frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Future of post-open-source? Considering a "source-visible, non-runnable" license

1•EGreg•3h ago
I've spent the last decade building Qbix, a platform for decentralized social apps, complete with internal economies (QBUX), multi-user apps, and a plugin architecture designed for security, scalability, and sovereign communities. I've also built open source web3 smart contracts. I've contributed more lines to open source than most people on earth.

For those who are curious:

  https://github.com/Qbix
  https://github.com/Intercoin
But now that I'm working on training autonomous AI agents to deeply understand and improve my codebase 24/7, I'm rethinking the entire point of open source in 2025.

So at Qbix we are considering a new direction:

  Source-readable, but not self-hostable. i.e.
  "look but don’t run" — unless you’re a licensed franchisee.
We package our software into QBOXes -- attested, tamper-evident environments with no SSH access, running in trusted clouds (e.g., AWS). The core is installed with nix or Amazon AMIs. Any third-party packages are all version-pinned, and installed only by installer scripts that the box downloads from various endpoints and verifies they've been approved by M of N auditors. The client software only connects to authorized QBOXes. Our clients can choose which auditors to trust.

Why? Security and reliability.

After multiple WordPress sites of ours got pwned — thanks to widely-used plugins — I started seeing the plugin ecosystem itself as a dangerous attack vector. Too much surface area, no containment.

QBOX flips the model: Each plugin can run in its own domain/iframe, like in Sandstorm, using postMessage and a Powerbox-like API. This even protects against speculative execution attacks like Meltdown and Spectre. No plugin can crash or compromise the host app.

We’re also eschewing commodity hosting, which historically introduced more variables and support costs than it was worth. You want to run a QBOX? Great -- license it. You don’t? No worries — the source is open to auditors, not repackagers.

This also avoids what happened with Matt Mullenweg and WordPress forks: open source competitors out-executing the core devs.

In short:

Open source still builds trust, but the AI is my team now.

Contributors can file issues, even in plain English. The agents will handle the rest, including communication with the submitters.

I don't really care as much about GitHub stars, I care about building a reliable platform that people who pass our course can get licensed to run their own QBOXes in cloud environments, for others to use. They're essentially going to be "dumb pipes" and redundant infrastructure, all over the world. And we're going to be building distributed systems far beyond "blockchain" on them, after we get enough critical mass.

Those who don't pass our course, the people who just run a community and want to use the software, will pay those who pass our course and get licensed to run and maintain QBOXes in the cloud (set it and forget it basically).

I am even considering making source code available only to auditors, who can form a Self-Regulatory Organization and add/remove auditors, authorizing their public keys. Then any software that winds up in a customer's QBOX does so because M of N auditors they trusted signed off on it. In this way, they can extend their security boundary from their client apps to our QBOXes running on the server, and they can handle keys, third party APIs (including sending emails with gmail, making payments, etc.)

What do you think? Has anyone else explored auditable, non-runnable open source as a middle ground? Is it sustainable? Dangerous? Would love to hear HN’s take.

My Database Is My Application: Rethinking Webhook Logic with DuckDB and SQL

https://www.hey.earth/posts/duckdb-webhook-gateway
1•chw9e•2m ago•0 comments

Jony Ive's AI gadget might be a pen

https://www.bloomberg.com/opinion/articles/2025-06-30/jony-ive-s-first-ai-gadget-clues-point-to-a-pen
1•theyinwhy•2m ago•0 comments

"Fuck the algorithm"?: What to learn from the UK's A-level grading fiasco (2020)

https://blogs.lse.ac.uk/impactofsocialsciences/2020/08/26/fk-the-algorithm-what-the-world-can-learn-from-the-uks-a-level-grading-fiasco/
1•djoldman•3m ago•0 comments

Senate GOP budget bill has little-noticed provision that could hurt your Wi-Fi

https://arstechnica.com/tech-policy/2025/06/senate-gop-budget-bill-has-little-noticed-provision-that-could-hurt-your-wi-fi/
1•spenvo•4m ago•0 comments

iOS Dev Weekly: Swift Everywhere: Bringing Swift Packages to Android

https://iosdevweekly.com/issues/697/
1•wahnfrieden•4m ago•0 comments

Machine Consciousness Psuedocode

1•cladking•5m ago•0 comments

Nuclear Matters Handbook [pdf]

https://www.acq.osd.mil/ncbdp/nm/NMHB2020rev/docs/NMHB2020rev.pdf
1•handfuloflight•5m ago•0 comments

Ted Chiang on Superintelligence in "The Hampdenshire Wonder"

https://lithub.com/ted-chiang-on-superintelligence-and-its-discontents-in-j-d-beresfords-innovative-work-of-early-20th-century-science-fiction/
1•laacz•6m ago•0 comments

Apple Loses Bid to Dismiss US Smartphone Monopoly Case

https://www.reuters.com/sustainability/boards-policy-regulation/apple-loses-bid-dismiss-us-smartphone-monopoly-case-2025-06-30/
1•jmsflknr•6m ago•0 comments

New band surges to 500k listeners on Spotify, but turns out it's AI slop

https://arstechnica.com/ai/2025/06/half-a-million-spotify-users-are-unknowingly-grooving-to-an-ai-generated-band/
4•Willingham•7m ago•0 comments

Mechanism shrinks when pulled [video]

https://www.youtube.com/watch?v=-QTkPfq7w1A
2•sandebert•7m ago•0 comments

Ukrainians Built a Jammer That Tells Russian Drones They're in Peru

https://daxe.substack.com/p/a-ukrainian-team-built-a-radio-jammer
1•vinnyglennon•8m ago•0 comments

Economic Nihilism

https://www.palladiummag.com/2025/06/30/economic-nihilism/
1•jebarker•8m ago•0 comments

Microsoft AI tool outperforms doctors in diagnosing complex medical cases

https://www.geekwire.com/2025/ai-vs-mds-microsoft-ai-tool-outperforms-doctors-in-diagnosing-complex-medical-cases/
2•JaakkoP•11m ago•0 comments

I still choose no-code vs. vibe code

https://twitter.com/marinatrajk/status/1939774832431780069
3•marince00•12m ago•0 comments

Perplexity Is Doomed

https://medium.com/utopian/perplexity-is-doomed-721abbca1228
3•bentcorner•12m ago•0 comments

How to Opt Out of Your Car's Surveillance State

https://www.carsandhorsepower.com/featured/how-to-opt-out-of-your-car-s-surveillance-state-before-it-s-too-late
2•Anumbia•12m ago•0 comments

Why Don't AI Agents Work (Yet)? [video]

https://www.youtube.com/watch?v=kpOWmwA6tJc
1•ngruhn•12m ago•1 comments

Want to stand out in IT job interviews? a home lab can help

https://www.zdnet.com/home-and-office/want-to-stand-out-in-it-job-interviews-10-ways-a-home-lab-can-help/
2•mooreds•13m ago•0 comments

Space Emerges from Time? Groundbreaking Theory Upends Einstein

https://scitechdaily.com/space-emerges-from-time-groundbreaking-theory-upends-einstein/
2•bookofjoe•13m ago•1 comments

Price of rice in Japan falls below ¥4k per 5 kilograms

https://www.japantimes.co.jp/news/2025/06/24/japan/japan-rice-price-falls-below-4000/
1•PaulHoule•14m ago•0 comments

Japan's Midget Submarine Attack on Pearl Harbor Was a Suicide Mission

https://daxe.substack.com/p/japans-midget-submarine-attack-on
2•vinnyglennon•15m ago•0 comments

Public Signal Backups Testing

https://community.signalusers.org/t/public-signal-backups-testing/69984
1•blendergeek•16m ago•0 comments

The Power of "and": At Bloomberg, Open Source and Corporate Philanthropy

https://www.bloomberg.com/company/stories/the-power-of-and-at-bloomberg-open-source-and-corporate-philanthropy-work-hand-in-hand/
2•pvachon•19m ago•0 comments

Is AI eating your coding skills?

https://jpreagan.com/blog/generative-ai-for-coding/
3•jpreagan•23m ago•0 comments

A simple PWA Hacker News client for desktop

https://hnreader.netlify.app/
3•ClassicOldSong•25m ago•1 comments

Bolivia's Last-Ditch Currency Bet: Spare Change Becomes Crypto Lifeline

https://latinamericanpost.com/economy-en/bolivias-last-ditch-currency-bet-when-spare-change-becomes-crypto-lifeline/
1•dxs•26m ago•0 comments

Show HN: "Computer use" mcp for webapps and Electron apps

https://github.com/snowfort-ai/circuit-mcp
1•clharman•28m ago•0 comments

Building Accurate Address Matching Systems

https://www.robinlinacre.com/address_matching/
1•Bogdanp•29m ago•0 comments

Ring Convolution Networks – Novel neural architecture achieves 90.1% on MNIST

2•bigdatateg1992•29m ago•0 comments