2026-04-25 19:51:02
RE: https://dice.camp/@realms/116459545804565917
I'd argue that "AI"-based development creates a bigger attack surface on closed source/proprietary software than open source software:
1. It's more likely that internal software development uses LLMs as they're most affordable to companies; leaving them more vulnerable to prompt injection and other types of attacks targeting LLM use.
2. It's more likely that internal commits aren't vetted as much (or even purely vibe-coded) as ones in open source projects.
3. It's more likely that attacks on open source projects are discovered quicker.
Also a reminder that the "Mythos" thing—like all the other doomerist things coming out of "AI" companies—is a marketing stunt to get Anthropic free press coverage.
from my link log —
Gecko: a fast GLR parser with automatic syntax error recovery.
https://vnmakarov.github.io/parsing/compilers/c/open-source/2026/04/22/gecko-glr.html
saved 2026-04-23
➡️ Scrapy - Open-source framework for efficient web scraping and data extraction
#bookmarks
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s MythoOpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
https://www.wired.com/story/openai-launche
OpenAI unveils an updated GPT-5.5-Cyber model, launches the Patch the Planet initiative in partnership with Trail of Bits to fix open source bugs, and more (Lily Hay Newman/Wired)
https://www.wired.com/story/openai-launche
EOLE Evento europeo sul diritto all'open source e al software libero. Workshop di apertura online domani 25 giugno 2026 (dalle 15:00 alle 17:30 CEST)
L'Europa ha riscoperto la "sovranitŠ" attraverso un'ondata di nuove regolamentazioni - Legge sulla resilienza informatica, Legge sull'IA, gare d'appalto per la sovranitŠ del cloud. EOLE 2026 adotta un punto di partenza opposto: il Software Libero, l'Open Source e l'IA aperta perseguono l'autonomia…
Einige der zuletzt hier besonders häufig geteilten #News:
Bund in der Abhängigkeitsfalle: Kostenexplosion bei Microsoft-Lizenzen
«#Zürich will sich von teurer #Microsoft-Software lösen – doch da gibt es ein Problem:
Die Zürcher Stadtverwaltung soll sich aus dem #M365-Würgegriff lösen und auf eine europäische
I believe that we in the US will begin to face a hard question:
We will soon, I hope, begin cleaning up the trump/maga mess.
Given that the trump/maga actors have engaged in inhumane, unlawful, and racist destruction of people and institutions I wonder about the following:
Should those people be protected by our Constitutional norms or will we want to, or need to, bypass our legal protections and procedures as we pursue punishment, disgorgement of ill gains, and compensatio…
🇺🇦 #NowPlaying on BBCRadio3's #Breakfast
Elin Manahan Thomas, George Frideric Handel, Orchestra of the Age of Enlightenment & Harry Christophers:
🎵 Eternal source of light divine (Birthday Ode for Queen Anne)
https://open.spotify.com/track/301GhrxRRyQ0h8NP6NQQxc
I don't understand Open Source.
I use it, I love it, I promote it, and sometimes I contribute, but I don't get it. Perhaps I don't need to.
🇺🇦 #NowPlaying on KEXP's #MidnightInAPerfectWorld
Jump Source ft. POiSON GiRL FRiEND:
🎵 Close
#JumpSourceftPOiSONGiRLFRiEND
https://jumpsource.bandcamp.com/track/close-ft-poison-girl-friend
https://open.spotify.com/track/6CVubsu8aHYG5QztcKmsLz
Right, time to crank out some open source PR's out
@… my context was:
― the The AI/ML Security Working Group.
The working group is an Open Source Security Foundation project. The OpenSSF is a project of the Linux Foundation.
If you must use extreme, inflammatory phrases such as "the beast" and "shitcan" in the future:
― be clearer about the meanings.
Cc
IResearch is an Apache 2.0 C search engine built to live inside databases.
Andrey Abramov is joining #bbuzz26 to benchmark it against leading open-source search engines, and explore how database-native search fits modern query execution.
Learn more: https://2026.berlinbuzzwords.de/session/c-search-for-database-kernels-built-in-not-bolted-on/
This AI Tool Rips Off Open Source Software Without Violating Copyright https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
Am 5. Mai gibt es wieder ein lokales "Free Software Foundation Europe"-Treffen in Wien! Komm vorbei, wenn dich die gesellschaftlichen und politischen Aspekte von Freier Software/Open Source Software interessieren und du dich mit anderen austauschen möchtest!
Wann?
Dienstag, 5. Mai 2026
Ab 18:30 Uhr gemütliches Ankommen
Um 19:00 Uhr Start
Wo?
Im @…
from my link log —
Open access to standards documents.
https://discourse.llvm.org/t/rfc-open-access-to-standards-documents/90856
saved 2026-05-21
I've recently talked with @… who brought up to my attention a 3D printers company I've never heard of: #snapmaker.
While there're not fully open-source, they are still more leaning towards that than some other companies, and they offer quite some…
Mirendil, founded by former Anthropic researchers and seeking to build self-improving AI for open-source developers, raised a $200M seed at a $1B valuation (Tina Li/Wall Street Journal)
https://www.wsj.com/tech/ai…
advogato: Advogato trust network (2009)
A network of trust relationships among users on Advogato, an online community of open source software developers. Edge direction indicates that node i trusts node j, and edge weight denotes one of four increasing levels of declared trust from i to j: observer (0.4), apprentice (0.6), journeyer (0.8), and master (1.0).
This network has 6541 nodes and 51127 edges.
Tags: Social, Online, Weighted
Im IT-Bereich gibt es eine besondere Form des ‚Whitewashings‘, nämlich das ‚Openwashing‘. Der Begriff beschreibt Software, die sich als Open-Source-Produkt ausgibt, es aber nicht ist. Um festzustellen, ob Software, die man einsetzen möchte, frei ist oder nur so tut, hilft: https://isitreallyfoss.com/
"PostgreSQL, MySQL, Cassandra, and other popular open source systems are not measured in and of themselves – only as part of commercial services."
What is the purpose of essentially delisting #PostgreSQL, #MySQL,
My neurologist advised that I should try EEG Neurofeedback. Unfortunately public health insurance doesn't cover it.
Well, I'm just going to DIY it. I just ordered an open source Neurofeedback device with some electrodes.
https://www.olimex.com/Products/EEG/OpenEE
I do understand that there are vast differences between the reactions to user feedback so I am not replying to this post directly, but I do now feel the need to leave this somewhere:
The usual reply I get from 1 man teams is "works as intended, won't fix" while community projects (nextcloud, CoMaps, ...) on the other hand have discussions over months and years that seem to be going nowhere until I don't even care anymore - and either have a workaround or use another a…
This is an excellent post / case study and a lot here for even ‘experienced’ family historians to learn. #genealogy #histodons @… @…
https://open-source-wettbewerb.de/
> das Bundesministerium für Digitales und Staatsmodernisierung übernimmt erneut die Schirmherrschaft für den Open Source Wettbewerb.
> Der Wettbewerb zeichnet Projekte aus, die digitale Verwaltungsprozesse verbessern, die Zusammenarbeit in der Verwaltung …
31st Developers and Devops DORS/CLUC conference starts tomorrow in Zagreb, Croatia.
And on Saturday we'll have #SOTMHR #Openstreetmap track https://
Part 1 of a new short story by Linda Teppler is out! Free to read on Substack #writingcommunity #banskolife #writing
@… That’s so cool, is it open source? Would love to see how you did it :)
As the US House probes Airbnb's use of Chinese AI models, CEO Brian Chesky says the company is not sharing data with Chinese firms and uses open-source models (Natalie Lung/Bloomberg)
https://www.bloomberg.com/news/articles/20
RE: https://unstable.systems/@jneen/116618931097778342
Worth looking at both the quoted text here and •especially• the linked page, which is quite good.
I’ll add another item of my own. The first screenshot mentions giving an LLM the task of “implementing an HTTP server in JavaScript from scratch” in 90 minutes. Sounds impressive, right? Until you remember that every open-source Javascript HTTP server in existence ••was in the training data••.
1/
«AI Slop oder besserer Code — GCC-Arbeitsgruppe für KI-Richtlinien gestartet:
Die Working Group for GCC AI Policy soll festlegen, inwiefern Contributors KI-Tools beim Entwickeln der GNU Compiler Collection nutzen dürfen.»
Da bin ich mal gespannt wie sich das auswirkt und ob dadurch die IT-Sicherheit im Open-Source Bereich wirklich erhöht wird.
🧑💻
No puede haber una IA de código abierto si todas sus partes no son de código abierto, y eso significa que también deben de ser accesibles los datos utilizados para entrenarla https://opensource.org/ai/open-source-ai-definition
Are they right? 🤔
"Euro-Office defaults to the fully proprietary OOXML document format, developed and controlled solely by Microsoft. This makes it a de facto ally of Microsoft in its content lock-in strategy, with control remaining firmly in Redmond and far from Europe."
https://blog.do…
Open source is benefiting from the current AI trend: some projects are already improving their security posture and reducing their attack surface.
Proprietary software, for now, seems more out of the loop.
But once LLMs become better at analysing binaries, compiled code, and obfuscation, I wonder how vendors will handle the likely increase in vulnerability disclosures.
#ai
Every modern digital technology
– from AI to quantum computing
– is based on foundational open source software building blocks.
Open source code is embedded in almost all products and services,
enabling economic growth and ensuring the resilience of our society and government.
While open source software has become the backbone of our digital infrastructure,
these essential components do not receive adequate support and investment.
Targeted and long…
The Baker, the Polluters and the Planet
https://open.substack.com/pub/theclimatehistorian/p/the-baker-the-polluters-and-the-planet?utm_source=share&utm_medium=android&r=e4myx
OPNsense
Professionelle Open-Source-Firewall für zu Hause und im Unternehmen
Seit einigen Monaten betreibe ich OPNsense auf einer dedizierten Firewall-Appliance — und ich möchte ehrlich sagen: Es war eine der besten Entscheidungen, die ich in Sachen Heimnetz- und Büronetz-Sicherheit je getroffen habe. Dieser Artikel erklärt, was OPNsense ist, was es kann, wo es an Grenzen stößt und warum es einer herkömmlichen Fritzbox in fast jeder Hinsicht überlegen ist.
How tech companies are using open source initiatives to achieve critical strategic goals and how such efforts are reshaping industries like AI, AVs, and more (Bill Gurley/Bill's Substack)
https://p3institute.substack.com/p/from-open-source-software-to-open…
The Irish Council for Civil Liberties (#ICCL) has released an open source tool designed to reduce LLM hallucinations.
If my 15-year-old PC had a GPU I'd be tempted to give it a try.
https://www.
Don't miss today's Metacurity for the most critical cybersecurity developments you might have missed over the weekend, including
--White House opens backchannel to Anthropic as Pentagon fight simmers,
--Anthropic gave NSA access to Mythos Preview,
--Anthropic's donation to open source developers highlights how under-sourced they are,
--Asian regulators urge banks to use Mythos,
--LayerZero-powered cross-chain bridge Kelp DAO lost $292m in DPRK exploit…
How hacker group TeamPCP exploited the open source trust model and distribution method to compromise and inject malware into over 1,000 software packages (Matt Kapko/CyberScoop)
https://cyberscoop.com/teampcp-breaks-open-source-software-trust-model/
Una lettera aperta agli utenti di suite per ufficio, poco prima dell'annuncio di Euro-Office
«Negli ultimi giorni avrete letto diversi articoli che annunciano l'arrivo di EuroOffice, presentato come la prima suite per ufficio open source sviluppata in Europa. Ci sentiamo in dovere – seppur a malincuore, poiché l'open source dovrebbe basarsi sulla trasparenza e non sull'inganno – di correggere questa affermazione. La prima suite per ufficio open source sviluppata in Euro…
«Ladybird-Browser stoppt öffentliche Code-Beiträge:
Wegen KI-generierter Beiträge schließt das Open-Source-Projekt Ladybird seine öffentlichen Pull-Requests, um die Sicherheit des Browsers zu garantieren.»
Da sehen wir wie KI das Gegenteil von sicherer Produktion ist, wenn es blind als unstrukturiertes Pull-Request eingesetzt wird.
🌐
from my link log —
Can we trust Microsoft with Open Source?
https://dusted.codes/can-we-trust-microsoft-with-open-source
saved 2021-10-23
Europe’s Digital Future
The EU Tech Sovereignty Package is a once-in-a-generation opportunity to reclaim control over our digital foundations.
For too long, public sector procurement has defaulted to proprietary lock-in, creating a weak sovereignty posture that hinders European resilience.
We are calling for a fundamental shift: the Open Source First principle.
Auch Zürich will hybriden Ansatz ausprobieren.
#OpenDesk #digitaleSouveränität
Einige der zuletzt hier besonders häufig geteilten #News:
Stringman: Fest montierter Open-Source-Roboter räumt einzelne Räume auf
After EV maker Fisker's collapse, ~4,000 car owners formed a nonprofit to keep their cars working by reverse-engineering software and building open-source tools (Fred Lambert/Electrek)
https://electrek.co/2026/05/16/fisker-ocean-open-source-ev-story-aft…
Just over a week after Mosaic 1.0 was released, CERN gifted the Web to the world as open source software. As of 30 April 1993, the still relatively new Internet communications platform was suddenly free for anyone to use, with no strings attached.
https://cybercultural.com/p/1993-mosai
Some organizations are doing panicky things over Mythos.
NHS Goes To War Against Open Source
https://shkspr.mobi/blog/2026/05/nhs-goes-to-war-against-open-source/
Microsoft has locked the lead developers of two prominent open source security projects out of their accounts.
https://www.computing.co.uk/news/2026/microsoft-locks-open-so…
Cal.com, which provides scheduling software, is moving its core open-source codebase to a closed repository, citing the dangers of AI hacking its open code (Steven Vaughan-Nichols/ZDNET)
https://www.zdnet.com/article/ai-security-worries-force-company-t…
OpenDesk kann vieles, aber halt nicht alles. Das ist das Fazit einer Studie aus Zürich, die die Open-Source-Lösung als Microsoft 365-Alternative unter die Lupe genommen hat. 🔍
Zum Artikel: https://heise.de/-11303065?wt_mc=sm.red.…
Moonshot introduces Kimi K2.6, an open-weight model that it says shows strong improvements in long-horizon coding tasks, available under a modified MIT License (Kimi AI)
https://www.kimi.com/blog/kimi-k2-6
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
Münchens IT-Wende: Open Source ist für die neue Koalition der Normalfall
from my link log —
MiniZinc high-level solver-independent constraint satisfaction and optimization modelling language.
https://www.minizinc.org/index.html
saved 2019-09-30
«Googles reCaptcha bekommt Handgestenerkennung:
Eine neue Option soll den Bot-Schutz mittels Googles reCaptcha verbessern. Die Kamera nimmt dafür einfache Handgesten auf.»
Ich bin dem sehr kritisch gegenüber, denn dies wird früher oder später sicherlich dann auch für das KI-Training genutzt. Abgesehen davon gibt es einige Open-Source Alternativen die Webservices vor Onlinespam schützen.
🫸
Meta: Neue KI-Modelle sollen teils Open-Source werden
Meta plant, neue KI-Modelle zu veröffentlichen. Die sollen in Teilen unter Open-Source-Lizenzen herausgegeben werden.
https://www.heis…
«Sniffnet 1.5: Welches Programm funkt nach Hause?
Der Open-Source-Netzwerkmonitor @… ordnet Traffic nun einzelnen Programmen zu. Version 1.5.0 bringt zudem Blacklists und Adapter-Vorschauen»
Zu viele glauben immer noch nichts zu verbergen zu haben und realisieren nicht, dass sie das Produkt sind anhand von IT- & Online-Tools.
🕵️
Socket: TeamPCP, the gang claiming GitHub's repositories breach, also executed 20 "waves" of supply chain attacks recently, compromising 500 pieces of software (Wired)
https://www.wired.com/story/teampcp-software-supply-chain-attack-spree-github/…
SpaceX signs a computing deal worth up to $6.3B with Reflection AI for access to Nvidia GB300s at Colossus 2; Reflection will pay $150M per month through 2029 (Deirdre Bosa/CNBC)
https://www.cnbc.com/2026/06/22/spacex-ai-colossus-data-center-reflection.html
FediSuite: Open-Source Social-Media-Management fürs Fediverse — Alle deine Fediverse-Accounts an einem Ort.
FediSuite ist eine kostenlose Open-Source-Plattform zum Planen von Beiträgen, automatischen Aufteilen langer Posts in Threads, Verwalten von Benachrichtigungen und dem Handling mehrerer Accounts auf 14 Fediverse-Plattformen — @…,
Sources: Meta is preparing to release the first AI models developed under Alexandr Wang, with plans to offer versions of those models via an open source license (Ina Fried/Axios)
https://www.axios.com/2026/04/06/meta-open-source-ai-models
Mozilla launches Thunderbolt, an open-source AI client for users and businesses who want to run their own self-hosted AI infrastructure, available on GitHub (Kyle Orland/Ars Technica)
https://arstechnica.com/ai/2026/04/mozil…
Einige der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Inference cloud startup DeepInfra raised a $107M Series B co-led by 500 Global and Georges Harik; it currently supports more than 190 open models (Mike Wheatley/SiliconANGLE)
https://siliconangle.com/2026/05/04/deepinfra-la…
Anthropic commits up to $100M in usage credits for Project Glasswing, along with $4M in direct donations to open-source security organizations (Greg Otto/CyberScoop)
https://cyberscoop.com/project-glasswing-anthropic-ai-open-source-software-vulnera…
Noch ein paar der zuletzt hier besonders häufig geteilten #News:
OpenReception 1.0: Open-Source-Terminverwaltung für Arztpraxen ist fertig
Europa hat jetzt sein eigenes Office – und das ist auch noch Open Source! 🚀
Zum Artikel: https://heise.de/-11320254?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
Servus, freie Software! 🥨 In München weht ein neuer Wind durchs Rathaus – und der riecht verdächtig nach Open Source.
Zum Artikel: https://heise.de/-11292444?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_sou…