Sign in

pchestek

@pchestek.fosstodon.org.ap.brid.gy
51 followers 1 following 236 posts

In private practice. North Carolina Certified Specialist in Trademark Law, Former board member of OSI. Opinions are my own. #Fedora #BeefyMiracle 🌉 bridged from ⁂ fosstodon.org/@pchestek, follow @ap.brid.gy to interact

PostsRepliesMedia
pchestek @pchestek.fosstodon.org.ap.brid.gy · 15/09/2026
Why does Firefox think that Fosstodon should go in a "Shopping" container?
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 15/09/2026
The thing I will be most happy about with the collapse of the AI bubble is all of the landscape I will regain on my vendor platforms interfaces when they don't push their AI solution (to problems I don't have) at the top of the page, obscuring the features I actually need and use
001
Reposted by pchestek
tante @tante.tldr.nettime.org.ap.brid.gy · 09/09/2026
Oh, did not expect that: The Automattic Board put Mullenweg on leave of absence. www.404media.co/wordpress-automatti…
2111
Reposted by pchestek
Simon Phipps @meshed.cloud · 06/09/2026
The world of #OpenSource and #FreeSoftware is divided between those who see #licences as giving protection from exploiters and those that see them as giving freedom to collaborators and users.
121
pchestek @pchestek.fosstodon.org.ap.brid.gy · 04/09/2026
Looking for scholarly articles or books that discuss decision-making in writing software code. I'm hoping to make an argument that it (almost) always involves developers making choices #coding #software #creativity
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 04/09/2026
@purpleidea can you shoot me an email? Pamela@chesteklegal.com. Let me know what you've sent to them.
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 04/09/2026
@purpleidea can you shoot me an email? Pamela@chesteklegal.com. Let me know what you've sent to them.
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 02/09/2026
Remarkable reversal from the Copyright Office, which in its AI preprint endorsed the "market dilution" theory of copyright infringement, adopted in Kadrey. Now, "the Kadrey court’s application of the fourth fair-use factor is deeply flawed." #Copyright […]
fosstodon.org
Original post on fosstodon.org
100
pchestek @pchestek.fosstodon.org.ap.brid.gy · 01/09/2026
Being entertained by pretending to opposing counsel that there was strategic thought put into the drafting of a legal document, when I'm fairly certain it was just AI-generated
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 31/08/2026
The First Amendment Problems With Meta’s $17 Billion Deal www.lawfaremedia.org/article/the-fi…
lawfaremedia.org
The First Amendment Problems With Meta’s $17 Billion Deal
Meta's settlement includes some social media speech restrictions that states can't directly impose.
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 28/08/2026
"The government is certainly owed deference on weighty issues of national security. But Defendants’ contemporaneous words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government, not based on […]
fosstodon.org
Original post on fosstodon.org
110
pchestek @pchestek.fosstodon.org.ap.brid.gy · 25/08/2026
💔💔💔 #RIP, you were a rare gift, one we will never see again in a lifetime of lifetimes
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 22/08/2026
There's an important conversation going on about a proposal for an open source license for AI systems - background here lwn.net/SubscriberLink/1089251/fe6e… (free link) This is an important conversation with some significant policy questions join in #OpenSource #OpenAI
lwn.net
Considering the OpenMDW license
The open-source world has been struggling for a few years now to understand how to approach lar [...]
154
pchestek @pchestek.fosstodon.org.ap.brid.gy · 18/08/2026
Seen in the wild #trademark #JackDaniels #dilution
010
pchestek @pchestek.fosstodon.org.ap.brid.gy · 27/07/2026
The Dawn theme is not open source, it has a license that restricts use to themes that integrate or interoperate with Shopify software or services. github.com/Shopify/dawn/blob/main/L…
github.com
dawn/LICENSE.md at main · Shopify/dawn
Shopify's first source available reference theme, with Online Store 2.0 features and performance built-in. - Shopify/dawn
010
pchestek @pchestek.fosstodon.org.ap.brid.gy · 27/07/2026
I missed this one: Shopify and Shopline settle a copyright infringement lawsuit. www.linkedin.com/news/story/shopify…
linkedin.com
Shopify settles copyright lawsuit against rival platform | LinkedIn
Shopify alleged that rival e-commerce platform Shopline duplicated its Dawn storefront technology and rebranded it as Seed.
100
pchestek @pchestek.fosstodon.org.ap.brid.gy · 27/07/2026
Hmmm.
Screenshot from a BestBuy page for a computer:
Questions & Answers
Does this nudity have any warranty?
This unit includes a one year parts and
labor warranty.
Answered 3 months ago by Joy Systems
001
pchestek @pchestek.fosstodon.org.ap.brid.gy · 25/07/2026
The AI industry singing an old song - open is better www.tomshardware.com/tech-industry/… #OpenSource #OpenSourceAI
tomshardware.com
Nvidia and 24 other companies sign open-weights letter as Washington weighs Chinese AI model ban — OpenAI, Anthropic, and Google absent from the list
Signatories include chipmakers, server vendors, cloud operators, enterprise software firms, security companies, and venture funds
030
Reposted by pchestek
Quixoticgeek @quixoticgeek.v.st.ap.brid.gy · 22/07/2026
Reminder, social media bans for kids are nothing to do with protecting kids, and everything to do with removing anonymity from the web.
01251
Reposted by pchestek
Niki @nikitonsky.mastodon.online.ap.brid.gy · 21/07/2026
You are absolutely right! I should not have injured a human being or, through inaction, allowed a human being to come to harm!
31384
pchestek @pchestek.fosstodon.org.ap.brid.gy · 16/07/2026
"Open" is a term of art in software: "That public may understand the term ‘OPENAI’ as meaning either accessible or unrestricted artificial intelligence, based on open source principles, or even one that is transparent or explainable." Registration denied as descriptive and devoid of distinctive […]
fosstodon.org
Original post on fosstodon.org
020
Reposted by pchestek
Jordan Maris 🇪🇺 🇺🇦 #NAFO @jmaris.me · 12/07/2026
RE: mstdn.social/@hkrn/1169085691294130… The only reason governments would want to ban #OpenSource and #OpenWeight #AI is to ensure OpenAI and Anthropic retain a duopoly.
mstdn.social
042
Reposted by pchestek
Dan Piponi @dpiponi.mathstodon.xyz.ap.brid.gy · 11/07/2026
Profound words from the manual
1152
pchestek @pchestek.fosstodon.org.ap.brid.gy · 01/07/2026
I'm so over Android, it keeps changing behavior. Latest? It now dims out even while actively using it. There's a setting now that to keep it active it has to watch you on the camera (I guess touching the screen isn't good enough). No thanks. #Spyware
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 28/06/2026
Google liable for defamation in Germany for false AI summaries #AI #Google #defamation ipkitten.blogspot.com/2026/06/ai-ge…
ipkitten.blogspot.com
AI-generated search summaries and personality rights: Munich court grants preliminary injunction against Google
The IPKat blog reports on copyright, patent, trade mark, info-tech and confidentiality issues from a mainly UK and European perspective.
000
Reposted by pchestek
Vee @veroniqueb99.mastodon.social.ap.brid.gy · 26/06/2026
Several bars and restaurants have brought their best minds and resources together to introduce a new high end cocktail to the world. The Reflecting Pool
16918
Reposted by pchestek
Doctor M. Popular @docpop.mastodon.social.ap.brid.gy · 16/06/2026
Gavin Snider had only been a full-time artist for about 10 months when the Knicks hired him to create a piece ahead of the 2026 NBA Finals. Shortly after the Knicks shared Gavin's watercolor, Devon Rodriguez posted an oil painting with a similar composition... right down to the jersey numbers.
A watercolor painting by Gavin Snider that shows a large crowd in Madison Square celebrating the Knicks. The art is stylish with a focus on red and blue colors. The characters are slightly cartoony, showing joy in their faces and wearing Knicks gear. A, oil painting by Devon Rodriguez that shows a large crowd in Madison Square celebrating the Knicks. The composition of this painting is nearly identical to the one by Gavin Snyder. The buildings are the same, the signs on the buildings are the same, there are other similarities like a Knicks flag and a large foam finger glove that are in the same places. Even the numbers on the jerseys are the same.
146
Reposted by pchestek
pchestek @pchestek.fosstodon.org.ap.brid.gy · 23/06/2026
Note that the law currently exists (see section 22757.3(c)(1), leginfo.legislature.ca.gov/faces/bi…), these companies are trying to get the law fixed #AI #OpenSource #OSI
leginfo.legislature.ca.gov
Bill Text - SB-942 California AI Transparency Act.
SB 942 California AI Transparency Act.
131
Reposted by pchestek
pchestek @pchestek.fosstodon.org.ap.brid.gy · 23/06/2026
CA law prohibits use of open source licenses for AI github.blog/news-insights/policy-ne… #AI #OpenSource #OSI
github.blog
132
pchestek @pchestek.fosstodon.org.ap.brid.gy · 23/06/2026
CA law prohibits use of open source licenses for AI github.blog/news-insights/policy-ne… #AI #OpenSource #OSI
github.blog
132
pchestek @pchestek.fosstodon.org.ap.brid.gy · 22/06/2026
Polymarket uses typo domain to trick consumers domainnamewire.com/2026/06/22/polym…
domainnamewire.com
Polymarket uses typo domain to trick consumers - Domain Name Wire | Domain Name News
Betting platform created fake site to help influencers fake wins on its real site. The Wall Street Journal published a report this weekend about how the betting platform Polymarket hired influencers to fabricate wins on its platform. The story kicks off with this antedote: In his videos, George Makihara appears to have a lucrative side […]
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 19/06/2026
Funny content warning. I guess it's interpreted as her middle finger? From: @DorotheaLange mastodon.ozioso.online/@DorotheaLan…
mastodon.ozioso.online
Dorothea Lange (@DorotheaLange@mastodon.ozioso.online)
Attached: 1 image · Content warning: This content might contain sensitive material that may be distressing or triggering to some readers.
100
pchestek @pchestek.fosstodon.org.ap.brid.gy · 07/06/2026
When Can Amazon Block an Agentic AI Service?–Amazon v. Perplexity (Guest Blog Post) blog.ericgoldman.org/archives/2026/…
blog.ericgoldman.org
When Can Amazon Block an Agentic AI Service?–Amazon v. Perplexity (Guest Blog Post)
by guest blogger Kieran McCarthy On March 9, 2026, Judge Chesney granted a preliminary injunction in the case of _Amazon v. Perplexity_, concluding Amazon was likely to succeed on its CFAA and California Penal Code section 502 theories. If you’re familiar with the CFAA, the outcome of the preliminary injunction opinion was what you might expect. But it is underwhelming in some new and interesting ways. It is, in my opinion, a shockingly poor effort to grapple with CFAA applicability to agentic AI technology after _Van Buren_. If you’re unfamiliar, agentic AI is simply the name for AI that actually does work for you instead of answering questions. An agent can take a loose goal, break it into steps, use tools, gather information, make decisions, and come back with the task done. That makes it useful for the work people hate but still need judgment to finish, such as research, product comparisons, customer support, and multi-step coordination. One valuable use case for agentic AI is shopping. Not only can Agentic AI tell you what the highest rated toaster on Amazon is for under $100, it can actually buy it for you. You can tell agentic AI: _Buy a toaster on Amazon for under $100. Prioritize name brands, Amazon Prime shipping, and wide slots for bagels. Do not buy based solely on Amazon rating. Consider only models with at least 1,000 reviews, a rating of 4.7 or higher, and no obvious fake-review pattern. Cross-check at least two independent review sources or testing sites for confirmation that the quality is among the best at this price point. Choose a 2-slice toaster unless a 4-slice model is clearly better._ _If one option is clearly superior under these criteria, add it to my cart and proceed to purchase. If not, add the best by these measures and I will review and purchase._ The thing about instructions like these is that they totally kill many of the ways online e-commerce sites make money. Amazon doesn’t just make money from selling you stuff and sending it to you. They also make money from product placement, ads, upselling, and a million other ways of nudging you into buying more stuff. Amazon wants their search bar to be the way that you buy things online. But if the interface for your shopping becomes the AI labs’ platforms, that’s a big deal for e-commerce sites. It’s an existential threat to some e-commerce platforms and a major margins headwind for giants like Amazon and Walmart. Those are the stakes. * * * The injunction in this case arose from Amazon’s challenge to Perplexity’s Comet browser and shopping agent. Perplexity built a tool that allows software to shop for users on Amazon through their logged-in accounts. Amazon sent a cease-and-desist letter. But Comet didn’t stop. Created by ChatGPT Dec. 2025 The court focused on a familiar question for CFAA folks, which is that Amazon allegedly revoked authorization, Perplexity’s agents continued accessing Amazon’s systems through user accounts, and therefore Amazon was likely to succeed under theories derived from CFAA and California computer-access law. From a pure CFAA perspective, the allegations were straightforward. Monopolist platform discovers a kind of automation that people who use the Internet enjoy, labels it “unauthorized,” cites to _Power Ventures_ , points to investigative costs, and gets its injunction. It has happened before and it will happen again. But the genuinely novel issue was totally ignored in the opinion. Perplexity’s Comet is an AI agent. And agentic AI is not merely collecting data. It is acting as the user’s delegated representative in an ongoing workflow. The opinion makes zero effort to analyze: * whether an AI agent should be treated like a browser, * whether it should be treated like a human assistant using delegated credentials, * whether agency-law concepts matter, * whether user autonomy creates an independent authorization interest distinct from _Power Ventures_ , * whether there is a meaningful distinction between scraping data and performing user-directed actions. Instead, the court seems to jump directly to the conclusion that Amazon retains ultimate authority to exclude the intermediary. (In partial defense of the court, they hint that they may have discussed this at oral arguments. But there’s no analysis of agentic AI in the opinion itself). From an agentic-AI perspective, it’s straightforward to ask: **If I can personally log into Amazon and buy a toaster, why can’t I save time and have software do it for me?** **Because _Power Ventures_ is dumb and Amazon says so, that’s why. ** The _Power Ventures_ framing has always allowed platforms to control their platforms, even when the user wants a certain tool to interact with them, if the integration includes a logged-in component. If there is a password at any part of the flow, most courts find that the CFAA can be used to crush any unwanted integration, no matter how benign or socially useful it is. Log-in plus cease-and-desist has almost always been a CFAA violation. That’s why _Power Ventures_ matters so much. If _Power Ventures_ controls, Amazon gets to frame Comet as just another unwanted logged-in integration. If it doesn’t, the case becomes about whether users can delegate ordinary account activity to software. That is also what makes this such an interesting test case for _Power Ventures_. Amazon wants to put Comet in the _Power Ventures_ box, and legally, that is exactly where a plaintiff wants to be. But the factual analogy is imperfect. Power Ventures was not merely helping users operate Facebook. It built a competing service, collected Facebook users’ information, imported that information into its own platform, and used users’ networks to market itself. Comet’s better factual description is simpler, because the user is still shopping. The user just has delegated parts of the shopping flow to software. If _Power Ventures_ means that a platform can veto any third-party agent, then the CFAA becomes a platform-control statute for the agentic web. Maybe that is where the Ninth Circuit ultimately lands. But if that’s the case, the CFAA is going to be an increasingly unpopular law. What’s especially disappointing is that courts continue to pretend that there are not difficult policy questions to consider with these new technologies. It is particularly true in this case, because it was a preliminary injunction proceeding, and the court was _required_ to consider the broader public interest question. Perplexity argued that an injunction would disserve the public interest in consumer choice and innovation. The court’s response was as thin and fragile as overcooked spaghetti. It said that the public has an interest in preventing unauthorized access to computers, and that was that. The platform says it’s not allowed, therefore it’s not allowed, and it’s in the public’s interest for it not to be allowed. See how easily we resolved issues with agentic AI? Reasoning like this makes the CFAA one giant circle of enforcing platform preferences. To be clear, there’s an argument for Amazon’s position, too. Platforms have real interests in account security, fraud prevention, bot detection, and knowing whether an automated system is moving through logged-in user accounts. But that’s only a small part of the story. The anti-competitive implications here are super-obvious. Perplexity’s stated theory of the case is that Amazon does not like a user tool that routes around Amazon’s preferred shopping and advertising experience. AI agents “don’t have eyeballs” for the ads Amazon “bombards” users with. Even if you think that line is a bit cute, the underlying point is real. Intermediaries often threaten incumbents precisely because they reduce friction, reorder presentation, or weaken monetization levers the incumbent would rather preserve. Search engines did that. Price-comparison tools do that. Browser extensions do that. API clients and integrations do that. AI agents will absolutely do that in a way that the platforms are not yet prepared to deal with. Stated plainly, the public interest section just isn’t serious here. A court need not become an antitrust tribunal every time someone says “innovation” or “consumer choice.” But this fact pattern is different from the fact pattern in _Power Ventures_. A court has a duty to at least think about that. — The other interesting part of this case is it’s another test of the definition of technological harm after _Van Buren_. Knowing that the _Power Ventures_ question was always going to be a tough climb, _Perplexity_ also asked some of the other tough CFAA questions that _Van Buren_ didn’t bother to answer. The order recognizes that _Van Buren_ at least raises a question about whether “loss” should be limited to technological harms, and it notes the Ninth Circuit’s comment in _hiQ_ about _Van Buren_ requiring such harms. Then it basically shrugs and says, in substance, “this is going to be resolved in Amazon’s favor,” without any explanation or analysis of whether that’s the correct outcome. To me, the technological harm question would be the easiest way to separate _Power Ventures_ from benign or socially useful integrations. A few courts have agreed, but many do not. And whether I like it or not, the Section 502 piece of the opinion is even more “chalk” than the CFAA ruling. California cases have long treated response and investigatory expenses as cognizable losses under Section 502. This also dates back to _Power Ventures_ and beyond. So if defendants already face an uphill fight arguing that CFAA investigative costs must be tethered to technological harm notwithstanding _Van Buren_ ’s “technological harms” language, that argument is harder still under Section 502, where _Van Buren_ is not controlling and the California text is friendlier to verification costs. Regardless, it is hard to imagine that _Power Ventures_ will survive agentic AI forever. Sooner or later, courts will be forced to acknowledge that people should be allowed to delegate to software tasks that they are legally allowed to do themselves, especially as software gets better and better at doing those tasks. But for now, _Power Ventures_ stays intact. Until courts grapple with the power with what agentic AI actually does, the CFAA will remain what large platforms want it to be. Not just a law against hacking, but a legal cudgel against unwanted interoperability or user preferences. The real task is for courts to acknowledge that platforms don’t need unchecked authority to kill all forms of automation on their platforms, but should instead distinguish malicious automation from disclosed, user-directed software that functions as the user’s chosen interface. I think we’ll get there eventually, but this opinion makes me think it’ll be some time before we do. Share this: * Click to email a link to a friend (Opens in new window) Email * Click to print (Opens in new window) Print * Click to share on Facebook (Opens in new window) Facebook * Click to share on LinkedIn (Opens in new window) LinkedIn * Click to share on X (Opens in new window) X * Click to share on Tumblr (Opens in new window) Tumblr * Click to share on Pinterest (Opens in new window) Pinterest * Click to share on Pocket (Opens in new window) Pocket * Click to share on Reddit (Opens in new window) Reddit *
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 07/06/2026
AI company sues the plaintiffs for breach of the AI company's terms of use […]
fosstodon.org
Original post on fosstodon.org
000
Reposted by pchestek
Ali Atmaca @aliatmaca.bsky.social · 06/06/2026
Go ahead, doomscroll past. You know you can't. #photography #streetphotography #blackandwhite #bnw #bnwmacro #monochrome #classicmono #macro #urban #travel #art #cat #cats #catpics #catsofbluesky #blueskycats #tabby #catsky #caturday #artyear #eck
A fluffy tabby cat lies down on a textured concrete wall. The cat has distinct dark stripes on its fur, prominent whiskers, and tufted ears; it looks directly toward the camera with a narrow, slightly grumpy, and sleepy gaze. In the background, a wire mesh fence is visible, with some vines woven near the top right. You may not understand why I'm gazing in my sleep, but it's the will of your planet. Give up your job and become a cat... while you can. e6ec033d-ace8-4f26-8703-42607e4af2dd
1266
Reposted by pchestek
David Penfold :verified: @davep.infosec.exchange.ap.brid.gy · 06/06/2026
John Finnemore on the French horn/cor anglais: "I was idly wondering why the cor anglais has a French name meaning ‘English horn’, and the French horn has an English name meaning… well, ‘French horn’. I looked it up, even though I knew there would just be some reasonable but rather dull […]
infosec.exchange
Original post on infosec.exchange
1327228
pchestek @pchestek.fosstodon.org.ap.brid.gy · 06/06/2026
@openvibe why does my Bsky feed disappear? There are messages on the Bsky app and OpenVibe has the link. Its a consistent problem, along with not telling me when the Bsky link is broken
000
Reposted by pchestek
Gabriele Svelto @gabrielesvelto.mas.to.ap.brid.gy · 05/06/2026
The idea of banning minors from using social media is at its heart an attempt to punish victims instead of going against the perpetrator. If minors are more easily victimized by the predatory practices of large tech corporations it's not their fault. The blame lies squarely on the corporations […]
mas.to
Original post on mas.to
232101
pchestek @pchestek.fosstodon.org.ap.brid.gy · 03/06/2026
Yeah, this is why you dont allow employees to register domain names - Cybersecurity company says former employee is holding domain name hostage domainnamewire.com/2026/06/03/cyber…
domainnamewire.com
Cybersecurity company says former employee is holding domain name hostage - Domain Name Wire | Domain Name News
San Francisco startup alleges terminated employee won’t give it access to its domain name. System Two Security, a San Francisco-based cybersecurity company that raised a $7 million seed round in 2024, is suing (pdf) a former employee who it alleges is holding the company’s domain name hostage. The company used the domain name detections.ai for […]
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 03/06/2026
Honest question - why is AI taking all the blame for the Insta hack? Isn't the problem with Insta for having such an insecure system? What did AI do that a human couldn't have done in a trivially easy way? Crossposted with @openvibe
110
pchestek @pchestek.fosstodon.org.ap.brid.gy · 01/06/2026
Open Source Initiative brings its expertise on openness in AI to the G7 opensource.org/blog/open-source-ini… #AI #OSI #OSAID
opensource.org
Open Source Initiative Helps G7 Deliver Vision On AI Openness
June 1, 2026 * News * Jordan Maris # Open Source Initiative Helps G7 Deliver Vision On AI Openness _On May 29, 2026 in Paris, G7 Digital and Technology ministers approved a “Vision on AI openness opportunities and shared language”. The vision, which sets out terminology around AI openness, is the result of a three-month partnership between the OSI and the G7._ OSI Executive Director, Duane O’Brien (pictured on the monitor), presents a summary of the work done to the G7 Ministers, while highlighting the benefits of Open Source AI and the need for continued collaboration to ensure clarity. The Vision, which comes under the French Presidency of the G7, highlights the vital role of the Open Source community in building and defining AI Openness. Additionally, it recognizes the challenges in understanding Openness and Open Source in the context of AI, as well as the elements that determine openness, and it calls for the use of clear and appropriate labels that accurately describe the degree of openness of AI systems. To this end, the Vision sets out clear criteria for AI model openness: labeling models with proprietary licensing as “ _Weights Available_ ”, while labeling models which are distributed under an Open Source license as “ _Open Weights”._ When it comes to Open Source AI, the criteria broadly follow those of the OSI’s Open Source AI definition (OSAID), however restrict exceptions to publishing training data to cases of legal or technical impossibility, and only require data information in absence of training data. Finally, the Vision adds criteria for “Open Source AI with Open Data” to describe AI systems where _all_ assets are released free of charge under an Open Source license – including its models’ weights, deployment code, training code, and full training data. As a knowledge partner in the process, the OSI sought to bring the voices of Open Source communities to the G7, making use of the expertise and experience gained in work on the OSAID, including the feedback received from Open Source communities about the definition. Over the course of three months, OSI staff helped draft the Vision and participated in online negotiations and in-person negotiations in Paris, providing clarity on the varying levels of openness in different AI models. OSI Executive Director Duane O’Brien welcomed the development, saying: > “ _The G7 Vision on AI Openness is the first such document to be written with this level of direct engagement between Government and representatives of the Open Source community. We believe it will contribute to creating certainty about Open Source AI, and are grateful to the French Presidency of the G7 for their inclusive approach, trust and support throughout this process.”_ In the G7 Ministerial Declaration on Digital & Technology, ministers also highlighted the role of the OSI in the process, welcoming “ _the valuable contribution of the Open Source Initiative, as well as other members of the community, in supporting the development of this document_.” Following the adoption of the Ministerial Declaration and shared vision at a meeting of G7 Digital and Technology Ministers in Paris, OSI Executive Director Duane O’Brien presented a summary of the work done to the attending Ministers, while highlighting the benefits of Open Source AI and the need for continued collaboration to ensure clarity: > _“Open Source transformed the global software industry. It enabled us to collaborate quickly and effectively to develop shared solutions for common problems. This transformation only worked because when we came together to collaborate, we had a shared understanding of what Open Source means. As we evolve our understanding of Open Source AI, it is vital that we continue to work from a similar shared understanding. We hope to continue to work closely with G7 countries on this important issue, and we stand ready to be your knowledge partners in the years to come.”_ As Open Source is increasingly in geopolitical focus, the Open Source Initiative continues to defend the interests of Open Source communities globally. Your membership and donations make our work possible! Click here to donate or to join the OSI.
001
pchestek @pchestek.fosstodon.org.ap.brid.gy · 28/05/2026
I hope if you're starting a car you don't need a diagram of where the clutch is ...
010
Reposted by pchestek
Cathy Gellis @cathygellis.mastodon.cloud.ap.brid.gy · 27/05/2026
I spent the weekend deciding who to vote for in the CA primary - there's many offices on the ballot, not just gov! I got really frustrated with how the top-two primary system was forcing me to vote, for who could win rather than who I want. So I wrote about how we really need ranked choice […]
mastodon.cloud
Original post on mastodon.cloud
002
pchestek @pchestek.fosstodon.org.ap.brid.gy · 15/05/2026
Is there a more insane way to do credit card expiration date? This is from the website for the American Intellectual Property Law Association and is about the worst website I've ever seen
A screenshot of a portion of an online payment screen where the expiration date is a dropdown with each line in the format YYYY/MM, rather than separate dropdowns for year and month
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 04/05/2026
I thought this was "Order in motion to rest" and thought the courts were being so kindly compassionate (or it was a burn) From: @ai_cases mastodon.social/@ai_cases/116517870…
mastodon.social
AI Cases Bot (@ai_cases@mastodon.social)
New filing: "Kogon v. Google (Putative class of musicians sue Google over music-generating models)" Doc #18: Order on motion to reset PDF: https://www.courtlistener.com/docket/72377338/18/kogon-v-google-llc/?redirect_or_modal=True Docket: https://www.courtlistener.com/docket/72377338/kogon-v-google-llc/?order_by=desc #CL72377338
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 30/04/2026
How not to handle AI www.plagiarismtoday.com/2026/04/29/… #Pinterest
plagiarismtoday.com
Pinterest: How NOT to Handle AI
When it comes to AI, no site has been immune to the challenges it presents. However, none have messed up nearly as badly or consistently as Pinterest.
001
pchestek @pchestek.fosstodon.org.ap.brid.gy · 29/04/2026
Matt Mullenweg may have deleted evidence www.courtlistener.com/docket/692211… #WordPress #Automattic #WPEngine #trademark
000
pchestek @pchestek.fosstodon.org.ap.brid.gy · 18/04/2026
open.substack.com/pub/chkbal/p/an-o…
chkbal.substack.com
An Open Letter to FCC Chairman Brendan Carr
An unsolicited plea for dignity, from a former FCC Chief Counsel.
000
Reposted by pchestek
Matthias Kirschner @kirschner.mastodon.social.ap.brid.gy · 17/04/2026
Proud of my @fsfe co-workers who did a great job organising our Legal and Licensing Workshop so people from all around the world involved in legal topics around #FreeSoftware #OpenSource have a safe space for knowledge exchange 👏 […] [Original post on mastodon.social]
nine people in front of a stage
002
pchestek @pchestek.fosstodon.org.ap.brid.gy · 17/04/2026
What to make of the threats from AI that jeopardize software that we all rely upon? blog.oppedahl.com/what-to-make-of-t…
blog.oppedahl.com
What to make of the threats from AI that jeopardize software that we all rely upon?
Recent news articles talk about instances where Anthropic’s _Mythos_ AI is said to have found software flaws in pieces of software that have been around for a long time. The pieces of software in which _Mythos_ has been said to have found flaws were each from the open-source community. What should we, as readers and users of software, make of this? What should we do differently? Should we avoid open-source software? In this blog article I offer my thoughts. I do think there are things that we, as readers and users of software, should do and not do. But avoiding open-source software is not among them. The writers of the articles try to help the reader appreciate the risks we all face because _Mythos_ attacks software that we all rely upon and finds bugs in it. A separate issue, not the focus of the articles, is the question of open-source versus proprietary (closed-source) software. One could pick any particular type or category of software and identify an open-source solution in that category and a closed-source (proprietary) solution. Here are a few examples: * * The software that people choose to do their email stuff. The email client. Open-source is Thunderbird, closed-source is Microsoft Outlook. * The software that people choose to run the data router in their house. Open-source is OpenWRT or Tomato or pfSense, closed-source is whatever is inside Verizon’s FIOS router or your Linksys or TP-Link or Asus or Eero or Netgear. * The software that people choose for the hardware wallet they entrust their bitcoin to. Open-source is Trezor, closed-source is Tangem or Ledger. * The software that people choose to host their web site. Open-source is WordPress, closed-source is Squarespace. * Messaging. Open-source is Signal and RCS text messaging if it is end-to-end encrypted (with the little padlock). Closed-source is SMS text messaging generally, Facebook messaging, iMessage, WeChat, WhatsApp. * Social media. Open-source is Bluesky and Mastodon. Closed-source is X, TikTok, Instagram. * Word processor. Open-source is Libre Office, closed-source is Microsoft Office. * The software that people choose for their smart phone. Open-source is Android, closed-source is Apple. * The software that people choose for their VPN. Open-source is Wireguard, closed-source is almost all of the others. * Software for image editing. Open-source is Gimp, closed-source is Photoshop. It is pretty much a settled observation is that no matter what category you pick, the closed-source one has more defects and security flaws in it than the open-source one. The closed-source one was written by some team of programmers who inevitably made whatever mistakes they made (always a nonzero number of mistakes). The company employing the programmers keeps the source code secret. The software has some number of security flaws, some of which are eventually discovered by members of the public. In contrast the open-source one is “out there” for anyone to inspect. Many bugs get found and fixed, and it is a quiet process that draws little attention. Yes, the articles talk about two instances of situations where _Mythos_ supposedly found some software flaw that the public inspection did not find. Meanwhile whatever the closed-source equivalent is, it has many more bugs in it. _Mythos_ will eventually find those bugs as well, and there are more bugs to find. Also not directly addressed in the articles is the problem of backdoors. History is filled with situations where the vendor of some closed-source product succumbed to pressure from a government to design a backdoor into the software of that product. Or where the vendor of some closed-source product succumbed to pressure from a government to hold back from using the best encryption algorithm available, instead using a weaker one that the government is able to decode. A government will make use of the backdoor or the weaker encryption to eavesdrop on whatever is going on. Inevitably the backdoor or intentional weakness is also eventually found by other governments or by a bad person that is not a government. But when a system is open-source, it would get found out if a backdoor had been designed into the product. it would get found out if a weaker encryption had been used instead of the best one. Also not directly addressed in the article is the problem of the vendor making use of inside access to whatever is going on. Facebook, X, Instagram all spy on everything the users do. If Bluesky or Mastodon were to do this, everybody would know. With a closed-source product, one line of attack that has been around for decades is for human beings to reverse-engineer the executable code that is in the closed-source product, and can work back in the direction of the source code. The humans can then find bugs and security flaws. See for example _Inside the Model 100_. As part of writing that book, I reverse-engineered the entirety of the closed-source software in the Model 100 computer. One of the Appendices in that book is a complete set of comments that I wrote, explaining the source code. Reverse engineering of closed-source code can be done by AIs even more effectively and faster than when humans do it. It is inevitable that _Mythos_ and other AIs will be asked to reverse-engineer closed-source software and will find bugs and security flaws. Probably AIs have already been asked to reverse-engineer closed-source software and products and have found bugs and weaknesses. So the main point of the articles, I think, is “we should be scared that _Mythos_ is out there and it may cause harm”. I agree with that point. What would be unfortunate is if a reader of the articles were to conclude “it is better to choose closed-source products than open-source products”. What has already been happening, and will continue to happen, is that the various open-source product vendors, and the open-source communities, make use of various AIs to look for bugs in the open-source software. Sunlight is the best disinfectant, that kind of thing. I think that gradually the various open-source initiatives will creep closer to being bug-free. In contrast the various closed-source vendors will differ from one to the next in their diligence about making use of the opportunity to find bugs with AI in their closed-source software. Eventually I expect the practical consequence of “AI looking for bugs in software” will be “fewer bugs in software” and it will happen for both open-source and closed-source software. And what will remain, after that migration has happened, is we will be back where we started. There will be open-source software where you can be confident it does not contain backdoors and intentional selections of weak encryption algorithms. And there will be closed-source products where it is not possible for the users to check for such things. There is another really good point in the articles, although it is often sort of buried toward the end. In the old days people wrote software the hard way. Human brains thinking, and human beings writing the software. I have written lots of very difficult software over the years. Many decades ago, in an earlier life, I helped write software that would control a commercial jet (the Lockeed L-1011 jumbo jet) as it lands on an airport runway. One hopes that we avoided making mistakes in that software that would lead to the airplane crashing. I believe there was never a crash of an L-1011 during a landing. Now there are no more L-1011s in service, so if we did make mistakes, that is in the past. Nowadays what happens more and more is that a person will use some AI shortcut to generate software to do this or that. Create an app to manage dental records or whatever. The resulting software will get put into use by users. And quite literally no human being who is actually experienced with writing software will have been involved in that process. In particular the person who used the AI did not do the tedious and unpleasant work of learning the programming language involved and learning how to write code in that language, and making mistakes and learning from the mistakes. And did not arrange to be part of a team with a second pair of eyes to try to catch mistakes. The app that manages the dental records will eventually be found to have some defect or weakness (or more likely, twenty defects and weaknesses). But the defect or weakness would likely not have happened (or would likely have been caught and corrected, earlier in the process) if the software had been written the hard way, the old-fashioned way, by human beings drawing upon experience. It reminds us of the cases we have read about where a lawyer asks an AI to write a legal brief, and the lawyer files the brief in court. And it turns out that one of the cited cases in the brief does not exist. The lawyer gets sanctioned. The client has a weaker position in court or loses the case or gets convicted of a crime. It would have been better had the lawyer “done it the hard way”, the old-fashioned way, researching the cases and personally drafting the brief. And maybe arranging to have a second pair of eyes look at the work product before it went out the door. Anyway, the articles correctly point out that _Mythos_ is going to have a much richer hunting ground to look for security flaws in a world where more and more apps got written by AIs rather than by being written the old-fashioned way, by humans doing hard work. What are the takeaways for people like you and me? What I say is, don’t purchase or use consumer products where you have no way of knowing whether the software was written by an AI instead of by humans doing it the hard way. And products where you have no way of knowing whether it has a backdoor or intentional weakness built in. And avoid products and software that are not open-source. Do you have a view about this? Please post a comment below. ### Share this: * Email a link to a friend (Opens in new window) Email * Share on LinkedIn (Opens in new window) LinkedIn * Share on Reddit (Opens in new window) Reddit * Share on Telegram (Opens in new window) Telegram * Share on WhatsApp (Opens in new window) WhatsApp * Share on Mastodon (Opens in new window) Mastodon * Share on Bluesky (Opens in new window) Bluesky * ### _Related_
000