BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Is open source more secure at the current level of AI?
- Subject: [Discuss] Is open source more secure at the current level of AI?
- From: dsr at randomstring.org (Dan Ritter)
- Date: Thu, 9 Apr 2026 15:25:06 -0400
- In-reply-to: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com>
Randall Rose wrote: > In the current state of the art, AI agents like Claude Mythos are good at > finding exploitable bugs in code. Objection: Anthropic says this. Pretty much everything Anthropic has ever said turns out to be overstated at best. (Counter-objection: Greg K-H says that LLM-discovered kernel bugs are now actually worth investigating.) > That affects open-source systems differently than closed-source systems, > and arguably it creates more risk for open-source. I have had visibility into several companies' nominally closed-source software and SaaS products, and it is a mistake to think that the work that they do is significantly insulated from open-source work. The XKCD about the Internet relying on a small Jenga brick developed by one person in Nebraska? Approximately true for every large project. Don't think of proprietary software as being different from open source. Think of proprietary software as being a layer of icing on top of a cake made mostly from open source components. > I suppose we are all biased in the pro-FOSS direction. But these risks > should be faced. Are open-source projects doing enough against these > risks? Are there open-source projects that are so benighted that they > don't even guard against risk (1)? No. Yes. -dsr-
- Follow-Ups:
- [Discuss] Is open source more secure at the current level of AI?
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Is open source more secure at the current level of AI?
- References:
- [Discuss] Is open source more secure at the current level of AI?
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Is open source more secure at the current level of AI?
- Prev by Date: [Discuss] Is open source more secure at the current level of AI?
- Next by Date: [Discuss] Is open source more secure at the current level of AI?
- Previous by thread: [Discuss] Is open source more secure at the current level of AI?
- Next by thread: [Discuss] Is open source more secure at the current level of AI?
- Index(es):
