Industry
Why? - Risk comes from capability asymmetry between attackers and defenders. Open source is what every frontier lab already trains on so def…
Why? - Risk comes from capability asymmetry between attackers and defenders. Open source is what every frontier lab already trains on so defenders get the same AI firepower as attackers. With propriet
Why? - Risk comes from capability asymmetry between attackers and defenders. Open source is what every frontier lab already trains on so defenders get the same AI firepower as attackers. With proprietary code, you're on your own. The biggest risk is someone training a model on your obscure stack and attacking you when no public model exists to defend it. - AI can now read stripped binaries, so proprietary obscurity barely protects anyone anymore. Most legacy firmware and embedded code is closed, binary-only, and no longer maintained. A huge attack surface that just became legible to AI. - In a Mythos world, software security becomes a speed race: detection, verification, coordination, patch propagation. Closed-source systems are weaker at all four because they centralize knowledge and action inside a vendor, while open ecosystems distribute both. - In open source, the defender crowd is usually bigger than the attacker crowd. In closed source, it's the opposite. AI force-multiplication will amplify that imbalance. And when closed-source systems fail, the blast radius tends to be much larger. They sit behind centralized user, customer, and cloud data, while open source more often runs locally with less data concentration. Let's go open-source! In a mythos world (which we are already in), closed-source projects will be 10x more at risk than open-source projects!
Related
- Open source software will be many times more secure than closed source software in the new Mythos era
- Given the increasingly closed-source nature of the U.S. AI ecosystem, it is now more important than ever to push for the proliferation of op…
- Feels like one of the cybersecurity risks over the coming months will be widely used open-source projects that are simply too lightly mainta…
- 'The priority for defenders is to start building now: the scaffolds, the pipelines, the maintainer relationships, the integration into devel…
Source: Clem Delangue (X) | 2026-04-20