Loading video...
Video Failed to Load
Open source is dead. That’s not a statement we ever thought we’d make. Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once... show more
1,566,770 views • 5 months ago •via X (Twitter)
51 Comments

@calcom

@calcom Did you see this piece by @dbreunig? He argues that the cost of locking down software through LLM analysis makes open source MORE valuable now:

@calcom @dbreunig I don’t think that this is wrong - it’s just that this would require us to spend crazy budgets that we don’t have, and overall in our situation proves to be unfeasible. Closing source is the biggest method of risk reduction we can take right now to secure our customers

@calcom Terrible decision. Open source will have the best security story in the long run because the number of bugs are finite. Obscurity won't save you, and it never has.

@calcom How are the number of bugs finite? We ship code constantly, meaning that there’s always going to be the possibility of introducing new bugs, and we need to be in the best possible position to defend against attackers discovering those bugs and exploiting them

@calcom A new equilibrium will be reached that benefits defenders, just like other cybersecurity innovation (e.g. fuzzers) Steady state probably looks something like every line of code gets reviewed in detail by AI experts before commits go through.

@pumfleet @calcom > every line of code gets reviewed in detail by ai experts perhaps in a decade when compute gets cheap enough. this isn’t going to happen anytime soon

@pumfleet @calcom i think there's a good chance this will be one of the highest demand uses of ai in the next 6-12 months if the cybersecurity arms race I'm anticipating materializes. i get why Bailey wants to defend from that, it's not wrong to worry about, i just disagree on the tactic

Love you guys but you’re better than this "open source is dead" shitposting. Security by obscurity has never been a good solution. Closing the repo buys time but at the end of the day if the vulnerabilities remains then AI will also make it much easier to reverse engineer at the API layer / perform mass injection, etc.

@calcom It's not meant to be shitposting. I genuinely believe that AI is getting to the point where almost anything is exploitable, and according to Hex Security, OSS is 5-10x more exploitable than closed source. So there's probably not that much left in OSS that can't be hacked by AI.

@calcom

@calcom As much as I’d love to have balls, I’d even more love to not be the headline of TechCrunch saying how customer’s calendar data was breached because we didn’t take the option on the table to go closed source

@calcom cutting your code off from the white hats of the world is a silly way to deal with those fears. but I’m sure security through obscurity will work THIS time, surely!

@pumfleet @calcom Pliny coming in hot, if anything it's actually now going to make things worse. Now, bad actors will be the only ones with the incentive to break it versus security hobbyists and big bounty hunters doing so.

@EffortDefines @pumfleet @calcom

@calcom Open-source is not dead. You just need to be adaptable.

@calcom Funny, we just went the opposite direction:

Switch from open to closed core does not address the underlying problem though. This makes it harder for code to be exploited, but it will eventually happen regardless with AI over time. We should start planning for the future we start giving access to more information so that that exploitation is not incentivized.

@calcom I agree, and going closed source isn't a complete fix. We're putting in tons of investment to secure in other ways, it's just that going closed source is just one way that we can massively reduce risk.

@calcom What!!! this is such a backward thinking in my honest opinion, if you can prove your code is secure publicly, then you can always claim that you're secure. In todays world, being open source means being confident and accountable to what you delivered. Not the other way around.

@calcom wowow, this is absolutely insane. cal is the last company i ever thought would go closed source

@calcom Honestly, me too, but we don't see that we have any other choice. Nothing about this is for marketing or business reasons. It's just the decision that we believe protects our customers best.

@calcom Honestly that sucks. While I never used I used that codebase dozens of times over the years as a solid reference for how to architect things in a large code base.

@calcom We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify. Just production application is moving to closed source.

@calcom Guys, it's the 15th, not April Fools' Day.

this is a retard take, I’m sorry - 1. Your code had already been open sourced, so unless you dramatically change everything, you are not saving anyone from vulnerabilities anytime soon. 2. You say AI is so capable and this and that, but you are aware that having your code open is not the only (and not the main) way of compromising your platform? “AI is GOD but only if we won’t open source the little new stuff we release from now on, after we’ve been in prod for years while open source, we will be safe” sure, bro 3. You do this at time when software is actually much easier to iterate on, when it becomes less proprietary - why? I love and use Cal, it’s a great product - but I genuinely don’t see the reasoning much. Especially not calling “Open source is dead”, like sure - build your brand, scale your company while riding on the community , then close it when series B investors are no longer comfortable with it

As part of this announcement, we did already say that we have rewritten massive parts of the codebase. The private codebase running is very diverged from any OSS release we've put out before. Of course it's not the only way, and I did address this in my post too. It's just one tool that we have available to us which massively reduces our risk. Most of our strategy revolves around other things: multiple AI vulnerability scanners, human pentesters and rigorous processes, but closing source is a valid option on the table for us, and why would I not take a significant risk reduction to our security if it was available to me? It's just one of many things we can do in response.

@calcom

@calcom How do these two statements work: "Open source is dead." "We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify." Are you just releasing code, but not participating in open source?

Your decision to close the core — your business, your call. But “AI has fundamentally altered security, transparency = exposure” still feels like spin. Automated scanning and exploits aren’t new; many critical OSS projects (Linux, Postgres, etc.) handle them daily without closing up.

@calcom Do they, though? BSD, one of the most secure open-source projects, had a 27-year-old vulnerability that was discovered by Anthropic Mythos. React Server Components had multiple vulnerabilities recently too. Times are changing, and we've just got to respond as best as we can.

@pumfleet @calcom Exactly

@calcom Good move. I'm a fan and contribute back to open source as often as I can, but I'd never open source the core code to a product I am building as a business. That's a easy way to open yourself up to unnecessary struggles.

@calcom Ok so if it's dead show me what you used after deleting all pip and npm packages in your products? Ah ok, so it's NOT dead then carry on

@calcom tbh been saying this for circa 9 months now. OSS doesn’t make sense when you can take full control of supply chain via generation.

@calcom Cancelling my subscription

@calcom bullshit. Strong ai can reverse engineer without source just fine. And same ai that exploits can also fix bugs and increase security against exploits before code even gets deployed it's entirely your choice to close source, but don't virtue signal.

So if I understanding this you're going to close source your product because you don't want people to look for vulnerabilities and report them to you. So you're going to hide your code with all the possible vulnerabilities that you yourself are saying you don't have any way of checking for because "a single unit test doesn't exist to test vulnerabilities". And the conclusion that is made from all this is that open source is dead?

@calcom Nah

@calcom what

@calcom damn

@calcom I once spoke with an experienced reverse engineer who assured me that it was *easier* to develop exploits against binaries than against source code. I was surprised! I wonder if that will be true of AIs?

@calcom Security through obscurity is never a good idea, sure having access to the source code makes hacking it easier but it also allows for more eyes to report issues faster, and truth to be told 90% of hacks are because of people not because of software. Anyway whatever works for you!

Was built on open source, using open source, and now we want to go closed source. Reshaping the world for the worse and dragging us back to the 60s and 70s, when gatekeeping was the norm. Closing the source of a product will not make you safe the way people think. If you look closely, you will notice that adversaries still target products like Microsoft’s in their campaigns. One way or another, you will still be relying on OSS in your project. Once that gets compromised, you will be affected too. People will gain nothing from this other than more gatekeeping and dragging us back to the freakin caves.

@calcom really sad to hear this.

@calcom Nah. This argument isn't compelling, sorry. This reads like a security-washing of your commercial interests.

@calcom Thoughtful argument in the wrong ways. And wrong message to publicize. You’re right to fear - just say you’re closing for commercial reasons without neglecting the entire history of the argument.

@calcom The hand-wringing over this is from the younger crowd that didn't know webdev or programming before open source went wide. This is how it used to be and it was fine. The call makes sense to me.

@calcom Thought this was an April fools post that got bubbled up again

@calcom Security by obscurity? Good luck with that.

@calcom Saying opensource is dead Is a bizarre statement just because in your specific circumstance you have decided to go closed source. The world runs on open source software and AI is increasing that reality if anything

