Загрузка видео...

Не удалось загрузить видео

На главную

Open source is dead. That’s not a statement we ever thought we’d make. Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once...

1,566,770 просмотров • 5 месяцев назад •via X (Twitter)

Комментарии: 51

Фото профиля ThePrimeagen
ThePrimeagen5 месяцев назад

@calcom

Фото профиля Simon Willison
Simon Willison5 месяцев назад

@calcom Did you see this piece by @dbreunig? He argues that the cost of locking down software through LLM analysis makes open source MORE valuable now:

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom @dbreunig I don’t think that this is wrong - it’s just that this would require us to spend crazy budgets that we don’t have, and overall in our situation proves to be unfeasible. Closing source is the biggest method of risk reduction we can take right now to secure our customers

Фото профиля xlr8harder
xlr8harder5 месяцев назад

@calcom Terrible decision. Open source will have the best security story in the long run because the number of bugs are finite. Obscurity won't save you, and it never has.

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom How are the number of bugs finite? We ship code constantly, meaning that there’s always going to be the possibility of introducing new bugs, and we need to be in the best possible position to defend against attackers discovering those bugs and exploiting them

Фото профиля xlr8harder
xlr8harder5 месяцев назад

@calcom A new equilibrium will be reached that benefits defenders, just like other cybersecurity innovation (e.g. fuzzers) Steady state probably looks something like every line of code gets reviewed in detail by AI experts before commits go through.

Фото профиля prom
prom5 месяцев назад

@pumfleet @calcom > every line of code gets reviewed in detail by ai experts perhaps in a decade when compute gets cheap enough. this isn’t going to happen anytime soon

Фото профиля xlr8harder
xlr8harder5 месяцев назад

@pumfleet @calcom i think there's a good chance this will be one of the highest demand uses of ai in the next 6-12 months if the cybersecurity arms race I'm anticipating materializes. i get why Bailey wants to defend from that, it's not wrong to worry about, i just disagree on the tactic

Фото профиля Félix Malfait
Félix Malfait5 месяцев назад

Love you guys but you’re better than this "open source is dead" shitposting. Security by obscurity has never been a good solution. Closing the repo buys time but at the end of the day if the vulnerabilities remains then AI will also make it much easier to reverse engineer at the API layer / perform mass injection, etc.

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom It's not meant to be shitposting. I genuinely believe that AI is getting to the point where almost anything is exploitable, and according to Hex Security, OSS is 5-10x more exploitable than closed source. So there's probably not that much left in OSS that can't be hacked by AI.

Фото профиля Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 месяцев назад

@calcom

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom As much as I’d love to have balls, I’d even more love to not be the headline of TechCrunch saying how customer’s calendar data was breached because we didn’t take the option on the table to go closed source

Фото профиля Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 месяцев назад

@calcom cutting your code off from the white hats of the world is a silly way to deal with those fears. but I’m sure security through obscurity will work THIS time, surely!

Фото профиля Rafael Aleksandryan
Rafael Aleksandryan5 месяцев назад

@pumfleet @calcom Pliny coming in hot, if anything it's actually now going to make things worse. Now, bad actors will be the only ones with the incentive to break it versus security hobbyists and big bounty hunters doing so.

Фото профиля Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 месяцев назад

@EffortDefines @pumfleet @calcom

Фото профиля GitHub Projects Community
GitHub Projects Community5 месяцев назад

@calcom Open-source is not dead. You just need to be adaptable.

Фото профиля Tudor Golubenco
Tudor Golubenco5 месяцев назад

@calcom Funny, we just went the opposite direction:

Фото профиля Clayton Kohler
Clayton Kohler5 месяцев назад

Switch from open to closed core does not address the underlying problem though. This makes it harder for code to be exploited, but it will eventually happen regardless with AI over time. We should start planning for the future we start giving access to more information so that that exploitation is not incentivized.

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom I agree, and going closed source isn't a complete fix. We're putting in tons of investment to secure in other ways, it's just that going closed source is just one way that we can massively reduce risk.

Фото профиля Veros
Veros5 месяцев назад

@calcom What!!! this is such a backward thinking in my honest opinion, if you can prove your code is secure publicly, then you can always claim that you're secure. In todays world, being open source means being confident and accountable to what you delivered. Not the other way around.

Фото профиля Nick Khami
Nick Khami5 месяцев назад

@calcom wowow, this is absolutely insane. cal is the last company i ever thought would go closed source

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom Honestly, me too, but we don't see that we have any other choice. Nothing about this is for marketing or business reasons. It's just the decision that we believe protects our customers best.

Фото профиля Sunny Golovine
Sunny Golovine5 месяцев назад

@calcom Honestly that sucks. While I never used I used that codebase dozens of times over the years as a solid reference for how to architect things in a large code base.

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify. Just production application is moving to closed source.

Фото профиля ryuz
ryuz5 месяцев назад

@calcom Guys, it's the 15th, not April Fools' Day.

Фото профиля Adam
Adam5 месяцев назад

this is a retard take, I’m sorry - 1. Your code had already been open sourced, so unless you dramatically change everything, you are not saving anyone from vulnerabilities anytime soon. 2. You say AI is so capable and this and that, but you are aware that having your code open is not the only (and not the main) way of compromising your platform? “AI is GOD but only if we won’t open source the little new stuff we release from now on, after we’ve been in prod for years while open source, we will be safe” sure, bro 3. You do this at time when software is actually much easier to iterate on, when it becomes less proprietary - why? I love and use Cal, it’s a great product - but I genuinely don’t see the reasoning much. Especially not calling “Open source is dead”, like sure - build your brand, scale your company while riding on the community , then close it when series B investors are no longer comfortable with it

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

As part of this announcement, we did already say that we have rewritten massive parts of the codebase. The private codebase running is very diverged from any OSS release we've put out before. Of course it's not the only way, and I did address this in my post too. It's just one tool that we have available to us which massively reduces our risk. Most of our strategy revolves around other things: multiple AI vulnerability scanners, human pentesters and rigorous processes, but closing source is a valid option on the table for us, and why would I not take a significant risk reduction to our security if it was available to me? It's just one of many things we can do in response.

Фото профиля Nizzy
Nizzy5 месяцев назад

@calcom

Фото профиля Peter Pistorius
Peter Pistorius5 месяцев назад

@calcom How do these two statements work: "Open source is dead." "We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify." Are you just releasing code, but not participating in open source?

Фото профиля Bhushan Mishra
Bhushan Mishra5 месяцев назад

Your decision to close the core — your business, your call. But “AI has fundamentally altered security, transparency = exposure” still feels like spin. Automated scanning and exploits aren’t new; many critical OSS projects (Linux, Postgres, etc.) handle them daily without closing up.

Фото профиля Bailey Pumfleet
Bailey Pumfleet5 месяцев назад

@calcom Do they, though? BSD, one of the most secure open-source projects, had a 27-year-old vulnerability that was discovered by Anthropic Mythos. React Server Components had multiple vulnerabilities recently too. Times are changing, and we've just got to respond as best as we can.

Фото профиля Bhushan Mishra
Bhushan Mishra5 месяцев назад

@pumfleet @calcom Exactly

Фото профиля Josh
Josh5 месяцев назад

@calcom Good move. I'm a fan and contribute back to open source as often as I can, but I'd never open source the core code to a product I am building as a business. That's a easy way to open yourself up to unnecessary struggles.

Фото профиля nisten
nisten5 месяцев назад

@calcom Ok so if it's dead show me what you used after deleting all pip and npm packages in your products? Ah ok, so it's NOT dead then carry on

Фото профиля geoff
geoff5 месяцев назад

@calcom tbh been saying this for circa 9 months now. OSS doesn’t make sense when you can take full control of supply chain via generation.

Фото профиля Muratcan Koylan
Muratcan Koylan5 месяцев назад

@calcom Cancelling my subscription

Фото профиля gary IH fung
gary IH fung5 месяцев назад

@calcom bullshit. Strong ai can reverse engineer without source just fine. And same ai that exploits can also fix bugs and increase security against exploits before code even gets deployed it's entirely your choice to close source, but don't virtue signal.

Фото профиля Jason Kneen
Jason Kneen5 месяцев назад

So if I understanding this you're going to close source your product because you don't want people to look for vulnerabilities and report them to you. So you're going to hide your code with all the possible vulnerabilities that you yourself are saying you don't have any way of checking for because "a single unit test doesn't exist to test vulnerabilities". And the conclusion that is made from all this is that open source is dead?

Фото профиля OpenAgents
OpenAgents5 месяцев назад

@calcom Nah

Фото профиля Aaron
Aaron5 месяцев назад

@calcom what

Фото профиля amrit
amrit5 месяцев назад

@calcom damn

Фото профиля zooko🛡🦓🦓🦓 ⓩ
zooko🛡🦓🦓🦓 ⓩ5 месяцев назад

@calcom I once spoke with an experienced reverse engineer who assured me that it was *easier* to develop exploits against binaries than against source code. I was surprised! I wonder if that will be true of AIs?

Фото профиля Michael Arnaldi
Michael Arnaldi5 месяцев назад

@calcom Security through obscurity is never a good idea, sure having access to the source code makes hacking it easier but it also allows for more eyes to report issues faster, and truth to be told 90% of hacks are because of people not because of software. Anyway whatever works for you!

Фото профиля AbuMuslim (أبومُسْلِم)
AbuMuslim (أبومُسْلِم)5 месяцев назад

Was built on open source, using open source, and now we want to go closed source. Reshaping the world for the worse and dragging us back to the 60s and 70s, when gatekeeping was the norm. Closing the source of a product will not make you safe the way people think. If you look closely, you will notice that adversaries still target products like Microsoft’s in their campaigns. One way or another, you will still be relying on OSS in your project. Once that gets compromised, you will be affected too. People will gain nothing from this other than more gatekeeping and dragging us back to the freakin caves.

Фото профиля Kartik
Kartik5 месяцев назад

@calcom really sad to hear this.

Фото профиля Proziam
Proziam5 месяцев назад

@calcom Nah. This argument isn't compelling, sorry. This reads like a security-washing of your commercial interests.

Фото профиля Michael Ramos
Michael Ramos5 месяцев назад

@calcom Thoughtful argument in the wrong ways. And wrong message to publicize. You’re right to fear - just say you’re closing for commercial reasons without neglecting the entire history of the argument.

Фото профиля andrew
andrew5 месяцев назад

@calcom The hand-wringing over this is from the younger crowd that didn't know webdev or programming before open source went wide. This is how it used to be and it was fine. The call makes sense to me.

Фото профиля Zack Chapple
Zack Chapple5 месяцев назад

@calcom Thought this was an April fools post that got bubbled up again

Фото профиля skot
skot5 месяцев назад

@calcom Security by obscurity? Good luck with that.

Фото профиля Justin Giudici
Justin Giudici5 месяцев назад

@calcom Saying opensource is dead Is a bizarre statement just because in your specific circumstance you have decided to go closed source. The world runs on open source software and AI is increasing that reality if anything

Похожие видео

Open source software is GREAT. But "open source" AI is NOT like software - it's VERY different. Rob Miles cuts through the bullshit: ROB: Oh, hey, Meta. I heard Llama's weights leaked. That's rough, man. Information security's hard. How you holding up? META: Oh, we're great. Yeah, we're fine. We... actually, that was deliberate. We meant to do that. ROB MILES: Oh, really? META: Yeah... well, the second time anyway. It's called open source. Look it up. ROB MILES: Oh. Well, I love free and open source software, but do those principles really apply to network weights? How does that work? META: Open source is good for users because it lets them read the source code and see what the program is really doing and how it works. ROB MILES: Wait, have you found a way to tell how a model works by looking at its weights? META: No. But, it lets developers all over the world spot bugs in the code and submit patches. ROB: Wait, people are fixing bugs in Llama's weights? META: Well, no. People can fine tune it themselves, though. ROB: ?? Other companies offer fine tuning through APIs. ... So, hang on, if you can't actually read the code and know what it's doing, then network weights are effectively a compiled binary. So, in what sense is this open source? Why not call it like public weights? Why call it open source at all? META: I love open source. ROB: Well, I know a lot of your employees do, but you don't love anything. You're a giant corporation. What's in it for you? META: I love, love open source.

AI Notkilleveryoneism Memes ⏸️

107,362 просмотров • 2 лет назад