This week I was reading this article, "we have a year to fix security everywhere".
The TL;DR, is that GLM-5.3 flash can be run locally on $5-15k hardware and is apparently good at hacking, especially when using an "abliterated" version which doesn't adhere to any safety checks.
In other words, anyone with a bit of money can run an agent 24/7 to find vulnerabilities and exploit them across the web. At least that is what it claims.
In the past, ethical hackers used to find vulnerabilities in a companies code and then email them to give them time to fix it, usually with the expectation of receiving a bounty. There are many cases of these vulnerabilities taking months to fix and it only getting resolved when the hacker decides to go public.
With hackers using agents to find and exploit vulnerabilities, companies no longer have months to fix these vulnerabilities, they may not even have hours.
For many indie developers the goal has been to create a SaaS with recurring revenue and sit back and relax. Once you have a working product you only need to iterate on it occasionally to keep customers interested and keep up with competitors.
If what they are saying is true, SaaS applications will now need water tight security if they want to stay in business. This means paying for security experts to evaluate your code or they would hope running your own agent with the latest models 24/7 to find potential security issues with your software before someone else does. I hope it doesn't come to that, as the last thing we need is more AI.
Either way, it is saying that SaaS is no longer a viable option for solo entrepreneurs as we don't have the resources to keep up with millions of hackers using AI agents to look for back doors in our code.
If all this is true, where does that leave us?
I think this is where offline software and apps are going to gain more traction again. We used to pay for applications and run them locally on our computers. Then companies switched to SaaS services so they could charge a subscription. With SaaS potentially becoming a security nightmare, I wonder if we will see a return of offline mobile and desktop applications.
For those that want collaborative features, there could be an option to self host a service. Businesses can then get all the collaborative features they are used to having with cloud based options but without it being publicly accessible to the internet.
Of course, all of this is already possible with self hosting. I have replaced a lot of the SaaS applications I have used in the past with open source options that run locally on my home network. If one of those contains a security vulnerability then it is not an issue as no one else can access it anyway.
Here are some of the alternatives I am using instead of cloud based platforms:
- Grist - This has replaced Google Sheets for me. If I need a smart spreadsheet that I can access with an API I use Grist.
- VaultWarden - Integrates with the BitWarden clients. Now all my passwords are only accessible within my home network or via VPN.
- ForgeJo - This has replaced GitHub for all of my personal projects. Big Tech can't train AI on your code if they can't access it.
- N8N - When I need a simple way to automate something that you would use IFTTT or Zapier for I use N8N instead.
- Uptime Kuma - I use this to monitor the uptime of all my publicly hosted services such as my website, PeerTube and public ForgeJo instance.
- Miniflux - This is my RSS feed reader which has replaced Feedly for me and before that Google Reader.
I also have a whole host of other self hosted software that I use ever day such as JellyFin, audiobookshelf and Calibre-Web-Automated.
I will do some more videos and posts in the future about my self-hosted set up as I think more people are going to need something similar going forward.
❤️ Picks of the Week #
🛠️ Tools #
StemDeck, a free, open-source and local AI stem separator - This is really cool. As a guitarist, it would definitely be helpful to have a way to isolate just the guitar from a song to see how it is played without all the other instruments or vocals. I did tried this out with Chasing Cars by Snow Patrol and it did a fantastic job. Interesting naming so we now have StemDeck, SteamDeck and StreamDeck...
💻 Programming #
Programming As A Hobby In The Age Of AI - I still think that writing code by hand isn't something you need to justify. People are only able to review and validate AI generated code because they know how to write it. If you don't continue the practice then you won't be able to review the AI output anymore.
🔒 Security & Privacy #
Tl;dv: Over 180k meetings left wide open - Wow we used TL;DV at work. I wonder if they still would have used it knowing all the recording meetings were public. It is these kind of data breaches that make running everything locally more compelling.
🎨 Design & UX #
The AI Aesthetic - I hadn't picked up on the small icons as I have seen other apps prior to AI using these as well. Obsidian which I use to write all my posts has them for example as well. I have definitely noticed the serif + mono font combination, orange highlighting and blinking dots everywhere now.
🤖 AI #
No cost, no value - This is where I am at right now. I could use AI and create things the easy way but I would rather spend the time doing it myself and learning along the way. It won't be quicker or easier but it will definitely be more fulfilling.
AI's top startups are barely publishing their research - I think if AI was solving the climate crisis instead of contributing to it and curing cancer it might just result in a net positive. Except it isn't doing any of these things, and if it is the AI companies are keeping it to themselves.
Destructive AI. - The destruction of books solely to profit AI companies really makes me mad.
Don't be a meat proxy - This is my pet peeve with people using AI. They don't even bother to reword or in some cases read what the LLM has produced. Here is a 10 page document Claude output. If you aren't reading, correcting and changing the code then you are just a meat proxy between the reviewer and the LLM.
Eight Myths on Software Engineering and GenAI - This is a good set of myths that I think help explain how GenAI isn't the solution people think it is.
Docker Sandboxes – Disposable, isolated sandboxes for AI agents - If you are going to be running AI agents on your computer then you need to make sure it is sandboxed to make sure that it doesn't rm -rf you home directory.
Muse Glimmer: 30B-parameter model optimized for always-on local agent workflows - Another local model from Meta. I am not sure this good at coding so looks to be more for personal assistant scenarios.
Where do YOU draw the AI line? - This seems to be the norm now. If I was forced to use AI I would quit on the spot. At the moment I am on some what of a career sabbatical trying to work out a way so I don't have to go back to something like this.
Detecting Claude by counting letters - This is quite cool. At least it recognised my text as written by a meat bag. With AI having to watermark all output these detection tools should get better. You can try it out here: Robot (Claude or ChatGPT) or Meatbag?
The smell of AI - For me as a developer, I do care if a tool is using generated code. It generally means the quality of that tool is going to degrade. This isn't always the case though. I won't stop using a tool because an LLM has been used in generating the code but if the tool stops working as well then I am unlikely to come back.
Vibecoding isn't as fun as writing code by hand - 100%. I particularly agree with this quote which some it up nicely.
I don’t like the way it makes me feel, and I don’t like the quality of the output. It manages to make me feel dumb and superfluous (and, sometimes, dirty for even using it), without earning my respect.
The load-bearing vocabulary of Claude - LLMs definitely have a very particular language. It might be the use of these words that cause it. I can never quite pin point it but I get the feeling that text is AI when reading it without being able to fully prove it.
Debian votes to allow "responsible use of generative AI" - I like Debian, it is often my first choice for putting on my servers. I will have to see how this pans out.
🏢 Tech Industry #
What happens if an entire class of workers loses faith in their careers - I am not sure AI will ever replace nonsense jobs but will likely just make them even more pointless.
If you watch only one ad today (good luck with that), watch this one! - This is hilarious. At least there are companies actively against AI data centres.
It is a sign of the times that Amazon gets to call this fair use while huge corporations try to sue the Internet Archive out of business. - The Internet Archive is also scanning books but unlike Amazon they aren't getting destroyed after. Scanning books privately and then selling derivative works based on the complete book is still IP theft.
GitHub's growth - This does make me feel a bit sad for GitHub (only slightly). It isn't entirely their fault that GitHub is now down so often.
Nvidia agrees to acquire Hugging Face for $13B - I wonder where this leaves open weight models now. I can see Nvidia trying to find a way to profit from this too.
🎮 Gaming #
A 12TB Steam "teraleak" spills more than a decade of lost PC gaming history - As a big lover of Steam games such as Portal all these leaks are really interesting.
🧠 Miscellaneous #
A physicist rigged his pet hamster’s wheel to upload to Strava - Haha this is hilarious.
Moon - I love these explanations we interactive diagrams.
Inception-style curved map for turn-by-turn directions - Useful? Probably not. Really cool to watch, absolutely!
Why Old Software Sometimes Feels Better - This is the software I want to make. Modern software that users can feel that they own and understand.
💬 Quote of the Week #
By sharing your journey publicly—and inviting friends, family, and complete strangers along for the ride—you will create your own fan club who are actively rooting for your success.
From the article "The ladders of wealth creation a step-by-step roadmap to building wealth" by Nathan Barry.
Top comments (0)