Hacker News new | past | comments | ask | show | jobs | submit

Malus – Clean Room as a Service

https://malus.sh
An interesting aspect of this, especially their blog post (https://malus.sh/blog.html ), is that it acknowledges a strain in our legal system I've been observing for decades, but don't think the legal system or people in general have dealt with, which is that generally costs matter.

A favorite example of mine is speed limits. There is a difference between "putting up a sign that says 55 mph and walking away", "putting up a sign that says 55 mph and occasionally enforcing it with expensive humans when they get around to it", and "putting up a sign that says 55 mph and rigidly enforcing it to the exact mph through a robot". Nominally, the law is "don't go faster than 55 mph". Realistically, those are three completely different policies in every way that matters.

We are all making a continual and ongoing grave error thinking that taking what were previously de jure policies that were de facto quite different in the real world, and thoughtlessly "upgrading" the de jure policies directly into de facto policies without realizing that that is in fact a huge change in policy. One that nobody voted for, one that no regulator even really thought about, one that we are just thoughtlessly putting into place because "well, the law is, 55 mph" without realizing that, no, in fact that never was the law before. That's what the law said, not what it was. In the past those could never really be the same thing. Now, more and more, they can.

This is a big change!

Cost of enforcement matters. The exact same nominal law that is very costly to enforce has completely different costs and benefits then that same law becoming all but free to rigidly enforce.

And without very many people consciously realizing it, we have centuries of laws that were written with the subconscious realization that enforcement is difficult and expensive, and that the discretion of that enforcement is part of the power of the government. Blindly translating those centuries of laws into rigid, free enforcement is a terrible idea for everyone.

Yet we still have almost no recognition that that is an issue. This could, perhaps surprisingly, be one of the first places we directly grapple with this in a legal case someday soon, that the legality of something may be at least partially influenced by the expense of the operation.

loading story #47353324
loading story #47352979
loading story #47353261
loading story #47352914
loading story #47354067
loading story #47353851
loading story #47353737
loading story #47353958
loading story #47353984
loading story #47353741
loading story #47355902
"I used to feel guilty about not attributing open source maintainers. Then I remembered that guilt doesn't show up on quarterly reports. Thank you, MalusCorp." ◆ Chad Stockholder Engineering Director, Profit First LLC
loading story #47352729
loading story #47353349
The fact that it took me the comments sections to understand this is satire speaks a lot about the current status of where things are going.

EDIT: Reading it again its quite obvious, I was just skimming at first, but still damn. Hilarious

loading story #47354348
loading story #47353496
loading story #47353882
loading story #47354020
There are two teenagers who learned about Malus in the last hour and have started figuring out how to actually build it, right now. They will not cite their source in their IPO statements.
loading story #47357403
loading story #47355386
Note for people who just briefly skimmed the site: This is satire.
loading story #47352539
loading story #47352604
loading story #47351858
loading story #47354301
loading story #47353127
loading story #47352466
loading story #47351643
For now...
loading story #47352248
loading story #47352910
loading story #47353122
loading story #47352346
This is satire but this is where things are heading. The impact on the OSS ecosystem is probably not a net positive overall, but don't forget that this also applies to commercial software as well.

There will be many questions asked, like why buy some SaaS with way too many features when you can just reimplement the parts you need? Why buy some expensive software package when you can point the LLM into the binary with Ghidra or IDA or whatever then spend a few weeks to reverse it?

loading story #47352640
loading story #47352463
"Change all your core software library dependencies to be unmaintained ripoff copies of those libraries." Sounds wise.....¡¡
loading story #47352132
I know this is satire, but I have an adjacent problem I could use help with. In my company, we have some legacy apps that run, but we no longer have the source, any everyone that worked on them has probably left the planet.

We need to replatform them at some point, and ideally I'd like to let some agents "use" the apps as a means to copy them / rebuild. Most of these are desktop apps, but some have browser interfaces. Has anyone tried something like this or can recommend a service that's worked for them?

loading story #47353029
loading story #47352634
loading story #47352713
loading story #47357375
loading story #47354969
Haha, was extremely rage-baited by this. Thanks.
This time it's satire, but I bet someone will offer exactly that for real in the next few days. The idea is unethical but far too lucrative from a business perspective.
loading story #47353043
loading story #47351537
scanning… …fuming… …blood pressure risingsees a quote attributed to “Chad Stockholder Engineering Director, Profit First LLC” …oh phew, thank god for that. I actually believed this could be real for a moment!
This is essentially 'License Laundering as a Service.' The 'Firewall' they describe is an illusion because the contamination happens at the training phase, not the inference phase. You can't claim independent creation when your 'independent developer' (the commercial LLM) already has the original implementation's patterns and edge cases baked into its weights.

In order to really do this, they would need to train LLMs from scratch that had no exposure whatsoever to open source code which they may be asked to reproduce. Those models in turn would be terrible at coding given how much of the training corpus is open source code.

The solution here seems to be to impose some constraint or requirement which means that literal copying is impossible (remember, copyright governs copies, it doesn't govern ideas or algorithms - that would be 'patents', which essentially no open source software has) or where any 'copying' from vaguely remembered pretraining code is on such an abstract indirect level that it is 'transformative' and thus safe.

For example, the Anthropic Rust C compiler could hardly have copied GCC or any of the many C compilers it surely trained on, because then it wouldn't have spat out reasonably idiomatic and natural looking Rust in a differently organized codebase.

Good news for Rust and Lean, I guess, as it seems like everyone these days is looking for an excuse to rewrite everything into those for either speed or safety or both.

loading story #47354478
>The 'Firewall' they describe is an illusion because [...]

it is an illusion because this is a satire site.

loading story #47354520
loading story #47354182
loading story #47357212
> You have been so generous, so unreasonably, almost suspiciously generous, that you have made it possible for an entire global economy to run on software that nobody technically owns, maintained by people that nobody technically employs, governed by licenses that nobody technically reads. It is a miracle of human cooperation. It is also, from a fiduciary standpoint, completely insane.

Funny but true.

loading story #47352412
loading story #47353425
loading story #47351569
>Our proprietary AI robots independently recreate any open source project from scratch.

Fact that this is satire aside, why would a company like this limit this methodology to only open source? Since they can make a "dirty room" AI that uses computer-use models, plays with an app, observes how it looks from the outside (UI) and inside (with debug tools), creates a spec sheet of how the app functions, and then sends those specs to the "clean room" AI.

loading story #47354370
loading story #47354991
loading story #47355947
loading story #47355375
This is brilliant satire. Wonderful response to the “rewrite” of chardet.

^ For those who haven’t been keeping up on the debacle.

If this site actually connects to Stripe, it's much more than just satire. It's a honeypot :D
loading story #47355460
Love the product link in footer to "Emergency AGPL Removal"
loading story #47355316
loading story #47355359
The joke is that the models have already seen the source code of said packages regardless, right?
loading story #47354976
loading story #47356003
Not sure their attempted point lands the way they think it will. I view this as an unmitigated good. Open source every damn thing. Open the floodgates. Break the system.

I'd cheer for a company like this.

It seems to dance just on the other side of what's legal, though.

loading story #47352076
loading story #47351485
loading story #47354768
loading story #47356232
loading story #47354741
loading story #47354558
loading story #47355276
loading story #47353653
The frustrating thing is I also thought about this as a natural conclusion - but as a natural workflow that corporations will do when they see AGPL dependencies they want to use. (I also think there's a world where we start tightening our software bill of materials anyway.)

I do not believe it will ever again make sense to build open source for business. the era of OSS as a business model will be very limited going forward. As sad and frustrating as it is, we did it to ourselves.

loading story #47354549
loading story #47356216
loading story #47353250
As a hypothetical.

Let’s say instead it consolidated a few packages into 1. This might even be a good idea for security reasons.

Then it offered a mandatory 15% revenue tip to the original projects.

So far GPL enforcement usually comes down to “umm, try and sue us lol”.

How much human intervention is needed for it to be a real innovation and not llm generated. Can I someone to watch Claude do its thing and press enter 3 times ?

loading story #47352701
loading story #47354414
loading story #47353719
loading story #47354746
loading story #47353492
loading story #47353401
loading story #47353329
loading story #47353591
I did try to upload a requirements.txt with "chardet < 7.0" in it ("Copyright (C) 2024 Dan Blanchard"? I don't think so buddy, it's mine now), but despite claiming otherwise, the satirical site only takes package.json so I uploaded the one from https://github.com/prokopschield/require-gpl/

It does actually generate a price (which is suspiciously like a fixed rate of $1 per megabyte), and does actually lead you to Stripe. What happens if someone actually pays? Are they going to be refunding everything, or are they actually going to file the serial numbers off for you?

loading story #47356620
Today's satire is tomorrow's reality, if the last 50 or so years is anything to go by.
I do sort of wonder how the law might consider attempts at trying to apply a certain license to LLM generated code. Haven't the courts essentially said something to the effect of: "No human, no copyright protection"?
is the motto, "Don't be good?"
loading story #47352627
loading story #47357457
I have to admit It took me an unconfortably long amount of time to realize this was fake-
It's interesting that the focus is just on open source licenses. If one can strip licenses from source code using LLMs, then surely a Microsoft employee could do the same with the Windows source code!
loading story #47355570
This is satire, but I actually have built something that can do this extremely well as an unintentional side effect. I will not be building my business around this capability however
loading story #47354302
loading story #47354158
loading story #47355366
loading story #47356441
malus, mala, malum ADJ

bad, evil, wicked; ugly; unlucky;

It's an interesting word in Latin, because depending on the phonetic length of the vowel and gender it vary greatly in meaning. The word 'malus' (short a, masculine adjective) means wicked, the word 'mālus' (long ā, feminine noun) means apple tree, and 'mālus' (long ā, masculine noun) means the mast of a ship.

loading story #47352282
loading story #47354300
loading story #47353630
Presumably this is a joke, based on the "Success Reports" and the footer, among other things.

"This service is provided "as is" without warranty. MalusCorp is not responsible for any legal consequences, moral implications, or late-night guilt spirals resulting from use of our services."

loading story #47353511
loading story #47353905
Let's not give anyone ideas!
if it were true that indeed was legal to rewrite and relicense open source code, would that also be true for non-open source code? as in, could someone do a similar rewrite of their employers proprietary code and release it publicly?
loading story #47354287
loading story #47354837
{"deleted":true,"id":47351835,"parent":47350424,"time":1773328383,"type":"comment"}
loading story #47353636
loading story #47355853
loading story #47353585
I bet someone has already made this service for real.
loading story #47354121
loading story #47356044
1. Best part of this (satirical) post is, the service they offer isn't really needed. LLM's can do this already for small projects, and soon likely will for large ones too. You don't need a company to do this, we all have the LLM tooling to do it. Critical we're all spending time thinking about what that means in a thoughtful way.

2. For the sake of argument assume 1 is completely true and feasible now and / or in the near term. If LLM generated code is also non copyrightable... but even if it is... if you can just make a copyleft version via the same manner... what will the licenses even mean any longer?

{"deleted":true,"id":47351203,"parent":47350424,"time":1773326350,"type":"comment"}
loading story #47355047
loading story #47354241
I love these satirical sites that take a jab at how LLMs are (genuinely) ruining software.

See: https://deploycel.org/

loading story #47354482
It took me too long to understand it’s satire. BP went through stratosphere before I noticed.

Let’s hope one of these fake AI grifters doesn’t take this as a serious idea, raised a couple hundred million, and do real damage.

(I’m not against AI, I just don’t like nonsense either in tech, or people)

loading story #47355374
loading story #47354386
loading story #47353832
loading story #47355197
loading story #47355418
loading story #47354390
Amazon getting all excited hoping it's real.
Oof, this is unironically amazing!
loading story #47357030
Oh no… VCs will see this and take it seriously
loading story #47351980
blegh, i like the motivation but why again and again do you need to write the content of the page with Slop-LLM-GPT? Your motive and points are valid, why waste it on a word filter that cannot capture it?
turd.png classy
loading story #47354802
In this climate, it almost feels like it's not satire.
loading story #47356089
loading story #47354569
Now this is a conversation piece
loading story #47353649
loading story #47354381
loading story #47354006
loading story #47354216
yay capitalism. thank god it is a joke!

> Those maintainers worked for free—why should they get credit?

ROFL

loading story #47355651
loading story #47355810
{"dead":true,"deleted":true,"id":47352890,"parent":47350424,"time":1773331558,"type":"comment"}
[flagged]
loading story #47352909
loading story #47352901
loading story #47352917
loading story #47352881
loading story #47353550
loading story #47353943