7 ms·
I think Tridge is simultaneously trying to be proactive and kinda giving too much credit to marketing. Anthropic has not been able to really give numbers or act
by Eufrat 4mo ago
I think Tridge is simultaneously trying to be proactive and kinda giving too much credit to marketing. Anthropic has not been able to really give numbers or actual values on what Mythos can really do. It just waved Mythos in front of the public like a boogeyman screaming that AI is going to cause a security nightmare (and it has, but mostly through vibe coded trash from what I’ve noticed); I’m hard pressed to find their statement that they spent less than $20,000 to find a Kerberos bug in FreeBSD a compelling win without a lot more context and they seem disinclined to provide that data. I really do wonder what evidence they have provided to their approved partners, all of this smells…weird.
I honestly think the main problem is Tridge just failed at communicating any of this correctly and I don’t think the implication he gives that all of this was due to the urgency of the impending security apocalypse really holds water.
Why was all of this written straight to the master branch? Now that the release is out, why not better explain what the urgency of this release was? Why wasn’t he proactive in communicating this and instead let the mob make up their own story? I think a lot of people are inclined to give Tridge a lot of leeway due to the fact that he literally is the reason why rsync exists, but this was avoidable and I think the comment in his response post where he mentions that, “I’d rather be out sailing than working on rsync security issues, so I have reached for several AI tools to help with what needs to be done,” speaks volumes as to what is going on.
- rsc 4mo agoAs a long-time open-source maintainer, I find all the second-guessing and armchair psychoanalysis here (not just in this comment, all over HN) about Tridge's motivations, state of mind, and so on incredibly off-putting. Tridge doesn't owe anyone anything as far as rsync is concerned. Yet he is spending his time maintaining it, only to be attacked for his efforts. To respond to the specific technical point, there really _is_ a flood of security reports arriving everywhere in the past few months. The jury is out on whether Mythos is that much better than alternatives, but even the publicly available models are _highly_ capable of finding real problems, and they are being employed to that end quite effectively. Here are the counts of security issues fixed in each monthly Go minor release going back to the start of 2024: 0 2024-01-09 Go 1.21.6, Go 1.20.13 0 2024-02-06 Go 1.21.7, Go 1.20.14 5 2024-03-05 Go 1.22.1, Go 1.21.8 1 2024-04-03 Go 1.22.2, Go 1.21.9 2 2024-05-07 Go 1.22.3, Go 1.21.10 2 2024-06-04 Go 1.22.4, Go 1.21.11 1 2024-07-02 Go 1.22.5, Go 1.21.12 0 2024-08-06 Go 1.22.6, Go 1.21.13 3 2024-09-05 Go 1.23.1, Go 1.22.7 0 2024-10-01 Go 1.23.2, Go 1.22.8 0 2024-11-06 Go 1.23.3, Go 1.22.9 0 2024-12-03 Go 1.23.4, Go 1.22.10 2 2025-01-16 Go 1.23.5, Go 1.22.11 1 2025-02-04 Go 1.23.6, Go 1.22.12 1 2025-03-04 Go 1.24.1, Go 1.23.7 1 2025-04-01 Go 1.24.2, Go 1.23.8 1 2025-05-06 Go 1.24.3, Go 1.23.9 3 2025-06-05 Go 1.24.4, Go 1.23.10 1 2025-07-08 Go 1.24.5, Go 1.23.11 2 2025-08-06 Go 1.24.6, Go 1.23.12 1 2025-09-03 Go 1.25.1, Go 1.24.7 10 2025-10-07 Go 1.25.2, Go 1.24.8 * 2025-10-13 Go 1.25.3, Go 1.24.9 0 2025-11-05 Go 1.25.4, Go 1.24.10 2 2025-12-02 Go 1.25.5, Go 1.24.11 6 2026-01-15 Go 1.25.6, Go 1.24.12 2 2026-02-04 Go 1.25.7, Go 1.24.13 5 2026-03-05 Go 1.26.1, Go 1.25.8 10 2026-04-07 Go 1.26.2, Go 1.25.9 11 2026-05-07 Go 1.26.3, Go 1.25.10 3 2026-06-02 Go 1.26.4, Go 1.25.11 * The Go 1.25.3 and Go 1.24.9 releases were a fast follow to fix a problem introduced by one of the security fixes the previous week. You can see that 2026 has been quite different from the previous years. There are plenty of other contemporaneous accounts from other security teams about the load increase they've seen (which again is almost entirely not Mythos). Also, the number of reports we are receiving has gone up far faster than the number of actual vulnerabilities. Over the 75-month period from January 2020 to early April 2026, the final 30 days accounted for ~16% of the reports. It is easy to believe that Tridge is seeing a similar flood of reports. More reports means more fixes means more code changes means more bugs.
- Eufrat 4mo ago> As a long-time open-source maintainer, I find all the second-guessing and armchair psychoanalysis here (not just in this comment, all over HN) about Tridge's motivations, state of mind, and so on incredibly off-putting. I agree that the entire episode is obscene, but I am also unsure of what to do here either. On some level this is the same problem movie stars run into. I agree that guessing or waxing about the motivations of anyone is a nosy and overall unproductive exercise (yet paparazzi exist because of this very human behavior), but I also think that there is a modest duty owed to users to explain things. > Tridge doesn't owe anyone anything as far as rsync is concerned. Yet he is spending his time maintaining it, only to be attacked for his efforts. I am reminded of this piece: https://mikemcquaid.com/open-source-maintainers-owe-you-nothing/ https://mikemcquaid.com/open-source-maintainers-owe-you-noth... Which, I empathize with, but I fundamentally disagree that maintainers owe users nothing. I will die on that hill. If you are getting to that point where you actively loathe working on the project, I agree you should be able to walk away. However, I strongly believe that when you create something for people to use that there’s an implicit social contract about how to go about doing certain things. I suppose in a very extreme and intentionally histrionic example, having a project carry the MIT license, getting frustrated and then changing the project to delete the entire system is a crime. The average person and the courts don’t care if the license is “as-is”. There is a duty that is understood that you don’t do that and I think we need to make it clear what that duty is for OSS. Ultimately, though, I think this is all symptomatic of the fact that the OSS model has gaps that the increase in security reports whether AI generated or not has exerted more pressure on. I have certainly been on the receiving end of a lot of frivolous security reports that were discarded because it was obvious that it was just someone with a security scanner wandering around the Internet. You still have to review that nonsense and it eats into your time. Doing this on your own time, without pay and having to listen to the peanut gallery is just infuriating. Is any business built on top of rsync going to donate their money in a sustainable manner?
- agartner 4mo ago> the courts don’t care if the license is “as-is”. There isn't any case law to show that. Certainly not in the age of AI. On the criminal side, the CFAA requires "intentionally causes damage" and that's entirely impossible to prove in the age of AI. On the civil side, liability waivers and warranty disclaimers generally cannot shield intentional or willful misconduct or gross negligence.
- wolletd 4mo ago> “I’d rather be out sailing than working on rsync security issues, so I have reached for several AI tools to help with what needs to be done,” Well, then maybe it's already overdue to find a new maintainer for the project and let someone else continue it? The tool will not get better from someone working on it who doesn't want to.
- kelnos 4mo agoUnless you're willing to step up and be that person, it's not your place for you to suggest it.
- wolletd 4mo agoI don't agree with that, I can very well still discuss that. He clearly sounds like someone who doesn't want to do this work anymore and should have searched for a successor. That's my impression from that sentence, at least. Don't you agree? So, why didn't he do it? Because just firing up Claude and let it rip is way easier than finding real people and building up trust? Did Claude increase bugs in rsync? Or did Claude just gave some basically retired programmer, who doesn't even want to work on his project anymore, the impression that he can replace finding a successor with just handing it to AI?
- lemming 4mo agoBecause just firing up Claude and let it rip Based on Tridge’s post, this seems an unfair characterisation of how he used Claude. Did Claude increase bugs in rsync? TFA answered this, the answer is “no”.
- prmoustache 4mo ago> and should have searched for a successor. He doesn't have to do that. If he ever do not care enough he can just stop maintaining it and that's it.
- duskdozer 4mo ago
- rossjudson 4mo agoYeah, we definitely need to make sure that we take the considerations of the mob into account. The person owning the project is using the master branch in the way he sees fit. Incidentally, there is no amount of communicating "correctly" that quells a mob. There's a Venn diagram of concerns, and those with concerns not being met will generate (now infinite) outrage.