Cal.com switched its production codebase from AGPL-3.0 to closed source in April, citing AI-assisted vulnerability discovery as the primary reason. The author argues this reasoning is incomplete: AI tools like XBOW can attack running services without needing source code, so closing the source doesn't meaningfully reduce attacker capability. A demonstration shows even a local model can reverse-engineer a binary and identify planted vulnerabilities. The real defensive advantage of open source is that it lets the community run the same AI auditing tools attackers use — before attackers do. The move also fits a familiar commercial pattern (HashiCorp, Elastic, MongoDB) of AGPL-then-closed pivots, making the security justification harder to evaluate in isolation.

8m read timeFrom xda-developers.com
Post cover image
Table of contents
Cal.com's reasoning isn't wrong, it's just incompleteEven a local model can reverse engineer a binaryOpen source still has the only real defenseWhat's changed for Cal.com?
168 Impressions