Remix.run Logo
mmaunder 19 hours ago

I'm a cybersecurity 'expert' and my 40 person team and I make our money by providing GPL software to the world that I wrote.

You have the same incentive you had to share your work as before, and that is to get attention, and customers, assuming that's your game. Open code means no vendor lockin for a lot of customers, so they can pay you but also trust you to not extort them. And if you're hit by a bus your product lives on, and someone else can adopt it.

Supply chain risks and vulnerabilities existed before LLMs came along. They're easier to handle now that we have LLMs helping us. In our org the tsunami of updates we need to do weekly is far more easy to handle with LLMs.

Open code has always been easier to find vulns in vs closed. AI didn't change that.

Yeah the slopfest is real, but easier to deal with thanks to agents/LLMs so it kind of offsets itself.

Your licenses are still enforceable in court. Agreed that not being able to reverse the fact that AI trained on your code and is selling that capability kind of sucks. But humans were doing that before AI.

Yeah on the one hand opening your code got you credit which was nice for the ego and for getting paid, and AI trains on it and doesn't give credit where it's due. But on the flip side, we get AI! Which I frikkin love. I feel like a kid in a candy store. It's training on my code too and it's training on my content. And when people ask about what the best product is for our space, the AI tells them its our product. Woohoo!

Regarding the future: We have some really really big problems that need solving - stuff that creates a massive amount of misery in dark stuffy hospital rooms with crying relatives saying goodbye to their 9 year old child. I've been in those spaces and I'd give up the previous generation of open source ethics in a heartbeat to make just an ounce of that misery stop. The training that my code provides AI is a tiny little part of that solution, and I'm proud of that. Whatever I can do to push our capabilities to the point where we can make the major breakthroughs this species needs, I'm happy to provide.

VladVladikoff 18 hours ago | parent | next [-]

Hey thanks for WordFence! It made my early days as a programmer a bit less crazy. Having clients constantly installing plugins (backdoors) in their websites was a never ending battle. Don’t really touch Wordpress stuff anymore but it was definitely my favourite plugin back then.

mmaunder 16 hours ago | parent [-]

Thanks! Still going strong. Weirdly WP is growing. I suspect it's the structure and framework it gives agentic tools to build around.

Forgeties79 18 hours ago | parent | prev | next [-]

“Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale.

LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrugging. Fake news always existed. Now one dude in India can flood multiple sock puppet media accounts with right wing content/images (actual example from a few months back) at a scale previously unimaginable.

People could always die crossing a street. Still, cars changed the discussion about pedestrian safety pretty materially. People didn’t simply throw up their hands and go “people have always been able to die crossing the street.”

NegativeK 17 hours ago | parent [-]

> The issue is scale

A guest on a podcast said, in response to open source and community websites being flooded with AI scrapers, "the internet has always had people scanning websites; get over it".

I still respect the podcast, but that was such a shitty take. The difference between before and now was that those websites started closing their doors instead of paying the increased hosting feeds.

I'll get over it when we stop giving people a pass for the damage they're doing just because they're a corporation.

TeMPOraL 18 hours ago | parent | prev | next [-]

100% this.

And frankly, I think most of the source of outrage is this:

> Yeah on the one hand opening your code got you credit which was nice for the ego and for getting paid, and AI trains on it and doesn't give credit where it's due.

Turns out, a lot of people didn't really do things in the open to benefit the others, in pay-it-forward style. They just did it for selfish gains. Which is fine, just like keeping source closed and selling licenses is fine. The problem is with lying - doing something for personal gain, while claiming it's for greater good, thus getting more gains through dishonesty.

LLMs just shone a light onto it. People who had betterment of others on their minds, don't have a reason to consider LLMs training on their output as taking anything from them. On the contrary, their outputs now contribute to a general-purpose problem solving tool that will (and already does) help humanity with way more problems that anyone imagined.

I personally am more than happy to know LLMs may have trained on my content. I don't begrudge the companies the $0.000001/year they probably owe me for my relative contributions. I get orders of magnitude more value for myself from LLMs every day, in my personal life alone.

There are other reasons to dislike LLMs and fear or hate what AI is doing to the world. But people who feel something was "stolen" from them, who now close their blogs and turns repos private because LLMs - they're just showing they had ulterior motives for their work - which again, is fine if they were up-front about it. The OSS subset of those, just paint themselves as being grifters all along.

Marha01 16 hours ago | parent | next [-]

> There are other reasons to dislike LLMs and fear or hate what AI is doing to the world. But people who feel something was "stolen" from them, who now close their blogs and turns repos private because LLMs - they're just showing they had ulterior motives for their work - which again, is fine if they were up-front about it.

100% this. Why should I be bothered that some of my work that I released freely to the world is now potentially used by millions of people as a small part of the knowledge in a state of the art AI system? I am honored!

But I guess some people just have different motivations for releasing their code, and require explicit attribution to feel honored enough to make it all worth it for them. Not me, though.

jminnl 18 hours ago | parent | prev | next [-]

You have no proof that the world will be a better place because of this stuff but there is plenty of proof already that it will be worse, possibly significantly worse but the jury is still out on that.

milkshakes 16 hours ago | parent [-]

"AI" -- as in agentic workflows -- have been around for a little over a year. it doesn't seem like enough time to "prove" anything conclusively to me, what makes you so confident?

milkshakes 17 hours ago | parent | prev | next [-]

> Turns out, a lot of people didn't really do things in the open to benefit the others, in pay-it-forward style. They just did it for selfish gains. Which is fine, just like keeping source closed and selling licenses is fine. The problem is with lying - doing something for personal gain, while claiming it's for greater good, thus getting more gains through dishonesty.

> There are other reasons to dislike LLMs and fear or hate what AI is doing to the world. But people who feel something was "stolen" from them, who now close their blogs and turns repos private because LLMs - they're just showing they had ulterior motives for their work - which again, is fine if they were up-front about it. The OSS subset of those, just paint themselves as being grifters all along.

thank you for putting such clear words to a feeling that's been troubling me about this outrage for a long time.

GeoAtreides 13 hours ago | parent | prev [-]

it's not selfish to want attribution for your work and knowledge, it's an essential human trait

watwut 18 hours ago | parent | prev [-]

> But on the flip side, we get AI

That is kind of net loss at this point. Hey, on the bright side we get onslaught of slop, ai psychosis, constant stream of doom trolling.

And ideology of pointlessness where any time you do or learn anything, you get told that why bother you should have used AI.

The kid forever locked in candy store is happy for a bit, but then they get hungry and feel bad. And no matter how much sugar you eat, it wont get better.

lisplist 18 hours ago | parent | next [-]

From an ego perspective, the artisan craft of programming basically being dead at this point makes me sad, having spent so much of my life getting good at it (or at least trying to).

From technological enthusiast perspective - if you can't find an endless stream of uses for this technology, I really don't know what to tell you anymore. I gave credence to AI naysayers for a while, but at this point I feel like its akin to denying gravity exists.

Who are we to gatekeep software development? So many people have gained the ability to interact with computers in ways they never dreamed of before! For me, I've never felt so engaged in software development, even if I'm no longer writing it line by line.

Like you say, there are a lot of negative externalities to this technology, but its something we're going to have to solve rather than dismissing it outright. The industrial revolution caused all sorts of problems! But you can't argue we're worse off because of it.

Pannoniae 18 hours ago | parent | next [-]

I don't think it's dead if you have a market which values high-quality, artisanal products.

Sure, artisanal code in itself isn't something inherently sellable but if you pride your program on being a quality product then it's still valuable for others:) AI is basically the new JavaScript in a way.It won't create the next Linux or the next SQLite by itself.

hombre_fatal 17 hours ago | parent [-]

That's separate from LLM usage though.

By this point, if you care about a quality product, you should learn how to leverage LLMs for that like running automated audits for correctness and performance opportunities.

There isn't a market for "yeah there's a memory leak but I wrote it by hand."

brabel 16 hours ago | parent | next [-]

Yep! We run security reviews on our pull requests now and are shocked at how it stops a lot of vulnerabilities being shipped. We've had a couple of high score CVEs from the before-LLM times, and when the AI reviews the code that introduced the CVEs, it easily picks them up. We had 2 humans reviewing every PR, and both missed the issues. It's far too easy to miss security issues when you manually review them, but LLMs are exceptionally good at finding them. Unfortunately for me, I admit, I just can't get myself to push code anymore without an LLM checking my work (or writing much of it when I'm at work, I try to write code by hand in my own time to make sure I don't rust away, but at work there's no way to justify doing it the "slow" way anymore).

Pannoniae 17 hours ago | parent | prev [-]

Fair enough, but as things stand now, the usual LLM-assisted piece of software is usually also partly or wholly LLM-designed too. Not just implemented on a function level or a file level. And LLM design is usually called "slop" because it's nothing spectacular unless you bring fresh ideas to it from a human perspective.

Hand-written memory leaks don't have a market but hand-designed software with hand-designed UX and a hand-designed vision does :)

hombre_fatal 17 hours ago | parent [-]

I'm generally impressed with the code that Fable/Opus is writing for me these days; I would be proud to have had the same foresight had I implemented the solution myself.

And Fable's architectural design is pretty much always well-reasoned and a good place to start.

There's this idea that the best way to use LLMs is to be in the backseat constantly yelling out corrections, but that hasn't been true in my experience for quite some time, though I only use a few sota models.

I think something being slop this late in the game is mainly a reflection of the person using it. I can't really blame AI anymore when pretty much any lever you'd recommend to de-slop it is one prompt away.

I agree with your last bit, and that is the only thing left now that AI solved the technical part.

GeoAtreides 13 hours ago | parent | prev [-]

>if you can't find an endless stream of uses for this technology,

it's the endless stream of employment that's getting harder/impossible to find...

mmaunder 16 hours ago | parent | prev | next [-]

Thing about being in cybersecurity is you get to see outcomes that aren't a matter of debate or taste. For example, if I lock an agent in a jail and tell it to attack something and that the only way to win is to show me a number stored on that target, and it succeeds, then assuming our jail was effective, it's an outcome that isn't debatable. I've lost count of the moments I've had this year where my jaw just drops because I'm holding undeniable proof of a level of expertise I've never seen in humans - and that is far above human capability, in a field where I'm an expert.

So I guess from my perspective, it's not a candy store or candy. It's something that can solve problems we've never before been able to solve. Problems that are too hard for a human.

Another example: Recently one of our agents found a vulnerability so complex, that our team, who are experts in their field, could not understand it and had to ask an agent to write a blog post to explain it to them. It had more steps in the exploit than we've ever seen, and would never have been discovered by a human.

Cybersecurity is a leading indicator of what's to come in other fields. Leading because programming is something models are inherently good at. Doing wetwork in a lab is harder to plug into a model or agent. But it's on the horizon. So we will be seeing these kinds of breakthroughs in other fields, and the leading indicator says they're going to blow our minds.

If you think this stuff is candy, and you're relating it to social media, you're simply not paying attention or getting your hands dirty. And honestly if I wasn't hands-on, every day that passed would make me progressively more scared and more angry as it pulled away from me.

post-it 18 hours ago | parent | prev [-]

> And ideology of pointlessness where any time you do or learn anything, you get told that why bother you should have used AI.

Who cares? Anyone can tell you anything online.

watwut 17 hours ago | parent [-]

That part was about people in real life and their real life comments.

post-it 16 hours ago | parent [-]

People in real life are going up to you and telling you you shouldn't bother learning things and just use AI instead?