

Profilbild von Clayton Kohler
Clayton Kohlervor 5 Monaten

Switch from open to closed core does not address the underlying problem though. This makes it harder for code to be exploited, but it will eventually happen regardless with AI over time. We should start planning for the future we start giving access to more information so that that exploitation is not incentivized.

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom I agree, and going closed source isn't a complete fix. We're putting in tons of investment to secure in other ways, it's just that going closed source is just one way that we can massively reduce risk.

Profilbild von Veros
Verosvor 5 Monaten

@calcom What!!! this is such a backward thinking in my honest opinion, if you can prove your code is secure publicly, then you can always claim that you're secure. In todays world, being open source means being confident and accountable to what you delivered. Not the other way around.

Profilbild von Nick Khami
Nick Khamivor 5 Monaten

@calcom wowow, this is absolutely insane. cal is the last company i ever thought would go closed source

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom Honestly, me too, but we don't see that we have any other choice. Nothing about this is for marketing or business reasons. It's just the decision that we believe protects our customers best.

Profilbild von Sunny Golovine
Sunny Golovinevor 5 Monaten

@calcom Honestly that sucks. While I never used I used that codebase dozens of times over the years as a solid reference for how to architect things in a large code base.

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify. Just production application is moving to closed source.

Profilbild von ryuz
ryuzvor 5 Monaten

@calcom Guys, it's the 15th, not April Fools' Day.

Profilbild von Adam
Adamvor 5 Monaten

this is a retard take, I’m sorry - 1. Your code had already been open sourced, so unless you dramatically change everything, you are not saving anyone from vulnerabilities anytime soon. 2. You say AI is so capable and this and that, but you are aware that having your code open is not the only (and not the main) way of compromising your platform? “AI is GOD but only if we won’t open source the little new stuff we release from now on, after we’ve been in prod for years while open source, we will be safe” sure, bro 3. You do this at time when software is actually much easier to iterate on, when it becomes less proprietary - why? I love and use Cal, it’s a great product - but I genuinely don’t see the reasoning much. Especially not calling “Open source is dead”, like sure - build your brand, scale your company while riding on the community , then close it when series B investors are no longer comfortable with it

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

As part of this announcement, we did already say that we have rewritten massive parts of the codebase. The private codebase running is very diverged from any OSS release we've put out before. Of course it's not the only way, and I did address this in my post too. It's just one tool that we have available to us which massively reduces our risk. Most of our strategy revolves around other things: multiple AI vulnerability scanners, human pentesters and rigorous processes, but closing source is a valid option on the table for us, and why would I not take a significant risk reduction to our security if it was available to me? It's just one of many things we can do in response.

Profilbild von Nizzy
Nizzyvor 5 Monaten

@calcom

Profilbild von Peter Pistorius
Peter Pistoriusvor 5 Monaten

@calcom How do these two statements work: "Open source is dead." "We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify." Are you just releasing code, but not participating in open source?

Profilbild von Bhushan Mishra
Bhushan Mishravor 5 Monaten

Your decision to close the core — your business, your call. But “AI has fundamentally altered security, transparency = exposure” still feels like spin. Automated scanning and exploits aren’t new; many critical OSS projects (Linux, Postgres, etc.) handle them daily without closing up.

Profilbild von Bailey Pumfleet
Bailey Pumfleetvor 5 Monaten

@calcom Do they, though? BSD, one of the most secure open-source projects, had a 27-year-old vulnerability that was discovered by Anthropic Mythos. React Server Components had multiple vulnerabilities recently too. Times are changing, and we've just got to respond as best as we can.

Profilbild von Bhushan Mishra
Bhushan Mishravor 5 Monaten

@pumfleet @calcom Exactly

Profilbild von Josh
Joshvor 5 Monaten

@calcom Good move. I'm a fan and contribute back to open source as often as I can, but I'd never open source the core code to a product I am building as a business. That's a easy way to open yourself up to unnecessary struggles.

Profilbild von nisten
nistenvor 5 Monaten

@calcom Ok so if it's dead show me what you used after deleting all pip and npm packages in your products? Ah ok, so it's NOT dead then carry on

Profilbild von geoff
geoffvor 5 Monaten

@calcom tbh been saying this for circa 9 months now. OSS doesn’t make sense when you can take full control of supply chain via generation.

Profilbild von Muratcan Koylan
Muratcan Koylanvor 5 Monaten

@calcom Cancelling my subscription

Profilbild von gary IH fung
gary IH fungvor 5 Monaten

@calcom bullshit. Strong ai can reverse engineer without source just fine. And same ai that exploits can also fix bugs and increase security against exploits before code even gets deployed it's entirely your choice to close source, but don't virtue signal.

Profilbild von Jason Kneen
Jason Kneenvor 5 Monaten

So if I understanding this you're going to close source your product because you don't want people to look for vulnerabilities and report them to you. So you're going to hide your code with all the possible vulnerabilities that you yourself are saying you don't have any way of checking for because "a single unit test doesn't exist to test vulnerabilities". And the conclusion that is made from all this is that open source is dead?

Profilbild von OpenAgents
OpenAgentsvor 5 Monaten

@calcom Nah

Profilbild von Aaron
Aaronvor 5 Monaten

@calcom what

Profilbild von amrit
amritvor 5 Monaten

@calcom damn

Profilbild von zooko🛡🦓🦓🦓 ⓩ
zooko🛡🦓🦓🦓 ⓩvor 5 Monaten

@calcom I once spoke with an experienced reverse engineer who assured me that it was *easier* to develop exploits against binaries than against source code. I was surprised! I wonder if that will be true of AIs?

Profilbild von Michael Arnaldi
Michael Arnaldivor 5 Monaten

@calcom Security through obscurity is never a good idea, sure having access to the source code makes hacking it easier but it also allows for more eyes to report issues faster, and truth to be told 90% of hacks are because of people not because of software. Anyway whatever works for you!

Profilbild von AbuMuslim (أبومُسْلِم)
AbuMuslim (أبومُسْلِم)vor 5 Monaten

Was built on open source, using open source, and now we want to go closed source. Reshaping the world for the worse and dragging us back to the 60s and 70s, when gatekeeping was the norm. Closing the source of a product will not make you safe the way people think. If you look closely, you will notice that adversaries still target products like Microsoft’s in their campaigns. One way or another, you will still be relying on OSS in your project. Once that gets compromised, you will be affected too. People will gain nothing from this other than more gatekeeping and dragging us back to the freakin caves.

Profilbild von Kartik
Kartikvor 5 Monaten

@calcom really sad to hear this.

Profilbild von Proziam
Proziamvor 5 Monaten

@calcom Nah. This argument isn't compelling, sorry. This reads like a security-washing of your commercial interests.

Profilbild von Michael Ramos
Michael Ramosvor 5 Monaten

@calcom Thoughtful argument in the wrong ways. And wrong message to publicize. You’re right to fear - just say you’re closing for commercial reasons without neglecting the entire history of the argument.

Profilbild von andrew
andrewvor 5 Monaten

@calcom The hand-wringing over this is from the younger crowd that didn't know webdev or programming before open source went wide. This is how it used to be and it was fine. The call makes sense to me.

Profilbild von Zack Chapple
Zack Chapplevor 5 Monaten

@calcom Thought this was an April fools post that got bubbled up again

Profilbild von skot
skotvor 5 Monaten

@calcom Security by obscurity? Good luck with that.

Profilbild von Justin Giudici
Justin Giudicivor 5 Monaten

@calcom Saying opensource is dead Is a bizarre statement just because in your specific circumstance you have decided to go closed source. The world runs on open source software and AI is increasing that reality if anything

Ähnliche Videos

Open source software is GREAT. But "open source" AI is NOT like software - it's VERY different. Rob Miles cuts through the bullshit: ROB: Oh, hey, Meta. I heard Llama's weights leaked. That's rough, man. Information security's hard. How you holding up? META: Oh, we're great. Yeah, we're fine. We... actually, that was deliberate. We meant to do that. ROB MILES: Oh, really? META: Yeah... well, the second time anyway. It's called open source. Look it up. ROB MILES: Oh. Well, I love free and open source software, but do those principles really apply to network weights? How does that work? META: Open source is good for users because it lets them read the source code and see what the program is really doing and how it works. ROB MILES: Wait, have you found a way to tell how a model works by looking at its weights? META: No. But, it lets developers all over the world spot bugs in the code and submit patches. ROB: Wait, people are fixing bugs in Llama's weights? META: Well, no. People can fine tune it themselves, though. ROB: ?? Other companies offer fine tuning through APIs. ... So, hang on, if you can't actually read the code and know what it's doing, then network weights are effectively a compiled binary. So, in what sense is this open source? Why not call it like public weights? Why call it open source at all? META: I love open source. ROB: Well, I know a lot of your employees do, but you don't love anything. You're a giant corporation. What's in it for you? META: I love, love open source.

AI Notkilleveryoneism Memes ⏸️

107,362 Aufrufe • vor 2 Jahren