OSS Supply Chain Security. Founder/CEO/Primary Ariba Admin at chainguard.dev Sigstore: sigstore.dev

The Arena
Open source is dying. We raised over $800M to save it. Chainguard is the world’s first infrastructure that stops cyberattacks before they can start:
63
41
317
839,935
This is a strange moment we’re living in. Dario is saying the most sane and balanced shit ever, that’s like completely common sense, and people are hearing ransom voices in their heads. Here let me try: “It would be bad if every 14-year-old boy could create massive hacking campaigns, or dox their female schoolmates with deepfakes that make them want to kill themselves, or any number of other things because they have an unrestricted open model that’s smarter than Mythos. Which will soon be possible. In other words there are millions of young people, and people who have nothing to lose, or people with low self-control that would accidentally or otherwise do extraordinary harm, with unrestricted models this smart. We’re just saying there should be a tiny amount of friction that prevents those types of seriously dangerous misuse by people who are good but in a (perhaps temporary) bad situation.” PEOPLE: “So you want to burn books.” ME: “No. I’m saying there are a lot of people suffering who have no money in this world. Like hundreds of millions or billions of people. People with severe mental problems. People losing their jobs and their relationships and their livelihoods. Or people who had never had any of those things and are willing to do anything to get ahead. All I’m saying is it’s a good idea to make it SLIGHTY harder to do harm on a whim. In other words, don’t make the models that are completely unrestricted and this smart publicly available on every model website for free with absolutely no restrictions. Because if we do that, the amount of harm that will result from it will be completely predictable.” PEOPLE: “So you only want rich billionaires to have good models, and everyone else is locked down to stupidest stuff forever.” ME: “Who said anything about stupid? Everyone should have extremely smart open source AI. All I’m saying is the public and widely available versions of the models should have some basic level of controls around preventing extremely dangerous prompts. Like how to ruin somebody’s reputation or shoot up a school or take down critical infrastructure or steal money from a local bank with bad security, etc.” THEM: “So you want Dario and Sam to rule the whole world then with no democracy.” Jfc. This is literally what this debate looks like right now. Virtually everywhere that it takes place. And the trajectory that we're on is basically going to guarantee that we have these unrestricted open-source models that are way better than Mythos or GPT-6. We are going to have these in the next three to 18 months, almost for certain. So we're about to find out really fast that when hundreds of millions of people, or billions of people, have access to something that is that dangerous and is completely free and unrestricted, bad things will happen. And then the same types of people will be like, "I can't believe we did this. We should have had some sort of controls." Yeah, no shit, that's literally what we are telling you right now.
96
15
124
24,637
Open source is dying. We raised over $800M to save it. Chainguard is the world’s first infrastructure that stops cyberattacks before they can start:
63
41
317
839,935
Today, @OpenAI, @anduriltech, @canva, and hundreds of other companies reduce their attack surface by 85%. We are becoming the foundation for modern software.
1
26
36,995
And now we’re hosting a bug hunt with a $200,000 prize pool. If you find a vulnerability in our system, we’ll pay you up to $200k. chainguard.dev/unchained/we-…
Open source is dying. We raised over $800M to save it. Chainguard is the world’s first infrastructure that stops cyberattacks before they can start:
20
35,376
We are so back
Letter: the US lifts its block on Mythos 5, allowing Anthropic to release it to more than 100 US institutions; sources: talks about Fable 5 are ongoing (Semafor) (Visit Techmeme dot com for the link and full context!)
3
46
3,237
Whoa, congrats to Chainguard on the 2nd biggest partnership of the day!
Chainguard 🤝 @cursor_ai Our new partnership is making trusted OSS the foundation for AI-driven development. Now, devs using Cursor can pull from our CVE-free containers and malware-resistant libraries instead of public registries. See it in action 👇 chainguard.dev/unchained/cha…
4
3
23
4,381
There's something charming about watching claude build other agents. When you debug prompts and tool calls, you can almost see it empathize with the smaller, weaker agent.
1
7
741
Dan Lorenc retweeted
some news; @latentpatterns 🤝 @chainguard_dev Chainguard will provide secure images for the embedded terminals within Latent Patterns. You’ll be able to run Claude code from within your browser. Zero api key provisioning or software installation. It just works, even on a Chromebook, from your browser... Thanks @lorenc_dan 🍻 ps. @chainguard_dev is hiring, and Dan mentioned employees get a near-unlimited budget for tokens...
5
3
58
5,057
Multicloud, my take on Gastown is alive, self-hosting, and cranking. Gastown showed me the future, this is my version of it. Check it out! github.com/dlorenc/multiclau…
12
4
38
7,267
Send help. I ignored all the instructions and used my Polecats with the Refinery. The Mayor and Deacon reported me to the Witness and the Sheriff is after me.
6
1,885
Dan Lorenc retweeted
The recent FFmpeg drama with Google is insane, and I'm surprised that so many people agree with FFmpeg's take on X. Google isn't even demanding FFmpeg's maintainer to fix the security bug. Are we living in a world now that sending LEGITIMATE bug reports is suddenly a sin?
I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 google oss fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments @ffmpeg (Kieran) has made about google. From all companies, google has been the most helpfull & nice
56
22
580
62,067
I am the main developer fixing security issues in FFmpeg. I have fixed over 2700 google oss fuzz issues. I have fixed most of the BIGSLEEP issues. And i disagree with the comments @ffmpeg (Kieran) has made about google. From all companies, google has been the most helpfull & nice
85
195
4,066
917,621
Some actual facts here.
We’re excited to see the security and OSS communities engage on vulnerability disclosure in light of new AI technologies that we believe will enable both defenders and attackers alike. Existing and emerging norms around disclosure are important debates, and we’ve noted the feedback. Thanks! Also want to share some additional thoughts. 1/10
1
6
1,954
Tragedy of the commons is the dumbest, laziest, worst possible analogy for open source sustainability. Stop using this. Please. Everyone.
Recently, there was a clash between the popular @FFmpeg project, a low-level multimedia library found everywhere… and Google. A Google AI agent found a bug in FFmpeg. FFmpeg is a far-ranging library, supporting niche multimedia files, often through reverse-engineering. It is entirely the result of volunteers and a marvellous piece of technology. For people who have never been on the receiving end of ‘security researchers’, it is difficult to understand why there is a pushback against them. Think about the commons. In Quebec, these are pieces of land where farmers send their cows during the summer. It is collectively owned, like FFmpeg. Everyone is responsible to care for the commons if they are using it. If you are not using it, you are supposed to stay away. Now, imagine a rich corporation comes in and sends its well-paid agents into the commons to find issues with it. Maybe a broken barrier or a dangerous hole. So far so good… But instead of fixing the issues, the corporation says “you have a month to fix the issue or else I will report you to the government”. How much love would the big corporation get in this context? Why do the security researchers insist on disclosing the issue without having contributed to fixing it? So that they can get credit for it. That's their entire scheme: find issues, irrespective of whether they affect the use case of their employer... after all, all issues no matter how small can be potentially significant at some point... and then brag about it without doing the hard work of trying to fix it. Let me be clear that no everyone working in security behaves this way. Many are good actors. But there are enough 'security researchers' behaving as parasites that it has become a recognizable pattern. « But Daniel, who should be fixing the bugs then? » If you are paying for commercial support, then get in touch with the folks you are paying. If you are not paying, then it is on you. It says so in the licenses. It is part of the moral code open source. It is part of the legal framework. Let me be clear. You do not get to bite back at Linus Torvalds if a bug in the linux kernel crashes your server. What you do is that you identify the issue, narrow it down and propose a fix. If you cannot do it, then you pay someone to do it. Or you just do not use Linux.
2
15
5,058