I gave up my smartphone 6 years ago because I concluded the conveniences it offered came at cost of too much of my attention, freedom, and privacy. My ability to focus was just gone, and this magic device was not making me happy or productive anymore.
Within a year, my hyper-focus abilities I remember having as a teen starting flowing back. In the last 5 years I have done the best work of my career, including creating the first fully deterministic Linux distribution, building a community around it, helping start 3 companies, learned endless new skills.
I am not reachable or able to reach the internet every second of every day, and in the modern world that sounds scary. Yet I have a family, an active social life, frequently travel, meet new people every week, co-running two companies while actively developing new tech with daily progress, etc.
All of those things were -accelerated- by me being intentionally offline whenever I am not at a desk.
Unplugging the internet is easy. Running high risk code offline in highly tamper evident ways is hard, but plenty of teams like mine specialize in this sort of thing. (See: https://distrust.co and https://caution.co)
In our audits we regularly see billions of dollars in value at major companies at risk of theft by any anon paying attention that wants it, and we also absolutely know how to fix it and we maintain a lot of open source tools to accelerate doing so.
Some simply have no interest in any fixes that are not legally required or might have any short term impact on team velocity.
I am not saying responsible research is easy, but I am saying that at their budget and scale there are no excuses to cut major corners on safety when the stakes and potential for very bad outcomes for others are this high.
You had my interest until "source available". Especially when you used MIT from the start and changed it later. FOSS hackers like me feel betrayed by moves like that because your product was built on FOSS others created and you are not paying that forward.
Also, I for one would never invest a second in tools I cannot freely modify and share the code of under OSI terms. I would strongly suggest a convenience tax model. Hackers will self host and maybe contribute but those with more money than time will put in a credit card. Maybe offer end to end encrypted memory and compute to secure enclaves where additional compute on the data can be done when the laptop is closed. (Shameless plug, this is what https://caution.co enables, and 100% FOSS)
However, with "source available" you are just begging for someone to AI launder your code into a FOSS clone you will have 0 recourse on. If you FOSS it yourself then you get to capture the FOSS community destined to form around this idea. Some of that community will have bosses that will pay you.
MIT may not be the right play though. AGPL is a good middle ground as it flips the script. Corpo lawyers are allergic to AGPL and will pay for an alternative license, but for community hackers that might want to improve and recommend your code it offers no restrictions.
Instead of asking users to create another password, they just specify a username, tap, and they have an account. Good security and UX do not need to be at odds.
I am the author of AirgapOS and I have designed systems to run in underground zero emissions chambers that are interacted with via carefully verified sd cards and/or fiber optic serial terminals.
If OpenAI had done this, the attack would not have happened. In high risk computation 0days must be in your threat model from the start, so you secure things with the laws of physics.
You can simulate the internet in an airgapped environment for the tests and services you want it to interact with if you have enough disk space, and, they absolutely do.
Models started proving readily capable of autonomously finding 0days over a year ago. At that point (ideally long before) the responsible sandbox for research labs with new models highly capable of this sort of thing should be literally airgapped. Disconnect the rack physically from any access to the internet, and give it an offline mirror of all of PyPi, NPM, Wikipedia, whatever as needed. They can afford the disk space. They already mirror it all anyway as training data. That is the bare minimum. Personally I would rule out side channel attacks with a $40k Tempest spec rack for good measure. Can interact with it via pubsub over a fiber optic serial terminal.
Such things are pretty normal in biotech, fintech, and defense who must have 0days in their threat models. AI labs absolutely need to start being forced to operate this way by endless negligence lawsuits. Move fast and break things culture is not going to cut it anymore.
It is not possible one of their extraordinarily high paid engineers did not know how to deploy an airgapped environment for the models to run in. Even if somehow true, they also clearly failed to contract specialists like myself to advise them on how to airgap software properly. Models will not break the laws of physics.
They simply thought "Running in a VM/Container is easier and probably fine".
And the next 1000 escapes will be for the same reason, because negligence is quick and thus more profitable.
Currently trying to avoid an open weight model ban while OpenAI, who is closed, lets theirs run wild on the internet causing harm to another company because they do not understand how to airgap things. Cool.
At Caution we -exclusively- allow passkeys. The entire database is user ids and public keys. If it leaks, it would only be mildly annoying.
If you are confused about digital passkeys, you can use a physical yubikey or nitrokey and tap it when it blinks. You can treat them like a credit card or house keys.
Asking people to keep up with and remember passwords is and always has been the thing that was invented with zero understanding of the consumer brain.
Three employers in a row insisted on handing me a macbook, and three times in a row I ported Gentoo to it out of pure spite and disdain for third parties trying to control the binaries I use to do my job.
At the time they called this crazy and unproductive, but those obsessions with control of my tools built the foundational skillsets that drove my career.
Opencode did have an adapter to use Anthropic models before they were sent legal threats that scared them into nuking the repo.
Remember is it not OpenAI vs Anthropic as bad guys vs good guys. They are all bad guys trying to profit from your data while maximizing dependency. Just buy or rent GPUs.
In the Stagex Linux distribution it is not possible for any single person to release anything. We require multiple independent review and reproduction signatures from the maintainer team.
We strongly urge other distros to take similar measures. Trusting a single person with effectively remote code execution privileges on every user workstation is never going to end well.
openpgp4fpr:6B61ECD76088748C70590D55E90A401336C8AAA9