sneezes don't happen at ground level
they happen at gesundheight
Finished a MSc in CS at University of Helsinki! đ
Senior SWE at Cactos, battery energy storage systems. Previously Senior SWE at Garden, SRE at Webflow.
Recreational computer graphics, Rust, photography, cycling.
| Pronouns | he/him |
| GitHub | https://github.com/walther |
| Bsky | https://bsky.app/profile/waltteri.net |
| https://twitter.com/anotherwalther |
sneezes don't happen at ground level
they happen at gesundheight
The four organizations who maintain your favorite open-source DNS software, ISC, CZ.NIC, PowerDNS and NLnet Labs, gave a lighting talk at @dnsoarc 46 about the avalanche of LLM-assisted security reports for their projects, and the effect it has on us and our users.
The last slide ends on a âHug your OSS maintainer" note, but I think this is understating the gravity of this situation. I hope we put forward a stronger message during the repeat of this presentation at RIPE 92.
People need to consider that we are in a situation where developers with talent, purpose and experience have created something valuable for the internet community over the last 20+ years. They could have chosen to work at $MEGACORP for twice, three times the pay, but they chose to do something meaningful.
Now, the body of work they carefully designed and maintained over the last decades is being picked apart by an LLM. Yes, as a result the products become some definition of âmore secureâ but there is no reasonable prospect that this avalanche of reports will end. Ignoring them is not an option. Feature development has come to a halt.
As an employer, what am I supposed to tell my developers? Thanks for creating this amazing DNS software over the last 20 years, it looks like youâll spend the next couple of years triaging and fixing bugs and coordinating CVEs with your peers.
How do we keep people motivated to do open source and even if we do, how do we keep this development model sustainable? We canât pivot to the âagentic eraâ just like that and even if we could, I think my colleagues do this job to create something amazingâartisanal if you willânot to to maximize output at all costs so shareholders get rich.
Practically though, encouraging organizations to purchase a support contract will certainly help on the short term, because:
- You will get access to world class support;
- You will get early security vulnerability notices under NDA, keeping your critical infrastructure safe from a whole new class of LLM fueled risks; and
- In the grand scheme of things, you will help keep this open source model sustainable so your favorite DNS software continues to exist and thrive.
Excited to announce that the @EUCommission has updated it's follow buttons on the website footer!
What's that first platform there? Could that be #Mastodon?
And where did the link to #X go?
All the posts and comments here on Mastodon calling for this, trust me we read them!