AI may erode open source’s classic security advantage, according to a Linus’s law rethink
BlackHC · x · 2026-07-27
Linus’s law — the idea that “given enough eyeballs, all bugs are shallow” — may need a rethink in the age of cheap AI models.
- Historically, open source gained two advantages:
- more free reviewers helped find and fix bugs
- openness created a net security win because defenders outnumbered attackers
- The post argues that AI changes both sides of the equation:
- models can continuously substitute for many human “eyeballs” at low cost
- the same openness also helps adversaries search for weaknesses and vulnerabilities
- The core question is whether the old asymmetry still holds once AI makes both scanning and exploitation cheaper, and whether more software could move back toward closed development.
More from AGI Musings
- Open-weight AI will be used for harm, says quote-tweet arguing bad actors always adapt — basedjensen · 2026-07-27
- ARC-AGI’s name may overstate what the benchmark can really tell us about AGI — tedgreenwald · 2026-07-27
- Joshua Saxe says a near-term international AI safety deal still looks hard as cyber risk rises — joshua_saxe · 2026-07-27
- Open weights may lag frontier AI by 3–12 months, but still act as a sovereign fallback — robleclerc · 2026-07-27
- Chamath says strict AI rules could leave the U.S. paying 50x more per token — KoseteBamse · 2026-07-27
- Why should LLMs be review-only if they already beat average human reviewers? — andrewgwils · 2026-07-27