6 ms·
AI-powered open-source code laundering
- ugh123 1y ago> Please DO NOT TURST ANY WORD THEY SAY. They're very good at lingual manipulation. I don't know if this was intentional misspelling or not but it's damn funny
- josfredo 1y agoIt is likely intentional as the author is battling AI with many means possible. However it leans towards funny and hopeless at the same time.
- ebcode 1y agonot hard to believe. I’ve been using claude code and am hesitant to publish publicly because I’m concerned about copyright violations. It would be nice if there were a registry (besides github) where I could compare “new” code against public repositories.
- deleted 1y ago[deleted]
- adastra22 1y agoWhy? That’s not how copyright works.
- CuriouslyC 1y agoSorry to say but this is going to be the new normal, and it's going to be quite difficult to stop. Your moat as a creator is your personal brand and the community you build around your tools.
- o11c 1y agoI just hope that means we're all allowed to feed leaked source code to our own AIs then. This is mandatory if we're to have any sort of coherent legal precedent.
- ares623 1y agoGame crackers can just claim they generated a completely different game using AI that just so happens to look very close to another game?
- CuriouslyC 1y agoThey could copy the core game mechanics and have AI launder the source and generate new art assets. Proving infringement is going to be basically impossible for all but the most trivial of cases.
- ares623 1y agoThe same could be done for movies too I guess. Probably easier. One can setup a site to crowdsource laundering 8-10 second sections of an entire movie and then stitching it back.
- throwaway290 1y agothis is a blatant try to normalize. "Bad people do unethical things, I guess we'll have to live with it and shut up" is the vibe the author is going good. it's not a new normal until everybody goes quiet
- pessimizer 1y ago> this is a blatant try to normalize. This doesn't mean anything. You have no ability to "normalize" anything. It's not an action that somebody can take. > it's not a new normal until everybody goes quiet Real let me speak to your manager energy. Nobody is waiting for you to go quiet to get on with things.
- akoboldfrying 1y ago> You have no ability to "normalize" anything. Normalisation isn't something that one person by themselves can achieve. It only happens when public opinion is swayed. How is it swayed? By people deliberately trying to sway it, like GP here. If you are instead arguing that normalisation is not really a thing at all: What do you call the change in attitudes to people who are left-handed, disabled, or homosexual?
- throwaway290 1y ago> You have no ability to "normalize" anything. You can if you convince everyone to stop making a fuss because it's the new normal. The comment literally said "it's the new normal".
- CuriouslyC 1y agoThis is a very bad faith comment from a throwaway account. Recognition of realities is different from wishing for things to occur. If you think you can stop unethical people from AI washing your software, feel free to try, you will fail.
- throwaway290 1y agoBad faith = trying to normalize bad faith behavior. > If you think you can stop unethical people from AI washing your software, feel free to try, you will fail. Posts like these = trying to stop unethical people from copyright (copyleft) washing. Telling people writing these posts that it's the new normal is basically saying they are doing pointless thing, while they are doing something very good
- userbinator 1y agoHopefully the spread of AI will make more people realise that everything is a derivative work. If it wasn't an AI, it was a human standing on the shoulders of giants.
- CamperBob2 1y agoI'll give you the only upvote you'll probably get for that sentiment around here. Enjoy your trip to -4 (Dead)!
- hu3 1y agoThis. AI is a magnificent way to make the entire world's codebase available as a giant, cross-platform, standard library. I welcome AI to copy my crap if that's going to help anyone in the future.
- alganet 1y agoYou forgot to mention that if things continue as they are, a very small group of people will have complete control over this giant library.
- hu3 1y agoIt's a concern. But there are open source models.
- zdwolfe 1y agoI find it odd that any LLM could be considered open source. Sure the weights are available to download and use, but you can't reasonably reconstruct the output model as it's impractical for an individual to gather a useful dataset or spend $5,000,000+ of GPU time training.
- _ea1k 1y agoDistillation can extract the knowledge from an existing model into a newly trained one. That doesn't solve the cost problem, but costs are steadily coming down.
- deleted 1y ago[deleted]
- dvrp 1y agoThis is the new reality. Information in the form of raw entropy encoded in weights—it doesn’t matter if it’s text, image, video, or 3D. Assets (or formerly known as assets) now belong to the big labs, if it’s on the internet. Internet plus AI implies the tragedy of the commons manifested in the digital world.
- arthurofbabylon 1y agoIf we step back and examine LLMs more broadly (beyond our personal use cases, beyond "economic impact", beyond the underlying computer science) what we are largely looking at is an emerging means of collaboration. I am not an expert computer scientist, and yet I can "collaborate" (I almost feel bad using this term) with expert computer scientists when my LLM helps me design my particular algorithm. I am not an expert on Indonesian surf breaks, yet I tap into an existing knowledge base when I query my LLM while planning the trip. I am very naive about a lot of things and thankfully there are numerous ways to integrate with experts and improve my capacity to engage in whatever I am naive about, LLMs offering the latest ground-breaking method. This is the most appropriate lens through which to assess AI and its impact on open source, intellectual property, and other proprietary assets. Alongside this new form of collaboration comes a restructuring of power. It's not clear to me how our various societies will design this restructuring (so far we are collectively doing nearly nothing) but the restructuring of these power structures is not a technical process; it is cultural and political. Engineers will only offer so much help here. For the most part, it is up to us to collectively orchestrate the new power structure, and I am still seeing very little literature on the topic. If anyone has a reading list, please share!
- visarga 1y ago> what we are largely looking at is an emerging means of collaboration. They surpass open source, "out-open source-opensouce" by learning skills everywhere and opening them up for anyone who needs them later.
- goku12 1y agoIt's owned by a few rich corporations and individuals. It isn't available to anyone - only to those they choose and are ready to pay them. And it isn't open source at all, because open source is not reuse without any obligations (even under permissive licenses). And let's not forget that they 'open' only FOSS works and individual works. They never expose proprietary IP belonging to rich corporations. It isn't an emerging method of collaboration - it's another method for wealth consolidation.
- 1y ago
- foxylad 1y agoThis will kill open source. Anything of value will be derived and re-derived and re-re-derived by bad players until no-one knows which package or library to trust. The fatal flaw of the open internet is that bad players can exploit with impunity. It happened with email, it happened with websites, it happened with search, and now it's happening with code. Greedy people spoil good things.
- awesome_dude 1y agoIf this was true, why hasn't it happened for the last... 30 or 40 years that FOSS code has been published on the internet
- ares623 1y agoLast i checked LLMs didn’t exist until only a few years ago
- makeitdouble 1y agoCopyright was the base protection layer. Not in the "I own it" sense, but in the "you can't take it and run with it" sense. With the current weakening of it, it opens the door to abuses that we don't have the proper tools to deal with now. Perhaps new ones will emerge, but we'll have to see.
- croes 1y agoSame reason why fake images and videos are now more. Photoshop existed 30 years ago. Before LLM you needed time and abilities to do it, with AI you need less of both.
- trod1234 1y agoUntil now, people have had the leverage/cost asymmetry in their favor where they could easily differentiate and make rational choices. AI has tipped that nuanced balance in a way that is both destructive, and unsustainable. Just like any other fraud or ponzi. Cost/loss constraint function now favors the unskilled, blind, destructive individual running an LLM who spits on all those that act with good faith. Quite twisted.
- cientifico 1y agoThe license was MIT until two months ago. That gives anyone the right to get the source code of that commit and do whatever. The article does not specified if the company is still using the code AFTER the license change. The rest of the points are still valid.
- Leynos 1y agoMIT places the following condition on the licencee if they wish to re-distribute the code: > The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. Which the other party was not doing.
- nasusnavas 1y agoI looked at their codebase and it seems the other party was doing. I'm seeing a pattern here where either this is not really a copyright problem but possibly a marketing stunt if its not, then it may well be an emotional spiral or lash-out for one person extending another's open source logic even with attribution clearly given. If so then this is not healthy for the open-source community. Also is it legal to start with MIT and change to Apache midway? The laws around opensource licensing are so tricky and cutthroat at this point. Also does anyone know what this Intentional License is from the other party, I have never seen it before. It seems that's what their main package is while the other packages are Apache. If its custom is it even legal to just create a new OSS License out of nothing? There's too much gray area with OSS especially when it comes to legalities we almost need a standard.
- ClassicOldSong 1y agoI'm the victim and yes, this is not entirelly about AI. If you have read the hall of shame, you'll know that they tends to lie. If it was only someone tried to use my code as their basis and forgot to include the attribution, after my notice they added, it's totally not worth a "hall of shame", and I'm actually glad that someone finally appreciates my works and make them useful. But the reality is, they lied to everyone and I'm a chained victim. I was introduced to him by NativeScript, and before that he didn't even know the existence of rEFui. Now rEFui has become the most important fundament of their entire project, clearly indicates that they want to get something for nothing from the very beginning. Till now they still didn't answer me why they made the basic mistakes and how it was fixed.They avoid everything I ask about them unless I presure them very hard, they'll give a very vage respond that answers nothing. > is it legal to start with MIT and change to Apache midway? As the author of the project, I have every right to change the license to anything. But also, I didn't wash the history to hide that the project was MIT. Technically I can, but that actually violates MIT itself and I don't want to be someone that say one thing and do another. > even with attribution clearly given They won't until I presured them very hard. They also washed much more than my projects, but also without attribution until I notified those project's authors. Actually, till now the code are still not fully attributed, only few get a proper attribution. They have now extracted code blocks from my original project into many many small separated files (potentially trying to hide the origin even further), but the code logic are actually not changed at all. According to those license, each piece of code they extract should keep an attribution to my original project. I have a backup of the deleted project that contains the entire commit history of how he laundered these projects, and I can provide the entire Discord message history if you need evidence of all my statements.
- laurex 1y agoI’m interested in a new kind of license which I’m calling “relational source” - not about money or whether a product is commercial but instead if there’s an actual person who wants to use the code with some kind of AGPL-esque mechanism to ensure no mindless ingestion- perhaps this would never work but it’s also breaking the spirit of everything I love about OSS to have AI erasing the contributions of the people who put their time into doing the work.
- haebom 1y agoWouldn't “Pretending It's Mine” be a better name for the project?
- pjfin123 1y agoIs the allegation here that a LLM generated code that was very similar to the author's copyright protected code or that they copied the code and then tried to use AI to hide that fact?
- Leynos 1y agoThe allegation is that the party in question copied the author's code verbatim and stripped off the copyright / licence notices.
- nasusnavas 1y ago[dead]
- selinkocalar 1y agoWe've seen cases where AI-generated code includes snippets that look suspiciously like they came from proprietary codebases. If an AI model was trained on copyrighted code and reproduces patterns from it, who's liable? The training process makes it really hard to trace back to original sources.
- lschueller 11mo agoI'm afraid we will see much more of this in the near future. Good to see, when someone starts documenting such behavior