2026-06-24 15:19:00
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythoOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
https://www.wired.com/story/openai-launche
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
OpenAI unveils an updated GPT-5.5-Cyber model, launches the Patch the Planet initiative in partnership with Trail of Bits to fix open source bugs, and more (Lily Hay Newman/Wired)
https://www.wired.com/story/openai-launche
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
EOLE Evento europeo sul diritto all'open source e al software libero. Workshop di apertura online domani 25 giugno 2026 (dalle 15:00 alle 17:30 CEST)
L'Europa ha riscoperto la "sovranitŠ" attraverso un'ondata di nuove regolamentazioni - Legge sulla resilienza informatica, Legge sull'IA, gare d'appalto per la sovranitŠ del cloud. EOLE 2026 adotta un punto di partenza opposto: il Software Libero, l'Open Source e l'IA aperta perseguono l'autonomia…
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
«#Zürich will sich von teurer #Microsoft-Software lösen – doch da gibt es ein Problem:
Die Zürcher Stadtverwaltung soll sich aus dem #M365-Würgegriff lösen und auf eine europäische
I believe that we in the US will begin to face a hard question:
We will soon, I hope, begin cleaning up the trump/maga mess.
Given that the trump/maga actors have engaged in inhumane, unlawful, and racist destruction of people and institutions I wonder about the following:
Should those people be protected by our Constitutional norms or will we want to, or need to, bypass our legal protections and procedures as we pursue punishment, disgorgement of ill gains, and compensatio…
🇺🇦 #NowPlaying on BBCRadio3's #Breakfast
Elin Manahan Thomas, George Frideric Handel, Orchestra of the Age of Enlightenment & Harry Christophers:
🎵 Eternal source of light divine (Birthday Ode for Queen Anne)
https://open.spotify.com/track/301GhrxRRyQ0h8NP6NQQxc
"PostgreSQL, MySQL, Cassandra, and other popular open source systems are not measured in and of themselves – only as part of commercial services."
What is the purpose of essentially delisting #PostgreSQL, #MySQL,
🇺🇦 #NowPlaying on KEXP's #MidnightInAPerfectWorld
Jump Source ft. POiSON GiRL FRiEND:
🎵 Close
#JumpSourceftPOiSONGiRLFRiEND
https://jumpsource.bandcamp.com/track/close-ft-poison-girl-friend
https://open.spotify.com/track/6CVubsu8aHYG5QztcKmsLz
This AI Tool Rips Off Open Source Software Without Violating Copyright https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
This is an excellent post / case study and a lot here for even ‘experienced’ family historians to learn. #genealogy #histodons @… @…
31st Developers and Devops DORS/CLUC conference starts tomorrow in Zagreb, Croatia.
And on Saturday we'll have #SOTMHR #Openstreetmap track https://
Right, time to crank out some open source PR's out
@… That’s so cool, is it open source? Would love to see how you did it :)
@… my context was:
― the The AI/ML Security Working Group.
The working group is an Open Source Security Foundation project. The OpenSSF is a project of the Linux Foundation.
If you must use extreme, inflammatory phrases such as "the beast" and "shitcan" in the future:
― be clearer about the meanings.
Cc
IResearch is an Apache 2.0 C search engine built to live inside databases.
Andrey Abramov is joining #bbuzz26 to benchmark it against leading open-source search engines, and explore how database-native search fits modern query execution.
Learn more: https://2026.berlinbuzzwords.de/session/c-search-for-database-kernels-built-in-not-bolted-on/
Am 5. Mai gibt es wieder ein lokales "Free Software Foundation Europe"-Treffen in Wien! Komm vorbei, wenn dich die gesellschaftlichen und politischen Aspekte von Freier Software/Open Source Software interessieren und du dich mit anderen austauschen möchtest!
Wann?
Dienstag, 5. Mai 2026
Ab 18:30 Uhr gemütliches Ankommen
Um 19:00 Uhr Start
Wo?
Im @…
Part 1 of a new short story by Linda Teppler is out! Free to read on Substack #writingcommunity #banskolife #writing
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
I've recently talked with @… who brought up to my attention a 3D printers company I've never heard of: #snapmaker.
While there're not fully open-source, they are still more leaning towards that than some other companies, and they offer quite some…
Mirendil, founded by former Anthropic researchers and seeking to build self-improving AI for open-source developers, raised a $200M seed at a $1B valuation (Tina Li/Wall Street Journal)
https://www.wsj.com/tech/ai…
advogato: Advogato trust network (2009)
A network of trust relationships among users on Advogato, an online community of open source software developers. Edge direction indicates that node i trusts node j, and edge weight denotes one of four increasing levels of declared trust from i to j: observer (0.4), apprentice (0.6), journeyer (0.8), and master (1.0).
This network has 6541 nodes and 51127 edges.
Tags: Social, Online, Weighted
«Ladybird-Browser stoppt öffentliche Code-Beiträge:
Wegen KI-generierter Beiträge schließt das Open-Source-Projekt Ladybird seine öffentlichen Pull-Requests, um die Sicherheit des Browsers zu garantieren.»
Da sehen wir wie KI das Gegenteil von sicherer Produktion ist, wenn es blind als unstrukturiertes Pull-Request eingesetzt wird.
🌐
My neurologist advised that I should try EEG Neurofeedback. Unfortunately public health insurance doesn't cover it.
Well, I'm just going to DIY it. I just ordered an open source Neurofeedback device with some electrodes.
https://www.olimex.com/Products/EEG/OpenEE
Im IT-Bereich gibt es eine besondere Form des ‚Whitewashings‘, nämlich das ‚Openwashing‘. Der Begriff beschreibt Software, die sich als Open-Source-Produkt ausgibt, es aber nicht ist. Um festzustellen, ob Software, die man einsetzen möchte, frei ist oder nur so tut, hilft: https://isitreallyfoss.com/
RE: https://unstable.systems/@jneen/116618931097778342
Worth looking at both the quoted text here and •especially• the linked page, which is quite good.
I’ll add another item of my own. The first screenshot mentions giving an LLM the task of “implementing an HTTP server in JavaScript from scratch” in 90 minutes. Sounds impressive, right? Until you remember that every open-source Javascript HTTP server in existence ••was in the training data••.
1/
https://open-source-wettbewerb.de/
> das Bundesministerium für Digitales und Staatsmodernisierung übernimmt erneut die Schirmherrschaft für den Open Source Wettbewerb.
> Der Wettbewerb zeichnet Projekte aus, die digitale Verwaltungsprozesse verbessern, die Zusammenarbeit in der Verwaltung …
I do understand that there are vast differences between the reactions to user feedback so I am not replying to this post directly, but I do now feel the need to leave this somewhere:
The usual reply I get from 1 man teams is "works as intended, won't fix" while community projects (nextcloud, CoMaps, ...) on the other hand have discussions over months and years that seem to be going nowhere until I don't even care anymore - and either have a workaround or use another a…
As the US House probes Airbnb's use of Chinese AI models, CEO Brian Chesky says the company is not sharing data with Chinese firms and uses open-source models (Natalie Lung/Bloomberg)
https://www.bloomberg.com/news/articles/20
The Baker, the Polluters and the Planet
https://open.substack.com/pub/theclimatehistorian/p/the-baker-the-polluters-and-the-planet?utm_source=share&utm_medium=android&r=e4myx
No puede haber una IA de código abierto si todas sus partes no son de código abierto, y eso significa que también deben de ser accesibles los datos utilizados para entrenarla https://opensource.org/ai/open-source-ai-definition
« Once an organisation accepts that the difficult software will be bought elsewhere, internal teams slowly lose the habit of building. Procurement becomes a substitute for strategy. Legal review becomes a substitute for leadership. Risk management becomes a substitute for execution. »
https://…
Every modern digital technology
– from AI to quantum computing
– is based on foundational open source software building blocks.
Open source code is embedded in almost all products and services,
enabling economic growth and ensuring the resilience of our society and government.
While open source software has become the backbone of our digital infrastructure,
these essential components do not receive adequate support and investment.
Targeted and long…
Are they right? 🤔
"Euro-Office defaults to the fully proprietary OOXML document format, developed and controlled solely by Microsoft. This makes it a de facto ally of Microsoft in its content lock-in strategy, with control remaining firmly in Redmond and far from Europe."
https://blog.do…
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
Do you have experience developing Open Educational Resources (OER) or developing educational software? The Journal of Open Source Education (JOSE) is looking for reviewers to help with our check-list driven peer review process. Happy to answer questions about reviewing for JOSE if you're interested.
https://forms.gle/Rizd3TcHnQKhrbYY7
Don't miss today's Metacurity for the most critical cybersecurity developments you might have missed over the weekend, including
--White House opens backchannel to Anthropic as Pentagon fight simmers,
--Anthropic gave NSA access to Mythos Preview,
--Anthropic's donation to open source developers highlights how under-sourced they are,
--Asian regulators urge banks to use Mythos,
--LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit…
The Irish Council for Civil Liberties (#ICCL) has released an open source tool designed to reduce LLM hallucinations.
If my 15-year-old PC had a GPU I'd be tempted to give it a try.
https://www.
How hacker group TeamPCP exploited the open source trust model and distribution method to compromise and inject malware into over 1,000 software packages (Matt Kapko/CyberScoop)
https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/
Einige der zuletzt hier besonders häufig geteilten #News:
Stringman: Fest montierter Open-Source-Roboter räumt einzelne Räume auf
Una lettera aperta agli utenti di suite per ufficio, poco prima dell'annuncio di Euro-Office
«Negli ultimi giorni avrete letto diversi articoli che annunciano l'arrivo di EuroOffice, presentato come la prima suite per ufficio open source sviluppata in Europa. Ci sentiamo in dovere – seppur a malincuore, poiché l'open source dovrebbe basarsi sulla trasparenza e non sull'inganno – di correggere questa affermazione. La prima suite per ufficio open source sviluppata in Euro…
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
Europe’s Digital Future
The EU Tech Sovereignty Package is a once-in-a-generation opportunity to reclaim control over our digital foundations.
For too long, public sector procurement has defaulted to proprietary lock-in, creating a weak sovereignty posture that hinders European resilience.
We are calling for a fundamental shift: the Open Source First principle.
Auch Zürich will hybriden Ansatz ausprobieren.
#OpenDesk #digitaleSouveränität
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6
Just over a week after Mosaic 1.0 was released, CERN gifted the Web to the world as open source software. As of 30 April 1993, the still relatively new Internet communications platform was suddenly free for anyone to use, with no strings attached.
https://cybercultural.com/p/1993-mosai
Microsoft has locked the lead developers of two prominent open source security projects out of their accounts.
https://www.computing.co.uk/news/2026/microsoft-locks-open-so…
Some organizations are doing panicky things over Mythos.
NHS Goes To War Against Open Source
https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Paperweight è un'applicazione desktop open-source, pensata per l'utilizzo locale che analizza la tua casella di posta per mappare la tua impronta digitale e a riprendere il controllo e a eliminare i tuoi dati.
Cosa fa:
- Inventario degli account: mappa tutte le aziende che ti hanno mai contattato via email, con classificazione dei rischi e raccomandazioni sulle azioni da intraprendere.
- Annullamento iscrizione in blocco: trova e annulla l'iscrizione a tutte le li…
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
Open source is benefiting from the current AI trend: some projects are already improving their security posture and reducing their attack surface.
Proprietary software, for now, seems more out of the loop.
But once LLMs become better at analysing binaries, compiled code, and obfuscation, I wonder how vendors will handle the likely increase in vulnerability disclosures.
#ai
OpenDesk kann vieles, aber halt nicht alles. Das ist das Fazit einer Studie aus Zürich, die die Open-Source-Lösung als Microsoft 365-Alternative unter die Lupe genommen hat. 🔍
Zum Artikel: https://heise.de/-11303065?wt_mc=sm.red.…
«Googles reCaptcha bekommt Handgestenerkennung:
Eine neue Option soll den Bot-Schutz mittels Googles reCaptcha verbessern. Die Kamera nimmt dafür einfache Handgesten auf.»
Ich bin dem sehr kritisch gegenüber, denn dies wird früher oder später sicherlich dann auch für das KI-Training genutzt. Abgesehen davon gibt es einige Open-Source Alternativen die Webservices vor Onlinespam schützen.
🫸
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
from my link log —
MiniZinc high-level solver-independent constraint satisfaction and optimization modelling language.
https://www.minizinc.org/index.html
saved 2019-09-30
SpaceX signs a computing deal worth up to $6.3B with Reflection AI for access to Nvidia GB300s at Colossus 2; Reflection will pay $150M per month through 2029 (Deirdre Bosa/CNBC)
https://www.cnbc.com/2026/06/22/spacex-ai-colossus-data-center-reflection.html
«Sniffnet 1.5: Welches Programm funkt nach Hause?
Der Open-Source-Netzwerkmonitor @… ordnet Traffic nun einzelnen Programmen zu. Version 1.5.0 bringt zudem Blacklists und Adapter-Vorschauen»
Zu viele glauben immer noch nichts zu verbergen zu haben und realisieren nicht, dass sie das Produkt sind anhand von IT- & Online-Tools.
🕵️
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
Socket: TeamPCP, the gang claiming GitHub's repositories breach, also executed 20 "waves" of supply chain attacks recently, compromising 500 pieces of software (Wired)
https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/…
Sources: Meta is preparing to release the first AI models developed under Alexandr Wang, with plans to offer versions of those models via an open source license (Ina Fried/Axios)
https://www.axios.com/2026/04/06/meta-open-source-ai-models
Socket, which helps companies safeguard open-source code against hackers, raised $60M led by Thrive Capital at a $1B valuation (Dina Bass/Bloomberg)
https://www.bloomberg.com/news/articles/2026-05-20/security-firm-thwarting-…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Mozilla launches Thunderbolt, an open-source AI client for users and businesses who want to run their own self-hosted AI infrastructure, available on GitHub (Kyle Orland/Ars Technica)
https://arstechnica.com/ai/2026/04/mozil…
Einige der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Anthropic commits up to $100M in usage credits for Project Glasswing, along with $4M in direct donations to open-source security organizations (Greg Otto/CyberScoop)
https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnera…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Europa hat jetzt sein eigenes Office – und das ist auch noch Open Source! 🚀
Zum Artikel: https://heise.de/-11320254?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
Servus, freie Software! 🥨 In München weht ein neuer Wind durchs Rathaus – und der riecht verdächtig nach Open Source.
Zum Artikel: https://heise.de/-11292444?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_sou…