BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Is open source more secure at the current level of AI?
- Subject: [Discuss] Is open source more secure at the current level of AI?
- From: richard.pieri at gmail.com (Rich Pieri)
- Date: Sat, 11 Apr 2026 19:11:38 -0400
- In-reply-to: <aae1dbf0-dec1-46cb-b09c-82a6d0257b91@borg.org>
- References: <3ba75ddf-6d93-40c7-85ca-050531c8a4dd@app.fastmail.com> <121cb616-ba15-460b-8633-68b12007d2c1@borg.org> <20260411125347.7a3b1c48.Richard.Pieri@gmail.com> <aae1dbf0-dec1-46cb-b09c-82a6d0257b91@borg.org>
On Sat, 11 Apr 2026 14:40:42 -0700 Kent Borg <kentborg at borg.org> wrote: > Just because the "closed source is better"-crowd makes an argument > doesn't mean the argument is garbage. (Trump sometimes says something > that is true, too. So?) It is garbage. "Open source is more secure than proprietary because more eyes, shallow bugs." "Proprietary is more secure because attackers can't see the source code." It's a false dichotomy on both sides because both sides are asserting one of the two must be true when NEITHER are true. The license does not make a program more or less secure. Look at Heartbleed and Bashdoor/Shellshock and XZ tools. Look at SolarWinds and NotPetya and the delivery restaurant menu hack. To name some of the highest profile compromises. The licenses did NOTHING to stop attackers from attacking and finding exploitable vulnerabilities. Neural network AI models don't change any of this. They can accelerate finding exploitable vulnerabilities. But if you think the black hats are the only ones applying these models to open source software or that they have any substantial advantage then you are very mistaken. -- \m/ (--) \m/
- Follow-Ups:
- [Discuss] Is open source more secure at the current level of AI?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Is open source more secure at the current level of AI?
- References:
- [Discuss] Is open source more secure at the current level of AI?
- From: rrose at pobox.com (Randall Rose)
- [Discuss] Is open source more secure at the current level of AI?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Is open source more secure at the current level of AI?
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Is open source more secure at the current level of AI?
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Is open source more secure at the current level of AI?
- Prev by Date: [Discuss] Is open source more secure at the current level of AI?
- Next by Date: [Discuss] Is open source more secure at the current level of AI?
- Previous by thread: [Discuss] Is open source more secure at the current level of AI?
- Next by thread: [Discuss] Is open source more secure at the current level of AI?
- Index(es):
