Video yükleniyor...

Video Yüklenemedi

Ana Sayfaya Dön

Open source is dead. That’s not a statement we ever thought we’d make. Cal.com was built on open source. It shaped our product, our community, and our growth. But the world has changed faster than our principles could keep up. AI has fundamentally altered the security landscape. What once...

1,566,770 görüntüleme • 5 ay önce •via X (Twitter)

51 Yorum

ThePrimeagen profil fotoğrafı
ThePrimeagen5 ay önce

@calcom

Simon Willison profil fotoğrafı
Simon Willison5 ay önce

@calcom Did you see this piece by @dbreunig? He argues that the cost of locking down software through LLM analysis makes open source MORE valuable now:

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom @dbreunig I don’t think that this is wrong - it’s just that this would require us to spend crazy budgets that we don’t have, and overall in our situation proves to be unfeasible. Closing source is the biggest method of risk reduction we can take right now to secure our customers

xlr8harder profil fotoğrafı
xlr8harder5 ay önce

@calcom Terrible decision. Open source will have the best security story in the long run because the number of bugs are finite. Obscurity won't save you, and it never has.

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom How are the number of bugs finite? We ship code constantly, meaning that there’s always going to be the possibility of introducing new bugs, and we need to be in the best possible position to defend against attackers discovering those bugs and exploiting them

xlr8harder profil fotoğrafı
xlr8harder5 ay önce

@calcom A new equilibrium will be reached that benefits defenders, just like other cybersecurity innovation (e.g. fuzzers) Steady state probably looks something like every line of code gets reviewed in detail by AI experts before commits go through.

prom profil fotoğrafı
prom5 ay önce

@pumfleet @calcom > every line of code gets reviewed in detail by ai experts perhaps in a decade when compute gets cheap enough. this isn’t going to happen anytime soon

xlr8harder profil fotoğrafı
xlr8harder5 ay önce

@pumfleet @calcom i think there's a good chance this will be one of the highest demand uses of ai in the next 6-12 months if the cybersecurity arms race I'm anticipating materializes. i get why Bailey wants to defend from that, it's not wrong to worry about, i just disagree on the tactic

Félix Malfait profil fotoğrafı
Félix Malfait5 ay önce

Love you guys but you’re better than this "open source is dead" shitposting. Security by obscurity has never been a good solution. Closing the repo buys time but at the end of the day if the vulnerabilities remains then AI will also make it much easier to reverse engineer at the API layer / perform mass injection, etc.

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom It's not meant to be shitposting. I genuinely believe that AI is getting to the point where almost anything is exploitable, and according to Hex Security, OSS is 5-10x more exploitable than closed source. So there's probably not that much left in OSS that can't be hacked by AI.

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 profil fotoğrafı
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 ay önce

@calcom

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom As much as I’d love to have balls, I’d even more love to not be the headline of TechCrunch saying how customer’s calendar data was breached because we didn’t take the option on the table to go closed source

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 profil fotoğrafı
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 ay önce

@calcom cutting your code off from the white hats of the world is a silly way to deal with those fears. but I’m sure security through obscurity will work THIS time, surely!

Rafael Aleksandryan profil fotoğrafı
Rafael Aleksandryan5 ay önce

@pumfleet @calcom Pliny coming in hot, if anything it's actually now going to make things worse. Now, bad actors will be the only ones with the incentive to break it versus security hobbyists and big bounty hunters doing so.

Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 profil fotoğrafı
Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭5 ay önce

@EffortDefines @pumfleet @calcom

GitHub Projects Community profil fotoğrafı
GitHub Projects Community5 ay önce

@calcom Open-source is not dead. You just need to be adaptable.

Tudor Golubenco profil fotoğrafı
Tudor Golubenco5 ay önce

@calcom Funny, we just went the opposite direction:

Clayton Kohler profil fotoğrafı
Clayton Kohler5 ay önce

Switch from open to closed core does not address the underlying problem though. This makes it harder for code to be exploited, but it will eventually happen regardless with AI over time. We should start planning for the future we start giving access to more information so that that exploitation is not incentivized.

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom I agree, and going closed source isn't a complete fix. We're putting in tons of investment to secure in other ways, it's just that going closed source is just one way that we can massively reduce risk.

Veros profil fotoğrafı
Veros5 ay önce

@calcom What!!! this is such a backward thinking in my honest opinion, if you can prove your code is secure publicly, then you can always claim that you're secure. In todays world, being open source means being confident and accountable to what you delivered. Not the other way around.

Nick Khami profil fotoğrafı
Nick Khami5 ay önce

@calcom wowow, this is absolutely insane. cal is the last company i ever thought would go closed source

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom Honestly, me too, but we don't see that we have any other choice. Nothing about this is for marketing or business reasons. It's just the decision that we believe protects our customers best.

Sunny Golovine profil fotoğrafı
Sunny Golovine5 ay önce

@calcom Honestly that sucks. While I never used I used that codebase dozens of times over the years as a solid reference for how to architect things in a large code base.

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify. Just production application is moving to closed source.

ryuz profil fotoğrafı
ryuz5 ay önce

@calcom Guys, it's the 15th, not April Fools' Day.

Adam profil fotoğrafı
Adam5 ay önce

this is a retard take, I’m sorry - 1. Your code had already been open sourced, so unless you dramatically change everything, you are not saving anyone from vulnerabilities anytime soon. 2. You say AI is so capable and this and that, but you are aware that having your code open is not the only (and not the main) way of compromising your platform? “AI is GOD but only if we won’t open source the little new stuff we release from now on, after we’ve been in prod for years while open source, we will be safe” sure, bro 3. You do this at time when software is actually much easier to iterate on, when it becomes less proprietary - why? I love and use Cal, it’s a great product - but I genuinely don’t see the reasoning much. Especially not calling “Open source is dead”, like sure - build your brand, scale your company while riding on the community , then close it when series B investors are no longer comfortable with it

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

As part of this announcement, we did already say that we have rewritten massive parts of the codebase. The private codebase running is very diverged from any OSS release we've put out before. Of course it's not the only way, and I did address this in my post too. It's just one tool that we have available to us which massively reduces our risk. Most of our strategy revolves around other things: multiple AI vulnerability scanners, human pentesters and rigorous processes, but closing source is a valid option on the table for us, and why would I not take a significant risk reduction to our security if it was available to me? It's just one of many things we can do in response.

Nizzy profil fotoğrafı
Nizzy5 ay önce

@calcom

Peter Pistorius profil fotoğrafı
Peter Pistorius5 ay önce

@calcom How do these two statements work: "Open source is dead." "We released our codebase under so you can still do this! It's now 100% MIT-licensed and free for you to use and modify." Are you just releasing code, but not participating in open source?

Bhushan Mishra profil fotoğrafı
Bhushan Mishra5 ay önce

Your decision to close the core — your business, your call. But “AI has fundamentally altered security, transparency = exposure” still feels like spin. Automated scanning and exploits aren’t new; many critical OSS projects (Linux, Postgres, etc.) handle them daily without closing up.

Bailey Pumfleet profil fotoğrafı
Bailey Pumfleet5 ay önce

@calcom Do they, though? BSD, one of the most secure open-source projects, had a 27-year-old vulnerability that was discovered by Anthropic Mythos. React Server Components had multiple vulnerabilities recently too. Times are changing, and we've just got to respond as best as we can.

Bhushan Mishra profil fotoğrafı
Bhushan Mishra5 ay önce

@pumfleet @calcom Exactly

Josh profil fotoğrafı
Josh5 ay önce

@calcom Good move. I'm a fan and contribute back to open source as often as I can, but I'd never open source the core code to a product I am building as a business. That's a easy way to open yourself up to unnecessary struggles.

nisten profil fotoğrafı
nisten5 ay önce

@calcom Ok so if it's dead show me what you used after deleting all pip and npm packages in your products? Ah ok, so it's NOT dead then carry on

geoff profil fotoğrafı
geoff5 ay önce

@calcom tbh been saying this for circa 9 months now. OSS doesn’t make sense when you can take full control of supply chain via generation.

Muratcan Koylan profil fotoğrafı
Muratcan Koylan5 ay önce

@calcom Cancelling my subscription

gary IH fung profil fotoğrafı
gary IH fung5 ay önce

@calcom bullshit. Strong ai can reverse engineer without source just fine. And same ai that exploits can also fix bugs and increase security against exploits before code even gets deployed it's entirely your choice to close source, but don't virtue signal.

Jason Kneen profil fotoğrafı
Jason Kneen5 ay önce

So if I understanding this you're going to close source your product because you don't want people to look for vulnerabilities and report them to you. So you're going to hide your code with all the possible vulnerabilities that you yourself are saying you don't have any way of checking for because "a single unit test doesn't exist to test vulnerabilities". And the conclusion that is made from all this is that open source is dead?

OpenAgents profil fotoğrafı
OpenAgents5 ay önce

@calcom Nah

Aaron profil fotoğrafı
Aaron5 ay önce

@calcom what

amrit profil fotoğrafı
amrit5 ay önce

@calcom damn

zooko🛡🦓🦓🦓 ⓩ profil fotoğrafı
zooko🛡🦓🦓🦓 ⓩ5 ay önce

@calcom I once spoke with an experienced reverse engineer who assured me that it was *easier* to develop exploits against binaries than against source code. I was surprised! I wonder if that will be true of AIs?

Michael Arnaldi profil fotoğrafı
Michael Arnaldi5 ay önce

@calcom Security through obscurity is never a good idea, sure having access to the source code makes hacking it easier but it also allows for more eyes to report issues faster, and truth to be told 90% of hacks are because of people not because of software. Anyway whatever works for you!

AbuMuslim (أبومُسْلِم) profil fotoğrafı
AbuMuslim (أبومُسْلِم)5 ay önce

Was built on open source, using open source, and now we want to go closed source. Reshaping the world for the worse and dragging us back to the 60s and 70s, when gatekeeping was the norm. Closing the source of a product will not make you safe the way people think. If you look closely, you will notice that adversaries still target products like Microsoft’s in their campaigns. One way or another, you will still be relying on OSS in your project. Once that gets compromised, you will be affected too. People will gain nothing from this other than more gatekeeping and dragging us back to the freakin caves.

Kartik profil fotoğrafı
Kartik5 ay önce

@calcom really sad to hear this.

Proziam profil fotoğrafı
Proziam5 ay önce

@calcom Nah. This argument isn't compelling, sorry. This reads like a security-washing of your commercial interests.

Michael Ramos profil fotoğrafı
Michael Ramos5 ay önce

@calcom Thoughtful argument in the wrong ways. And wrong message to publicize. You’re right to fear - just say you’re closing for commercial reasons without neglecting the entire history of the argument.

andrew profil fotoğrafı
andrew5 ay önce

@calcom The hand-wringing over this is from the younger crowd that didn't know webdev or programming before open source went wide. This is how it used to be and it was fine. The call makes sense to me.

Zack Chapple profil fotoğrafı
Zack Chapple5 ay önce

@calcom Thought this was an April fools post that got bubbled up again

skot profil fotoğrafı
skot5 ay önce

@calcom Security by obscurity? Good luck with that.

Justin Giudici profil fotoğrafı
Justin Giudici5 ay önce

@calcom Saying opensource is dead Is a bizarre statement just because in your specific circumstance you have decided to go closed source. The world runs on open source software and AI is increasing that reality if anything

Benzer Videolar

Open source software is GREAT. But "open source" AI is NOT like software - it's VERY different. Rob Miles cuts through the bullshit: ROB: Oh, hey, Meta. I heard Llama's weights leaked. That's rough, man. Information security's hard. How you holding up? META: Oh, we're great. Yeah, we're fine. We... actually, that was deliberate. We meant to do that. ROB MILES: Oh, really? META: Yeah... well, the second time anyway. It's called open source. Look it up. ROB MILES: Oh. Well, I love free and open source software, but do those principles really apply to network weights? How does that work? META: Open source is good for users because it lets them read the source code and see what the program is really doing and how it works. ROB MILES: Wait, have you found a way to tell how a model works by looking at its weights? META: No. But, it lets developers all over the world spot bugs in the code and submit patches. ROB: Wait, people are fixing bugs in Llama's weights? META: Well, no. People can fine tune it themselves, though. ROB: ?? Other companies offer fine tuning through APIs. ... So, hang on, if you can't actually read the code and know what it's doing, then network weights are effectively a compiled binary. So, in what sense is this open source? Why not call it like public weights? Why call it open source at all? META: I love open source. ROB: Well, I know a lot of your employees do, but you don't love anything. You're a giant corporation. What's in it for you? META: I love, love open source.

AI Notkilleveryoneism Memes ⏸️

107,362 görüntüleme • 2 yıl önce