Brief IA

Cal Abandons Open Source: AI Redefines Software Security

💻 Code & Dev·Tom Levy·

Cal Abandons Open Source: AI Redefines Software Security

Cal Abandons Open Source: AI Redefines Software Security
Key Takeaways
1Cal, founded in 2022, is migrating its flagship program to a proprietary license to counter AI hacking threats.
2Bailey Pumfleet, CEO of Cal, emphasizes that tools like Claude Opus exploit vulnerabilities in open-source code.
3Cal.diy, an open-source version for hobbyists, is launched despite the withdrawal of the commercial program from open source.
💡Why it mattersThis decision could influence other open-source companies in light of the increased risks of AI hacking.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

Cal migrates to a proprietary license

Cal, a company founded in 2022, has decided to transform its flagship open-source program into a proprietary model. This decision, made by CEO and co-founder Bailey Pumfleet, is driven by the increasing dangers posed by AI-facilitated hacking. From its inception, Pumfleet emphasized that Cal.com would be an open-source project to overcome the limitations of existing scheduling products. Today, Cal claims to be the largest Next.js project, which reflects its initial success.

A growing threat

Modern AI tools, such as Claude Opus, are capable of scanning open-source code for vulnerabilities. This capability has prompted Cal to abandon the GNU Affero General Public License (AGPL) in favor of a proprietary license to enhance the security of its program. Pumfleet compared open-source code to handing over the blueprint of a safe, adding that there are now 100 times more hackers studying that blueprint.

The impact of AI hackers

Historically, many companies have opted for semi-proprietary licenses for commercial reasons. However, Cal is innovating by completely closing its open-source commercial program, a decision that could disrupt open-source advocates. Peer Richelsen, co-founder of Cal, stated that the security of open source relied on transparency, but that AI attackers are now exploiting this openness. "The security of open source has always depended on people finding and fixing issues," he explained.

Risks highlighted by Mythos

Anthropic's Mythos model has demonstrated its ability to penetrate secure systems, such as OpenBSD. However, it is not Mythos that has precipitated Cal's change, but rather the ease with which earlier models like Claude Opus can exploit vulnerabilities in open-source code. Huzaifa Ahmad, CEO of Hex Security, asserted that open-source applications are 5 to 10 times easier to exploit than closed-source ones.

A changing software economy

Pumfleet emphasized that Cal does not want to risk its users' sensitive data to maintain an open-source model. "We want to be a scheduling company, not a cybersecurity company," he stated. This position reflects a fundamental shift in the software economy, where companies must choose between data security and code openness.

Introduction of Cal.diy

In parallel, Cal has launched Cal.diy, a fully open-source version aimed at enthusiasts. This project allows experimentation outside of the commercial application, which handles sensitive data. Pumfleet reiterated Cal's commitment to open source, specifying that the situation could evolve if security conditions improve. "This decision is entirely about the vulnerability that open source introduces. We still firmly love open source, and if the situation were to change, we would open our code again," he concluded.

The rise of AI poses a major challenge to open-source projects, and other companies may follow Cal's example to protect their data and users.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.