I'm a cybersecurity 'expert' and my 40 person team and I make our money by providing GPL software to the world that I wrote.
You have the same incentive you had to share your work as before, and that is to get attention, and customers, assuming that's your game. Open code means no vendor lockin for a lot of customers, so they can pay you but also trust you to not extort them. And if you're hit by a bus your product lives on, and someone else can adopt it.
Supply chain risks and vulnerabilities existed before LLMs came along. They're easier to handle now that we have LLMs helping us. In our org the tsunami of updates we need to do weekly is far more easy to handle with LLMs.
Open code has always been easier to find vulns in vs closed. AI didn't change that.
Yeah the slopfest is real, but easier to deal with thanks to agents/LLMs so it kind of offsets itself.
Your licenses are still enforceable in court. Agreed that not being able to reverse the fact that AI trained on your code and is selling that capability kind of sucks. But humans were doing that before AI.
Yeah on the one hand opening your code got you credit which was nice for the ego and for getting paid, and AI trains on it and doesn't give credit where it's due. But on the flip side, we get AI! Which I frikkin love. I feel like a kid in a candy store. It's training on my code too and it's training on my content. And when people ask about what the best product is for our space, the AI tells them its our product. Woohoo!
Regarding the future: We have some really really big problems that need solving - stuff that creates a massive amount of misery in dark stuffy hospital rooms with crying relatives saying goodbye to their 9 year old child. I've been in those spaces and I'd give up the previous generation of open source ethics in a heartbeat to make just an ounce of that misery stop. The training that my code provides AI is a tiny little part of that solution, and I'm proud of that. Whatever I can do to push our capabilities to the point where we can make the major breakthroughs this species needs, I'm happy to provide.
That is kind of net loss at this point. Hey, on the bright side we get onslaught of slop, ai psychosis, constant stream of doom trolling.
And ideology of pointlessness where any time you do or learn anything, you get told that why bother you should have used AI.
The kid forever locked in candy store is happy for a bit, but then they get hungry and feel bad. And no matter how much sugar you eat, it wont get better.
Thing about being in cybersecurity is you get to see outcomes that aren't a matter of debate or taste. For example, if I lock an agent in a jail and tell it to attack something and that the only way to win is to show me a number stored on that target, and it succeeds, then assuming our jail was effective, it's an outcome that isn't debatable. I've lost count of the moments I've had this year where my jaw just drops because I'm holding undeniable proof of a level of expertise I've never seen in humans - and that is far above human capability, in a field where I'm an expert.
So I guess from my perspective, it's not a candy store or candy. It's something that can solve problems we've never before been able to solve. Problems that are too hard for a human.
Another example: Recently one of our agents found a vulnerability so complex, that our team, who are experts in their field, could not understand it and had to ask an agent to write a blog post to explain it to them. It had more steps in the exploit than we've ever seen, and would never have been discovered by a human.
Cybersecurity is a leading indicator of what's to come in other fields. Leading because programming is something models are inherently good at. Doing wetwork in a lab is harder to plug into a model or agent. But it's on the horizon. So we will be seeing these kinds of breakthroughs in other fields, and the leading indicator says they're going to blow our minds.
If you think this stuff is candy, and you're relating it to social media, you're simply not paying attention or getting your hands dirty. And honestly if I wasn't hands-on, every day that passed would make me progressively more scared and more angry as it pulled away from me.
mmaunder · · focus · HN ↗
You have the same incentive you had to share your work as before, and that is to get attention, and customers, assuming that's your game. Open code means no vendor lockin for a lot of customers, so they can pay you but also trust you to not extort them. And if you're hit by a bus your product lives on, and someone else can adopt it.
Supply chain risks and vulnerabilities existed before LLMs came along. They're easier to handle now that we have LLMs helping us. In our org the tsunami of updates we need to do weekly is far more easy to handle with LLMs.
Open code has always been easier to find vulns in vs closed. AI didn't change that.
Yeah the slopfest is real, but easier to deal with thanks to agents/LLMs so it kind of offsets itself.
Your licenses are still enforceable in court. Agreed that not being able to reverse the fact that AI trained on your code and is selling that capability kind of sucks. But humans were doing that before AI.
Yeah on the one hand opening your code got you credit which was nice for the ego and for getting paid, and AI trains on it and doesn't give credit where it's due. But on the flip side, we get AI! Which I frikkin love. I feel like a kid in a candy store. It's training on my code too and it's training on my content. And when people ask about what the best product is for our space, the AI tells them its our product. Woohoo!
Regarding the future: We have some really really big problems that need solving - stuff that creates a massive amount of misery in dark stuffy hospital rooms with crying relatives saying goodbye to their 9 year old child. I've been in those spaces and I'd give up the previous generation of open source ethics in a heartbeat to make just an ounce of that misery stop. The training that my code provides AI is a tiny little part of that solution, and I'm proud of that. Whatever I can do to push our capabilities to the point where we can make the major breakthroughs this species needs, I'm happy to provide.
watwut · · focus · HN ↗
That is kind of net loss at this point. Hey, on the bright side we get onslaught of slop, ai psychosis, constant stream of doom trolling.
And ideology of pointlessness where any time you do or learn anything, you get told that why bother you should have used AI.
The kid forever locked in candy store is happy for a bit, but then they get hungry and feel bad. And no matter how much sugar you eat, it wont get better.
mmaunder · · focus · HN ↗
So I guess from my perspective, it's not a candy store or candy. It's something that can solve problems we've never before been able to solve. Problems that are too hard for a human.
Another example: Recently one of our agents found a vulnerability so complex, that our team, who are experts in their field, could not understand it and had to ask an agent to write a blog post to explain it to them. It had more steps in the exploit than we've ever seen, and would never have been discovered by a human.
Cybersecurity is a leading indicator of what's to come in other fields. Leading because programming is something models are inherently good at. Doing wetwork in a lab is harder to plug into a model or agent. But it's on the horizon. So we will be seeing these kinds of breakthroughs in other fields, and the leading indicator says they're going to blow our minds.
If you think this stuff is candy, and you're relating it to social media, you're simply not paying attention or getting your hands dirty. And honestly if I wasn't hands-on, every day that passed would make me progressively more scared and more angry as it pulled away from me.