The Changelog
Forking Cal.com to closed source (Interview)
00:001:54:32
00:00
What's up friends, we'll go back to this is the change log.
朋友们最近怎么样,我们回到这期《The Change Log》。
00:04
What if the majority of open source repos out there?
如果外面绝大多数开源仓库其实已经被攻陷了,只是我们还不知道呢?
00:08
They're already compromised, and we just don't know yet.
这就是本周嘉宾PureRitualsson——Catacombrings联合创始人——带来的那个让人不安的理论。
00:12
That is the unsettling theory, PureRitualsson, co-founder of Catacombrings to this podcast
这期我们深入聊了AI如何把知识图谱给压平了,以至于一个16岁的小孩能像他妈妈用vibe coding写个iOS应用一样轻松地去“vibe hack”一座发电站。
00:18
this week.
还有为什么这么多年来一直让开源保持安全的那套报告文化,现在……
00:19
We dig into how AI has flattened the knowledge graph, so a 16 year old can vibe hack a power
我们深入探讨了AI如何将知识图谱变得扁平化,以至于一个16岁的孩子就能轻松“黑”进电力系统。
00:25
station as easily as their mom can vibe code an iOS app.
station就像他们妈妈能轻松 vibe code 一个 iOS app 一样容易。
00:31
Why the reporting culture that has kept open source safe and secure all these years is
为什么这些年来让开源保持安全可靠的举报文化,
00:35
collapsing under the AI generated noise, slop, whatever you want to call it, Catacombs
在AI生成的噪音、垃圾内容,随便你怎么叫,之下崩塌,Catacombs
00:42
move to fork its own code base and take the sensitive parts private and the eye opening
转向分叉自己的代码库,把敏感部分私有化,以及那个让人大开眼界的
00:47
reality that shipping $1 of AI tokens for pennies on a dollar, that is now a common
现实——以几分钱的价格卖出价值1美元的AI token,这现在已经成了常见的
00:53
start of business model, lots going on, lots changing, a massive thank you to our friends
商业模式起点,事情很多,变化也很多,非常感谢我们的朋友
01:01
and our partners at fly.io, your agents, they need computers, my agents, they need computers,
和我们在fly.io的合作伙伴,你的agent,它们需要计算机,我的agent,它们也需要计算机,
01:09
we host everything we do on fly.io, and you should too, check them out at fly.io, okay,
我们把自己做的一切都托管在fly.io上,你也应该这样,去fly.io看看吧,好了,
01:18
let's do this.
我们开始吧。
01:25
Well friends, this episode has brought to you by our friends at coder.com secure environments,
朋友们,这期节目由我们的朋友coder.com的安全环境赞助播出。
01:30
where developers and agents work in parallel, and I'm joined by Nikki Pike, field CTO,
在这里,开发者和智能体并行工作。今天和我一起的是Nikki Pike,field CTO,
01:36
forecoder, Nikki, what is the field CTO?
forecoder。Nikki,field CTO是做什么的?
01:38
So, I get that question a lot, and it's, you know, half the people understand it,
这个问题我经常被问到,你知道,一半人懂,一半人不懂。所以field CTO,我描述得非常简单——我们就是面向C-level高管的dev realm。也就是说,我们在客户的声音、C-level高管、经理层以及客户的领导团队之间架起一座桥,把这些声音带回我们的产品里。然后我们会去帮我们的团队统一口径,确保信息是准确的,确保我们做的东西是大家真正想要的,而不只是我们自己觉得好的东西。
01:42
half the people don't, so field CTO, I describe it very simply as we're dev realm for the C
一半的人不这么认为,所以作为领域CTO,我把它描述得非常简单:我们就是CTO的dev realm。
01:47
suite. So, we provide a bridge between the customer voice, between the C suite and the managers
套件。所以,我们在客户的声音、C级高管和经理之间搭建了一座桥梁。
01:53
and the leadership teams of our customers back into our product, and then we go through and we help
并将我们客户的领导团队反馈融入产品中,然后我们会逐一跟进并提供帮助。
01:57
enable our teams to have the same message to make sure that the message is correct,
让我们的团队能够传递一致的信息,确保信息是准确的。
02:01
and that we're building on something that people actually want, not just something that we think
并且我们是在人们真正想要的东西之上进行构建,而不只是我们自认为想要的东西。
02:04
they want. Okay, so, we're taking the laptop away from the developer, not really though,
他们想要什么。好吧,那我们其实不是真的要把笔记本电脑从开发者手里拿走,
02:09
we're putting them in a cloud development environment, a secure environment where they can work with
而是把他们放到一个云开发环境里,一个安全的环境,在那里他们可以和
02:13
their agents, in parallel, these are blessed environments, what's wrong with the laptop?
他们的agent并行工作,这些是受认可的环境,那笔记本电脑有什么问题?
02:17
The laptop is the trap here, and not only because the fact that it could be stolen,
笔记本电脑就是个陷阱,不仅是因为它可能被偷,
02:22
you could lose it, it breaks, and you're out of work while you're waiting for a new one, but there's
你可能把它弄丢、它坏了、你在等新电脑的时候就没法工作了,还有
02:25
also just the consistency that you got there. We all know developers, developers are going to be
就是你在那里得到的一致性。我们都认识开发者,开发者总是想要
02:29
looking for some of the latest and greatest, and if you're not really controlling how they get out
最新最好的东西,如果你没有真正控制他们怎么把东西发布出去,
02:33
there, that's where you get this, it works on my machine, it doesn't work on production,
就会出现这种情况:在我机器上能跑,在生产环境就不行。
02:37
it doesn't work anywhere else, because you don't have that consistency, you don't have that
这在别的地方就行不通了,因为你没有那种一致性,也没有那种能力去真正标准化环境长什么样。而且这个问题不只是针对新进来的人——你知道,入职这块,我估计平均下来一个新员工要花四到五周才能真正把本地笔记本电脑配好,准备好开始写第一行代码。你知道,首次提交代码的时间几乎是所有人都知道的一个指标。他们之所以做不到,是因为这里面有大量所谓的“部落知识”,他们得去跟其他开发者聊,我们用什么啊,依赖从哪儿拿啊,是从公共仓库还是私有仓库拿,但还有——
02:40
ability to really standardize what that environment looks like, and this is a problem not only for
真正实现对该环境样貌的标准化,这个问题不仅限于
02:45
new people coming in, you know, the onboarding statement, as average, I think is like four to five
新来的人,你知道的,入职培训那套说辞,平均下来我觉得大概是四到五。
02:49
weeks for a new employee to really get their local laptops set up and ready to start doing their
新员工要花好几周时间才能真正把本地笔记本电脑设置好,准备好开始干活。
02:54
first time of code, and you know, the time to first commit is a metric that almost everybody knows,
第一次写代码的时间,你知道的,首次提交代码的时间是一个几乎所有人都知道的指标。
02:58
and the reason they can't do that is because there's a lot of tribal knowledge out there,
他们之所以做不到这一点,是因为这里面有很多“部落知识”在流传。
03:01
they got to go talk to other developers, what are we using, where do we get our dependencies,
他们得去跟其他开发者交流,我们在用什么,依赖从哪儿来,
03:05
are we getting them from public, are we getting them from private repositories, but there's also
我们是从公开渠道获取的,还是从私有仓库获取的,但还有另一种情况——
03:09
the security and the supply chain aspect of this, when you have local machines out there,
这里的安全和供应链方面,当你有本地机器在外面的时候,
03:14
look at like the shy halud, you know, that virus that went out not long ago, this was a compromise
比如说那个 shy halud,你知道吧,就是不久前出现的一个病毒,这是一次
03:19
of the MPM public repositories, they went and downloaded things, MPM did what it did, next thing,
对 MPM 公共仓库的入侵。他们跑去下载了东西,MPM 该怎样还是怎样,接着
03:24
you know, you're compromised, but when you use something like what we're doing with cloud development
你就被攻破了。但是当你使用像我们正在做的 cloud development
03:29
environments, then you can mandate, and you can put restrictions on there to say, hey, you can only
environments 这种东西时,你就可以强制加上限制,说,嘿,你只能
03:34
go get your packages from our private repo, those packages are expected to have been thoroughly
从我们的 private repo 获取包,那些包应该是经过彻底
03:38
vetted, we know that they're clean, now does this stop everything like shy halud, no, if that
审查的,我们知道它们是干净的。那这能不能阻止所有类似 shy halud 的东西?不能,如果那个
03:43
compromise package gets into your private repo, you can still have that, but it really reduces the
被入侵的包进了你的 private repo,你还是可能中招,但它确实能减少
03:48
surface area of the attack, and it also reduces the blast area of the compromise should it happen,
attack surface,而且如果真的发生 compromise,它也会缩小 blast area,
03:53
because if your laptop gets compromised and you have to kill the laptop for whatever reason,
因为如果你的 laptop 被 compromise 了,而且不管什么原因你需要 kill 掉这台 laptop,
03:58
that's weeks out of work while you're either fixing that or you're getting a new laptop in,
那就是几周没法工作,不管你是去修它,还是等新的 laptop 到货,
04:03
the cloud development environment allows you to kill that, start back up fresh, and you're back in running
而 cloud development environment 让你可以 kill 掉它,重新起一个干净环境,然后马上恢复运行,
04:07
in five minutes, you don't have to wait all that time. Well friends, the first step is to go to
五分钟就搞定,你不需要等那么久。好了朋友们,第一步就是去
04:12
coder.com install coder, self-hosted environments for your teams to enjoy, to standardize around,
coder.com 安装 Coder,为你的团队提供 self-hosted 环境,让大家用得开心、标准一致,
04:19
and it's open source, so you can try it out today, once again coder.com.
而且它是 open source 的,所以你今天就可以试试。再说一次:coder.com。
04:43
Well friends, I'm here with an old friend, it's been a while, it's been too long here,
好了朋友们,我和一位老朋友在一起了,有段时间没见,确实太久没见了。
04:50
a co-founder of one of my favorite counties out there, I use you daily, Cal is how we schedule this,
我是我最喜欢的公司之一的联合创始人,我每天都用你们,Cal 就是我们安排日程的方式,
04:54
thank you very much for being the backbone of all my scheduling, it is about time since we've gotten
非常感谢你支撑了我所有的日程安排,距离我们上次上播客确实有一阵子了,是的,这个梗是故意的,非常感谢。我觉得其实我们第一次
05:00
back on the pod, yes, the pump was intended, thank you so much. I think actually our first
播客聊的就是“是时候了”这个话题,当时那段对话的开端大概就是
05:04
pod was really about how it was about time, where the initial conversation sort of began with this
Cal.com 那个时代,我甚至不确定我们录那期播客的时候你到底有没有 Cal.com,
05:09
era where cal.com, I'm not even sure if you had cal.com at the very moment we did that podcast or not,
但当时,我们只是 Cal 的用户,我说“我们”是指整个团队后来变了,
05:17
but it was, we were users of Cal only, when I say we, I mean, the organization changed
Cal only 其实已经存在一段时间了,但他们改版了,不好用了,我是说,
05:24
and Cal only has been around for a while, but they had changed, they weren't working, I mean,
很多乱七八糟的事,我相信你肯定也知道,但其中有一条暗线,
05:29
a lot of different stuff which I'm sure you're aware of, but one of the things, one of the undercurrents,
很多不同的东西,我相信你肯定都知道,但其中有一件事,一个潜在的暗流,
05:33
the themes of that podcast was it is about time, and so you know this very well because you
那期播客的主题就是“时间”,所以你肯定特别懂这个,毕竟你是cal.com的联合创始人之一,生活、吃饭、呼吸都跟时间相关。不过还是谢谢你再次来做客,没错,这期就是关于时间的。
05:40
probably live, eat and breathe, all the things around time being one of the co-founders of cal.com,
太感谢了,确实隔了一段时间了,我们得挤出更多时间。我记得我们买下cal.com大概就是那时候,可能三四年前吧,时间这东西真的很奇妙。所以,谢谢你再次邀请我,我很期待。
05:47
but thank you for coming back on, and yes, it is about time.
顺便稍微披露一下,我是Cal的一个很小额的投资人。通过你很久以前在AngelList上的项目投的,非常小的种子轮。
05:51
Thank you so much, it's been time and we need to make more time. I think it was right around
非常感谢,时间到了,我们确实需要更多时间。我想大概就是那个时候——
05:58
the time when we bought cal.com which may or may not be four years ago or three years ago, time
我们买下cal.com的时候,可能是四年前也可能是三年前,时间
06:04
is a weird concept. So yeah, thank you for having me again, I'm excited.
是个挺奇怪的概念。所以,是啊,谢谢你再次邀请我,我很期待。
06:11
And I guess slight full disclosure, I am a very small check investor in Cal.
顺便说一句,稍微披露一下,我是Cal的极小额投资人。
06:21
Very small seed investor through, I think, your angelist stuff that you had way back and
非常小的种子投资人,通过你很久以前在AngelList上的那些东西进来的。
06:25
that's how much I believed in it because I was like, okay, I think even then, if I'm recalling
我当时就是那么相信它的,因为我想,好吧,我觉得即使在那个时候,如果我没记错的话——我是在努力回忆——open source 确实是你们使命的核心,你知道吧,你们做 open source 已经很久了,你们的商业产品大概用的是不同的 license,但我不太清楚你具体选了哪种 license,以及那是怎么划分的。我知道今年 open source 这边也在变化。我相信你肯定有想法。所以你想聊哪儿我都乐意奉陪,但真的,我是 cal.com 的超级粉丝,每天都在用 cal.com,而且我们太久没好好叙旧了,我相信 cal 的这个新时代一定会不一样。我想在接下来的 agents 时代里,你可能会看到很多人用 agents 来——
06:30
correctly because I'm trying to go back on my memory, open source was core to your mission,
说得对,因为我是在努力回忆过去,开源一直是你的核心使命,
06:36
you know, you've been open source for a very long time, your commercial product is probably licensed
你知道,你做开源已经很久了,你的商业产品可能用的是不同的许可,
06:40
differently, which I'm not familiar with exactly which license you chose and how that sliced out.
具体你选了哪种许可、怎么划分的,我其实不太清楚。
06:45
I know things are changing even too this year around open source. I'm sure you have thoughts on
我知道今年连开源这块也在发生变化,我猜你肯定有想法。
06:51
that. So I'm happy to go wherever you want to, but yeah, big fan of cal.com, user daily of cal.com
所以你想聊哪儿都行,但说真的,我是cal.com的忠实粉丝,每天都在用,
06:57
and it's been too long to catch up and I'm sure that this new era of cal is going to be different.
而且我们确实太久没聊了,我敢说cal的这个新时代肯定会不一样。
07:03
I suppose in this next era of agents where you probably have a lot of folks using agents to
我觉得在下一个agent时代,你可能会看到很多人用agent替他们办事,
07:10
act on their behalf to maybe create events, measure availability, even book time with someone,
比如创建日程、查可用时间,甚至帮他们约人见面。
07:18
what is it like in this world that we're in with agents running a muck or maybe not a muck
在这个到处都是agent乱跑的世界里到底是什么感觉,或者说也许并没有乱跑?
07:25
in this era for you? I think all the cars have been shuffled and nobody knows what's coming next.
对你来说在这个时代是什么样?我觉得所有的牌都被重新洗过了,没人知道接下来会发生什么。
07:33
I think I don't think there's a single person who can predict what the outcome is going to be
我觉得——我不认为有任何人能预测最终的结果会是什么。
07:39
like predicting how a certain stock goes, like that person is a liar. You can never really say
就像预测某只股票怎么走一样,那种人就是在撒谎。你永远没法真正说准
07:44
what's going to happen. But one thing for sure is that I think a lot of things
接下来会发生什么。但有一点是确定的,我觉得有很多事情
07:51
are happening that we could not predict as easily as before. Usually you start a SaaS company,
正在发生,而我们不像以前那样容易预测了。以前你开一家SaaS公司,
07:56
you have a playbook, you get from 0 to 1 million, from 1 to 10 million, 100 million. There's certain
你有一套playbook,你从0做到100万,从100万做到1000万,再到1亿。有固定的
08:05
pattern matching and playbooks, etc. I don't think any of that works anymore. Even when it comes to
模式匹配和打法之类的。我觉得那套东西现在完全不灵了。甚至就连……
08:11
how to build in public or how to build open source, how to build the safest software or the fastest
怎么公开做产品,或者怎么做开源,怎么做最安全的软件,或者增长最快的软件,所有东西都被重新洗牌了。大概七个月前我们还开玩笑说,Dario预测六个月后所有人都会用AI agent写代码。我已经好几个星期没写过一行代码了,样本都直接给我们的反工程团队。现在全是代码生成和系统里的AI agent。所以那个预测七个月前听起来特别离谱,大家都在笑。但现在就是技术已经到位了,对吧?所以问题就是还有什么会变,而且我只能关注商业开源这块。现在噪音太多了,以前那种感觉就是——
08:21
growing software, everything has been reshuffled. I think about seven months ago we joked
随着软件的发展,一切都重新洗牌了。我记得大概七个月前我们还在开玩笑说,
08:27
that Dario set like in six months from now everybody will be using AI agents to write code.
Dario在六个月前设定的那个目标,从现在起,每个人都会用AI agents来写代码。
08:32
I have not written a line of code like in weeks and samples to our anti-engineering team.
我已经好几个星期没写过一行代码了,样本都交给我们的anti-engineering团队了。
08:40
It's all code gen and AI agent in the system. And so it's like that prediction was so
系统里全是代码生成和AI agent。所以那个预测就是这么来的。
08:47
back seven months ago and everybody was laughing at it. And now it's just like it's the technologies
七个月前,所有人还在嘲笑它。现在呢,它就成了那项技术了。
08:54
here, right? And so the question is like what else will change in terms of, and I can only focus on
在这里,对吧?所以问题就是,除此之外还有哪些方面会发生变化——而我只能专注于……
09:01
startups. I don't want to touch broad society aspects of like what's the meaning of jobs and
startups。
09:07
work. I don't want to touch that. But I think for startups it's a really weird time right now.
我不想碰那些更广泛的社会层面,比如 jobs 和 work 的意义是什么。
09:17
Like some time that you could never really predict before. And then you start as always a weird
这个我不想碰。
09:24
journey. But now it feels like extra volatile I'd say. And I think to get to your point to open
但我觉得对 startups 来说,现在真的是个很奇怪的时期。
09:32
source. And I think open source multiplies that by like a factor of 10. Like you're basically
就像某种以前你根本无法预测的时期。
09:38
drinking from the fireholes because when you have a private source or the closed source business
然后你一如既往地开始一段奇怪的旅程。
09:46
you're the only one committing to it. There's no such thing as a public repository where people can
但现在感觉格外动荡,我会说。
09:52
like look inside and contribute et cetera, et cetera. For all those businesses and I strictly
然后我想接回你刚说的 open source 那个点。
09:57
focus on commercial open source. You just have so much noise and like back in the days it was like
专注于商业开源。现在噪音太多了,以前那会儿就像——
10:07
if somebody opens a pull request you would immediately know okay it's black and white. Either it's
如果有人开了一个pull request,你马上就能看出来,这事儿就是黑白分明的。要么这是一个想得很周全的pull request,有测试、有完整的结构,什么都齐;要么就是乱七八糟的。如果是乱七八糟的,你就直接关掉。而且任何人都能看一眼就说,行,这个该关。那个值得好好review一下,然后你就在那个基础上继续推进,跟作者互动。现在呢,什么东西看起来都一样。你收到一个pull request,永远都是cloud code写的,或者可能是codex写的,运气好点可能是别的什么coding assistant写的。但以前不一样,那时候你有上千个开源项目,会有另一个人直接否定那个想法,现在你只是有一千个人在用两个同样的工具。
10:11
a well thought out pull request and you can with tests and everything and well thought out structure
一个深思熟虑的pull request,而且你可以带上测试和所有东西,结构也考虑得很周全。
10:20
or it's whack. And if it's whack you close it. And it's like anyone can look at it and be like okay
或者它不行。如果不行,你就把它关掉。而且任何人都能看一眼就说,行吧。
10:25
yeah this is worth closing. That one's worth reviewing and then you you know you build on top of
是的,这一点值得收尾。那个值得回顾一下,然后你知道的,你在此基础上继续构建。
10:30
that and you engage with the author. Nowadays everything looks the same. Like you get a pull request
那一点,以及你和作者互动。现在所有东西看起来都一个样。比如你收到一个pull request。
10:39
and it's always written by by cloud by cloud code or by maybe codex or maybe if you're lucky by
而且它总是由云端代码写的,或者可能是Codex写的,或者如果你运气好的话,是由
10:46
some other coding assistant. But it's like back in the days you had a thousand open source
一些其他的编码助手。但这就好比以前你有一千个开源
10:52
contributors and you would have a thousand opinions and one person would do something and the
Contributors 一多,你就会有上千种意见。一个人做了件事,另一个人可能就会否决那个想法,结果现在就是一千个人在用两种不同的 coding assistant。这就有点像“最好的想法胜出”那套说法,只不过现在是“最好的 LLM 胜出”;或者也许应该说,是“给那个 LLM 的最好的 prompt”会胜出,因为 prompt 之间还是有一定差异的,对吧。但要说搞清楚到底该把什么 merge 进项目里,真的特别特别难。更糟的是,那种 pull request 看上去还特别有把握,因为 LLM 就像在说“最好的东西已经放在金盘子里端给你了”。
10:56
other person would like reject that idea and now you just have a thousand people using two
其他人可能会反对这个想法,而现在你只有一千个人在用两个。
11:02
different coding assistants. It's like this whole notion of like the best idea wins it's like
不同的编程助手。就像整个“最好的想法胜出”的概念,是
11:10
the best large language model wins but you only have or maybe the best prompt given to that
最好的大语言模型胜出,但你只有——或者说也许是最好的提示词给了那个
11:15
large language model wins because there's still some variation among prompts right. But like
大语言模型才会胜出,因为提示词之间还是有差异对吧。但
11:21
it's really really hard to distill what should be merged into the project and whatnot.
真的很难提炼出什么应该合并进项目里之类的。
11:28
And then what's even worse is that like the confidence of that pull request is so high because
更糟的是,那个拉取请求的自信度高得离谱,因为
11:33
the large language model is like here's the best thing delivered to you on a golden plate
大语言模型就像在说:这是最好的东西,放在金盘子里端给你了。
11:39
and then you start to peel off the layers of the undying and you're like wow even these tests are
然后你开始一层层剥开表象,你会发现哇,连这些测试都是
11:44
like hallucinated like none of this makes sense like it looks so real right like it's wow this
幻觉出来的,没有一样讲得通,它看起来太真了,对吧,真是哇。
11:49
is like the best thing ever and then you start to run and you're like wait why is that thing hard
就像是天底下最棒的东西,然后你开始跑起来,你就会想,等等,为什么这个是硬编码的,你知道吗,就是满脑子问号,然后你会想,我到底为什么要审这个代码。
11:53
coded like you know like so many question marks and it's like you're like why am I even reviewing this
所以想象一下你是一家商业开源公司,外面推特上那么多帖子,我们都不用专门举例子,随便搜一下“开源”和“AI”就能看到,他们都在关闭外部pull request,搞那种担保人制度,只有那种特别亲近、经过好几轮面试的人才能往仓库里提交代码,因为实在是有太多AI垃圾了,真的就是AI编码的垃圾机器人往你仓库里扔东西。
12:02
and so imagine being a commercial open source company there's so many tweets out there we don't
所以这就是第一个问题,这就是为什么我说,这就像对着消防水管喝水一样。
12:07
even need to reference one there's so many just search for like open source and AI and they're like
甚至都不需要引用某一个,因为太多了,随便搜一下开源和AI,就能看到一大堆。
12:12
shutting down external pull requests and having this like vouch system where only like really
关闭外部pull request,然后搞一个那种担保人系统,只有真正
12:18
close people who went through like multiple rounds of interviews are able to commit to the
那些经历了多轮面试的亲近的人,才能对这件事做出承诺。
12:23
repository because it's just so much AI slot like literally AI coded slot beings thrown at your
这个repository里全是AI生成的内容,简直就像是一堆AI编码的槽位生物直接砸到你脸上。
12:31
repository so that's problem number one that's why I'm saying like drinking from the firewalls imagine
仓库就是这样,这是第一个问题,所以我才说,这就像对着防火墙喝水一样。
12:36
one cracked engineer on cloud code like spamming your private repository okay now have a hundred of
一个很厉害的工程师在云代码上乱发,就像往你的私有仓库里狂刷垃圾一样,现在有上百个这种pull request,有些pull request说白了就是“嘿,云,你能帮我修一下这个GitHub issue吗”,然后他们就开了一个pull request,我就想说,行吧,谢了,但这事儿我自己也能干啊,你懂吧,你所谓的“新增知识”在哪儿呢?这根本没有任何新增知识,你只是往代码库里堆了更多垃圾,所以真的很难搞,这是第一个问题。我很乐意继续讲更多问题。然后我跟我一个朋友聊,Adam Jacob,你认识Adam Jacob吗?他挺有名的,是Chef的创始人。
12:42
those who just and and some of these pull requests are literally just like hey cloud can you fix
那些刚加入的人,还有一些这些pull request基本上就是,“嘿,Cloud,你能修一下吗?”
12:48
this GitHub issue for me and then they open a pull request and I'm like okay but like thanks but I
帮我看看这个GitHub issue,然后他们直接开了一个pull request,我就想,行吧,谢了但不用了。
12:53
could have done that you know like where's your well added knowledge come you know this is
你知道的,这种事本来可以做到的,就像——你那些所谓的知识到底是从哪儿来的,你懂的,就是这样。
13:04
no no added knowledge and you're just essentially adding more slot to the code base so
不不,没有新增知识,你本质上只是在给代码库增加更多的插槽而已。
13:08
it's really hard um that's problem number one I'm happy to go over many more problems
这真的很难,嗯,这是第一个问题。我很乐意继续讲更多的问题。
13:14
now it's talking to a friend of mine uh a friend of mine Adam Jacob did you know Adam Jacob
现在我要跟我的一个朋友聊一聊,嗯,我的一个朋友Adam Jacob,你认识Adam Jacob吗?
13:20
money chances he uh a name you know Adam Jacob he's famous for being the founder of chef
钱的机会,他呃,有个名字你懂的,Adam Jacob,他出名是因为创办了chef。
13:28
and maybe infinitely being the founder chef it was here you'd probably laugh at this moment but
而且可能作为创始主厨无限期地待在这里,你大概会觉得现在这一幕挺好笑,但
13:35
he created a company called system initiative and they had begun to rethink
他创办了一家公司叫System Initiative,他们开始重新思考
13:44
CI or not sorry not CI but they began to rethink infrastructure it was very visual very innovative
CI——不对,抱歉,不是CI——他们开始重新思考基础设施,非常视觉化,非常有创新性,
13:52
but they focused focus on this visual layer and this is pre AI and obviously we know how things have
但他们专注在这个视觉层,而且那是在AI之前,显然我们都知道后来事情
13:57
played out and so they've sort of failed product market fit but a lot of the ideas were still really
是怎么发展的,所以他们算是没找到产品市场契合,但很多想法其实仍然非常
14:03
good and they partly did a lot of that good stuff into what's now called swamp dot club and they are
好,而且他们把这些好东西部分融入了现在叫Swamp Dot Club的项目,他们是
14:09
uh a gpl v3 open source yeah same but very specifically they are open source but not open to
呃,GPL v3开源,对,一样,但非常特别的是他们是开源但不开放
14:20
contributions they do issue based contributions now is this is this where you're thinking of like
贡献,他们现在做基于issue的贡献,这是——这是你想到的那种吗?
14:25
hey you can file an issue you can file bug you can file your your concerns but we'll never accept
你可以提issue,你可以报bug,你可以提你的顾虑,但我们永远不会接受
14:29
a pull request ever that's fine i mean i i think so here's my here's my current issue with everything
pull request,永远不。这没问题,我是说,我觉得是这样。但这是我对现在所有
14:40
open source um we we're clearly training AI that's okay i mean that's connected AI companies are
开源东西最大的不满。我们显然在训练AI,这没问题,我是说,那些AI公司
14:51
already giving open source companies tons of free tokens which is you know great like
已经给了开源公司一大堆免费token,你知道,这挺好的,
14:56
i have a free box max i have a free codex i'm very grateful for that um i understand that we are
我有免费的Box Max,我有免费的Codex,我非常感激。我理解我们
15:04
producing the code that they are training the next large language model on and that's i think
正在产出代码,而他们拿这些代码去训练下一代大语言模型,我觉得
15:09
is fine i mean it's still violating the license i guess but um philharie but i think the problem is
这没问题。我是说,这确实还是违反许可证的,但,唉,但我觉得问题在于,
15:18
that when entire open source repositories as it is right now gets overwhelmed with
当整个开源仓库,就像现在这样,被这些东西淹没的时候——
15:25
slop it just destroys cold quality i mean look it's still our job to as maintainers to review
垃圾内容就是在摧毁代码质量。我的意思是,看吧,维护者仍然有责任去审查、批准、合并和处理那些糟糕的PR,所以确保质量高依然是我们的事。但问题是,现在要区分一个烂PR和一个好PR,工作量实在太大了,大到人力根本不可能完成。而且我知道OpenClause的Peter,他已经不再看自己那些diff了,比如他自己的Cloud Codex PR。但我不觉得闭上眼睛祈祷一切顺利、然后随便测一半就是解决办法,因为你看过那张图——一旦你把垃圾内容引入代码库,那个编码agent就会看着你现有的项目,然后开始学坏。
15:34
and and approve and merge and change poor requests so it's still our job to to make sure the
批准、合并以及修改那些质量不佳的pull request,所以确保这些仍然是我们的工作。
15:42
quality is high but it's just so much more work now to differentiate between bad PR and good PR
质量很高,但现在要区分糟糕的PR和好的PR,工作量大多了。
15:50
that it's simply not possible like humanly possible and i know peter from open clause that he's not
这根本不可能,从人力上来说不可能,而且我知道OpenAI的Peter,他不是那样的人。
15:58
reading his his own uh diffs anymore like his own cloud codex um PR's i don't think necessarily that
他不再读自己的diff了,比如他自己的Cloud Codex PR,我觉得那倒不一定。
16:07
that's the solution that we just like close our eyes and hope for the best and then like half test
这就是那种我们闭上眼睛、祈祷一切顺利,然后只做一半测试的解决方案。
16:12
etc because um there's this this graphic what that was like the moment you were introduced
等等,因为,嗯,有一个图表,那就像是你被介绍给大家的那个时刻。
16:18
slop to your code base now the coding agent looks at your existing project and then adopts bad
现在把slop加进你的代码库,coding agent会查看你现有的项目,然后学坏。
16:24
practices and you know it's kind of like a recursive loop of pool right like it just gets worse
实践就是这样,你知道这有点像一种递归循环,对吧,就是会越来越糟
16:29
worse over time same thing happens with with large language models right the worst quality
随着时间推移越来越差,大型语言模型也是一样的,对吧,开源代码库的质量越差
16:35
of an open source repository the worst AI will be in the future learning from that bad code right
未来AI从那些烂代码里学到的就越差,对吧
16:41
and so um that's another issue i have the open source where if you cannot get the resources in place
所以这也是我对开源有意见的另一个点,如果你没办法把资源落实到位
16:49
to actually have really really high quality and and be in mind that means you need to end up
去真正保证非常非常高的质量,而且你要知道,这意味着你最终得
16:56
hiring really like i see five i see seven level people who know what they're doing because you hire
招那种,我觉得是IC5、IC7级别的人,真正懂行的人,因为如果你招
17:03
a generic i see one i see two i see three chances are they will be using cloud code and they they
一个普通的IC1、IC2、IC3,他们大概率会用cloud code,而且他们
17:09
incentivize to use cloud code because that's just how the whole industry works today
有动力去用cloud code,因为现在整个行业就是这么运作的
17:13
and that's okay i'm not saying that's bad but like you still need these like
这没什么,我不是说这不好,但你还是需要这些——不好意思直说——学计算机科学的人,他们懂那些东西,而且我也不是说他们不好。
17:18
sorry to say this like study computer scientists who know what oh and it's and i'm on them don't
然后,呃,对,所以,嗯,如果垃圾内容被成倍放大,那前景真的不太乐观,你懂吧。所以我觉得整个训练层面,还有那个,你知道的,代码和公开层面,真的是一个非常核心的共同问题。对,你刚才在说你的担忧和挑战的时候,我正好在看cow.com的开源仓库,get.com斜杠cow.com斜杠cow.com,然后我正停在pull requests那个标签页上,你大概能看到,那里真的有一大堆——多到你根本不想看,或者说根本看不过来的程度。
17:25
and uh so yeah um i it's not it's not a great outlook if
嗯,所以,呃,对,我,这不算,这不算什么好前景。
17:32
slop gets multiplied you know um so i think the whole training aspect and the the
垃圾内容会被成倍放大,你懂的,嗯,所以我觉得整个训练环节,还有那个——
17:37
you know code and public aspect is really really the common issue yeah as you're speaking about
你知道的,代码和公开方面真的是非常非常常见的问题,对,就像你正在说的那样。
17:45
uh your concerns and challenges i'm looking at cow.com's open source repository
嗯,你的担忧和挑战,我正在看cow.com的开源仓库。
17:51
get.com slash cow.com slash cow.com and i'm on the port requests tab and you can probably see
get.com斜杠cow.com斜杠cow.com,我现在在port requests这个标签页上,你们大概能看到。
17:59
there's just an immense i mean more than you would probably ever want to or be able to
这简直是巨大的,我是说,远超你可能想要或能够处理的量。
18:06
no there's no chance there's there's no chance we'll get to the bottom of this it's just
不,没戏,绝对没戏,我们不可能把这事儿彻底搞明白,就是
18:11
so it's um well and and this also hurts the community right like people expect to get the same
所以呢,嗯,而且这也伤害了整个社区,对吧?大家会期待得到同样级别的对待——比如有人提个“嘿,云平台,麻烦修一下issue 115”,跟那种投入了大量深度知识、时间和资源去改进东西、觉得自己做的东西值得被合并的人,得到的待遇是一样的。所以这几乎就像,嗯,怎么形容最贴切呢?最好的说法就是,这就像大规模宣传,你你你就
18:18
level of treatment for like a one nine hey cloud please fix issue one one five yeah then someone who's
哇,他们是从哪儿冒出来的?然后你会想单独联系这些人,跟他们说,天哪,太感谢你贡献了,这阵子真的超开心
18:24
investing deep knowledge and and time and resources into making something better that they feel
将深厚的知识、时间和资源投入到他们觉得值得改进的事情上
18:32
deserves to be merged so it's like it's almost like um how would you describe this best like
这应该被合并起来,所以它就像是,嗯,该怎么形容这个最贴切呢?
18:40
the best way it's it's like it's like mass propaganda where you where you where you just
最好的方式就是,它就像,它就像大规模宣传,你只要,你只要,你只要
18:45
post so much misinformation that it's just impossible to know what's the truth and what's not because
发那么多 misinformation,让你根本没法分辨什么是真的、什么是假的,因为
18:51
you're just drowning in the sea of everything's fake and then the reality just gets murky right
你整个人淹没在“一切都是假的”的海洋里,现实就变得越来越模糊,对吧
18:56
and the same with porn with us like you just don't know what's good anymore when everything looks
色情内容也一样,对我们来说,当所有东西看起来都差不多的时候,你根本不知道什么是好的了
19:01
equally good and then there's like a stellar PR and then the rest is just uh two line prompts from
偶尔会有一个超棒的 PR,剩下的就只是从 cloud 上来的两行 prompt,
19:10
cloud you know so it's like it's really tough like i it's it's i i don't envy any i don't even envy
你知道吧。所以这真的很难。我……我谁也不羡慕,我甚至不羡慕
19:17
freemium open source maintainers who back in the days would be happy you would be happy for
freemium 的 open source 维护者们。以前他们会很开心,你会为每一个
19:22
every pull request that would come in you would be heck yeah like some issues must have they think
进来的 pull request 感到兴奋,你会说“太棒了!”就像有些 issue,他们肯定会想
19:28
something i could change it yeah let's do it when when when we first had a conversation we
“这个东西我可以改啊,好啊,来吧。”当我们第一次、第一次第一次聊天的时候,我们……
19:32
probably had 20 open pull requests and then when you had like suddenly you had five more you'd be
可能本来有20个 open pull requests,然后突然又多了五个,你就会想,哇,这些是从哪儿冒出来的?然后你就会去联系这些人,一个个跟他们说,天哪,真的太感谢你来贡献了,这整个过程特别棒,等等等等。所以就是,嗯,这也让我很痛心,因为还有一个问题,就是人们现在面对的——他们觉得自己如果能拿出 open source contributions,就更容易被录用。所以现在他们的整套 pipeline 就是:先找 top 10 repositories,再 orchestrate 12 个不同的 agents,让它们全都去找不同的 issues。基本上,Claude 的 instruction 就是找最 upvoted 的 issue。
19:37
like whoa where did they come from and and you would like reach out to these people and be like
哇,这些人是从哪儿冒出来的?然后你就会想联系这些人,然后说——
19:42
individually like oh my god thank you so much for you know contributing this has been a blast
就像是在说,天哪,太感谢你了,你知道的,能参与进来真的太棒了
19:46
etc etc so it's like yeah it's um and it's and it pains me because also there's um this is
等等等等,所以就是,嗯,它让我挺难受的,因为还有另一个问题,就是大家现在觉得,如果能展示开源贡献,就更容易被录用。所以现在他们的整个流程就变成了——让我找top 10的仓库,让我编排12个不同的agent,然后它们全都试着去找不同的问题,基本上那个clawed的指令就是“找到被上传最多的问题”,然后提交一个PR。这五个不同的……这几乎就像你在把自己的CV海投给几百家公司,顺便说一句这也是个非常糟糕的策略,然后指望其中一家能中。然后你的AI agent回来跟你说,“哦我已经开了20个不同的……”
19:54
another problem that um people are facing that they think they are more likely to get hired if
另一个问题是,嗯,人们面临的一个情况是,他们觉得自己更有可能被录用,如果——
19:59
they can show open source contributions so now they their entire pipeline is let me find the
他们可以展示开源贡献,所以现在他们的整个流程就是让我找到那个
20:06
top 10 repositories let me orchestrate 12 different agents and they all try to find different issues
前10个仓库让我编排了12个不同的agent,它们都试着去找不同的问题
20:13
like basically the the clawed instruction is find the most uploaded issue
基本上,clawed的指令就是找到上传次数最多的问题。
20:19
and then submit a PR and these five different it's almost like you're spamming your your CV which
然后提交一个PR,这五种不同的东西,感觉就像你在刷自己的简历一样。
20:25
is also really terrible strategy by the way into like hundreds of companies and trying to
顺便说一句,这也真的是很糟糕的策略——分散到几百家公司里,然后试图……
20:30
hope one of them sticks and then your AI agent comes back with like oh i've opened 20 different
希望其中有一个能奏效,然后你的AI agent回来跟你说,哦,我已经打开了20个不同的
20:35
pull requests in these in these in these different repositories does that make you more likely
在这些不同的仓库里发pull requests,会让你更容易被录用吗?我不知道,所以这挺怪的,现在真的是个很怪的时代。我不是说这有什么,就是……挺怪的,真的很怪。我们真的在挣扎,真的在挣扎。是啊,我是说——等等,我还没说那个数字,所以你有358个pull requests,不对,抱歉,356个。嗯,那其实也挺多的,就算是358也很多,我是说就多了两个,但还是很多。556和358之间有个很大的戏剧性差距,但那个数量的pull requests真的很夸张。如果那是我的pull requests收件箱,我就会直接说收件箱清零,然后直接取消掉。对啊,我是说,不,就……或者干脆把PR那个标签页整个关掉,我觉得这样也行。
20:39
to get hired i don't know so it's weird it's a really weird time i'm i'm not saying there's uh this is
要找到工作我也不知道,所以这很奇怪,现在真的是个很奇怪的时期。我不是说这有什么——
20:49
it's it's weird i it's weird we are really struggling we're really struggling yeah well i mean
这真的很奇怪,我们确实在苦苦挣扎,真的在苦苦挣扎。是啊,我是说——
20:56
so let me i didn't say the number so you've got 358 pull requests no sorry 356 yes
所以让我说下数字——你有358个pull requests,不对,抱歉,是356个。
21:04
um and that's still a lot even 358 is i mean it's two more it's a lot another big
嗯,那仍然很多,即便是358,我的意思是,也就多了两个,但还是很多,另一个大问题。
21:10
dramatic difference there between 556 and 358 but that's a that's a dramatic amount of
556和358之间的差异非常显著,但那可是一个巨大的量。
21:16
four requests if that were my pull requests inbox i would just say inbox zero at and just cancel it
如果那是我的pull requests收件箱,我会直接说收件箱清零,然后把它关掉。
21:23
right i mean no get yeah or or just literally cancel the PR tab altogether which i think
对,我的意思是,不,你说得对,或者干脆直接把PR标签整个取消掉,我觉得这样也行。
21:32
is kind of what i was mentioning before Adam Jacob his his philosophy was swamp that club
这其实就跟我之前提到的Adam Jacob的理念差不多,他的理念就是“swamp the club”,就是那个swamp.club,超酷的东西,你们真该去看看。他们就是那种“算了,我们不搞了”的态度。我觉得他们的问题不在于PR的数量,甚至不在于那些PR很可能就是AI生成的垃圾内容,而更像是——我们知道我们在做什么,我们知道自己想做什么,我们很乐意接受你的想法,但我们就是不要你的代码。我们要的是我们自己会写的那种代码,符合我们风格的代码,我们的工程师能去筛选,不管是用agent还是什么,它得符合我们的风格,符合我们的行话,跟上我们的节奏,解决我们认为值得解决的问题。
21:37
and that is the or else swamp dot club it's the coolest thing never and you guys check it out um
这就是那个“否则沼泽俱乐部”,它是有史以来最酷的东西,你们快去看看吧。
21:43
they're just like forget it we're not going to do it you know and there i don't think they're
他们就是那种“算了,我们不干了”的态度,你懂的,而且我觉得他们并不是……
21:47
their problem was the amount of pull requests or even the pull requests that would be or likely
他们的问题是pull request的数量,甚至那些可能是或很可能是pull request的东西。
21:53
be AI slop it was more like we know we're building we don't we want to build we're happy to take
这更像是AI垃圾内容,我们是知道自己在做什么的,我们不是不想做,而是愿意接受。
21:58
your ideas we just don't want your code we want code that we would write that matches our style
你的想法我们只是不想要你的代码,我们想要的是我们自己会写的那种、符合我们风格的代码
22:05
of code that our engineers uh can curate whether it's with an agent or not it matches our style
我们的工程师可以筛选的代码,不管是不是通过agent来做的,它都符合我们的风格
22:13
it matches our lingo it goes in our pace it fixes our problems that we think are worth fixing
它跟我们的行话对得上,节奏也合拍,还能解决我们认为值得解决的问题。
22:17
we're happy to hear ideas we want to use swamp but it's issue-based co-contributions and you'll
我们很乐意听取大家的想法,我们想用Swamp,但它是基于问题的共同贡献,你们会把问题、挑战或解决方案以正反两面告诉我们,他们甚至可能在幕后把背景带进来,甚至可能写一个承诺,甚至可能写出启动整个旅程的初始问题。我同意,所以嗯,确实有,显然有很多开源的理由和好处,对吧?有些东西就是必须开源,React.js必须开源,JavaScript必须开源,Python必须开源,就是为了能跑起来。Carot.com倒不一定非要开源,对吧?所以我们开源有很多不同的原因,但为了运行它,那并不是开源的唯一理由。
22:24
give us the problem or the challenge or the solution in in pros and they may even bring that
给我们讲讲问题、挑战或解决方案,他们甚至可能会把那套思路带进来。
22:31
into context behind the scenes and they may even write a promise and they may even write the the
进入幕后的背景信息,他们甚至可能会写下一个承诺,甚至可能会写下那个……
22:36
initial problem that that starts the journey i agree so um it's uh there there are clearly um there's
最初的问题开启了这段旅程,我同意,所以嗯,显然有,嗯,有——
22:44
multiple reasons and benefits to be open source right like something simply have to be open source
开源有很多原因和好处,对吧,有些东西就是必须得开源。
22:49
react j as has to be open source java script has to be open source python has to be open source
React J作为框架必须是开源的,JavaScript必须是开源的,Python也必须是开源的。
22:54
just to run the thing carot com necessarily doesn't have to be open source right so we've been
只是为了运行这个东西,carot com 不一定要开源,对吧,所以我们一直在
23:03
open source for many different reasons but but to in order to run it that's not all the open source
开源有很多不同的原因,但为了运行它,那并不是开源的的全部。
23:11
right we're not a java script framework we're not a UI library so for us the the the the the
对,我们不是JavaScript框架,也不是UI库。所以对我们来说,卖点和想法一直都是——公开开发、建立信任、把东西做出来。还有一点,就是做出最安全的代码库。因为我觉得,直到1月26号之前,我都会说开源永远比闭源更安全,我以前是坚持这个观点的。但问题就在今天,我不再这么认为了。对吧,所以这个钟摆已经摆过去了。你知道,如果开源很安全的话,那是因为——当你开源的时候,有安全研究员会提交非常好的PR,修复漏洞、报告漏洞,那时候存在一种报告文化。但这种报告文化已经不存在了,我们现在收到的报告99%都是AI生成的。
23:18
pitch and the idea was always like build in public build trust build them and another thing build
推销和这个想法一直是——公开构建,建立信任,构建它们,还有另一件事,构建。
23:24
them most secure code base because i would say up until january 26 i would say open source is always
他们最安全的代码库,因为我会说直到1月26号之前,开源始终是……
23:35
more secure than close source like i would stand by that statement and that's the problem today
比闭源更安全——我坚持这个说法,而这就是今天的问题所在。
23:41
i no longer think that right so like the pendulum has swung you know if this is like very safe
我不再这么认为了,所以就像钟摆已经摆过去了,你知道,如果这非常安全的话。
23:49
open source because bear might when you were open source you had security researchers making
开源是因为熊可能会——当你开源时,会有安全研究人员来帮你做这件事。
23:55
really good PRs fixing the holes fixing vulnerabilities reporting vulnerabilities that there was a
真的很好的PR,修复漏洞、报告漏洞,确实有这种情况。
24:01
reporting culture the reporting culture no longer exists 99% of the reporting we get our AI generated
报告文化——报告文化已经不存在了。我们收到的报告99%都是AI生成的。
24:08
like we have an inbox security at cal.com that people send vulnerabilities and 99% of them are
比如我们在 cal.com 有一个收件箱安全机制,人们会提交漏洞,其中 99% 都是 AI 生成的,包括发那封邮件的本身,因为大家都在往仓库里刷垃圾信息,而且那些漏洞里有一半也是幻觉,就是根本不存在,你去复现一下发现根本没有,或者它搞错了,用了错误的 API 和调用点。所以开源这种文化反而让你更安全,因为你有非常优秀的人,这些人真的很聪明,他们现在会去执行那些攻击。也许不是针对云,因为云有那么多安全特性,但现在确实有一些大语言模型,它们在渗透测试方面非常强,说实话云安全方面也很强。
24:15
AI generated like including that email that sends it because people are spamming repositories
AI生成的,包括那封邮件之所以会发出去,是因为人们在刷仓库。
24:23
and and half of those vulnerabilities are also hallucinated like they just simply don't exist
而且那些漏洞里有一半也是幻觉,根本就是不存在的东西。
24:28
you you reproduce it and it's not there or it it it got something wrong and it's using the wrong
你复现它,结果它不在那儿,或者它出了错,用了错误的东西。
24:34
API and point and so the culture of like open source makes you more secure because you have
API和point,所以那种开源文化让你更安全,因为你有了——
24:42
actual human beings who know what they're doing checking your code base has kind of formed behind
真正懂行的人来检查你的 code base,这件事某种程度上已经被甩在后面了
24:47
and then at the same time so that's gone and then at the same time the autonomous attack
然后与此同时,这个已经没了;与此同时,autonomous attack
24:54
attacking tools i've gotten so good that the amount of knowledge needed to attack a repository
攻击工具已经变得太强了,以至于要攻击一个 repository 所需的知识量
25:05
is basically can you run a shell command in your terminal right so like
基本上就是——你会不会在 terminal 里跑一条 shell command?对吧,所以
25:11
we went from pen testing requires crazy amounts of tooling and knowledge and reverse engineering
我们以前做 pen testing,需要极其大量的 tooling、知识,还要 reverse engineering
25:19
of APIs and and and and man in the middle attacks and yeah yeah yeah like so much work had to go in into
要去搞 APIs,还要弄 man-in-the-middle attacks,对对对,就是得投入巨多的功夫
25:26
basically finding an abusing vulnerability let's say you're a black hat hacker right like
基本上才能找到一个 vulnerability 然后利用它。假设你是个 black hat hacker,对吧
25:31
let's say you are an evil person you want to extort people it was really hard you had to be
假设你是个坏人,想敲诈勒索别人,那真的很难,你得
25:36
really good these are really smart people who would execute those attacks nowadays
真的很好,这些人现在都是非常聪明的家伙,他们会执行那些攻击。
25:44
maybe not with cloud because of all the security features but there are large language models out
也许不会用云端,因为涉及所有安全功能,但确实有大型语言模型存在
25:48
there that are so good at pen and pen testing and and well cloud security to be honest of their
他们在渗透测试方面非常出色,而且说实话,云安全方面也很强。
25:54
product that it's really easy to find dormant vulnerabilities like Firefox had like 12 p0
这种产品特别容易发现潜在漏洞,比如Firefox之前有12个p0漏洞,都是AI报告出来的,React React React也有AI发现的漏洞,Next.js也有不少AI报告的漏洞。所以我们现在真的麻烦了,我不是说我们工程团队在AI之前就完美无缺,显然这不是AI代码和AI之前代码的对比,但用来发现和利用漏洞的钱、资源和人才,在易用性上大概提升了一百倍。也就是说,基本上坏人只要在终端里敲一条提示词,就能找到并滥用开源仓库。所以整个“我们开源所以我们更安全”的论调,已经完全倒向另一边了。
26:05
vulnerabilities reported by AI react react react have vulnerabilities found by AI next JS had its
AI react react react报告了漏洞,AI发现的漏洞,next JS也有它的漏洞。
26:12
own fair shares of vulnerabilities reported by AI so it's like we're really in trouble because
AI自身也报告了不少漏洞,所以看起来我们真的麻烦了,因为——
26:20
I'm not saying our engineering team is flawless from pre AI like obviously this is not AI versus
我不是说我们的工程团队在AI之前就完美无缺,显然这不是AI与非AI的对立。
26:26
pre AI code but the amount of money resources and talent through find and abuse vulnerabilities
前AI时代的代码,但要投入大量的资金、资源和人才去发现和利用漏洞
26:36
has like a hundred acts in terms of ease of use right and so you're getting basically evil people
在易用性方面大概有一百个层级,对吧?所以你基本上是在培养邪恶的人。
26:44
at a single prompt in their terminal to find an abuse open source repositories so the whole
只需在终端里输入一条命令,就能发现滥用开源代码库的问题,整个过程就是这样。
26:51
pendulum of like oh we open source we're more secure it has completely swung in the other direction
钟摆已经完全摆向了另一个方向,比如“我们开源,我们更安全”这种说法。
26:56
where it's like wow this is so easy to hack any open source repository my theory is that the majority
就是那种“哇,这开源仓库也太好黑了吧”的感觉。我的理论是,现在大多数开源仓库其实都已经被攻破了,只是我们还没发现而已。
27:03
of open source repositories are compromised right now we just don't know yet
就像Firefox说的,一个Firefox有12个P0漏洞,你觉得你自己的开源仓库能好到哪去?是啊,说起来好笑,但其实真的很严峻。
27:08
like a firefox says to a firefox a firefox is 12 p0 vulnerabilities like what do you think your
所以我们刚才聊到的,最近的一个案例就是LightLLM,被供应链攻击给搞了。那个案例还挺特别的,它的执行方式很恶意,但攻击者是怎么进去的其实很有意思——背后的社会工程学,或者说他们是怎么拿到密钥之类的,然后利用正规的CI/CD管道来达成目的。
27:16
open source repositories looking like you know yeah that's funny it's not it's really grim so yeah
开源仓库看起来,你懂的,嗯,挺搞笑的,但其实不是,真的挺惨的,所以就这样吧。
27:25
we just had that you know one of the more recent ones was light LLM
我们刚才提到,你知道,最近的一个例子就是Light LLM。
27:31
it was compromised by supply chain attack I mean that was even more unique one was malicious in how
它遭到了供应链攻击,我是说那个甚至更特别,一个是恶意的。
27:37
I executed it but how they got there was really interesting you know the social engineering behind it
我执行了,但他们是怎么走到那一步的,真的很有意思,你知道,背后的社会工程学。
27:43
or even just getting the keys and stuff like that and using the the blessed pipeline to get the
或者甚至只是拿到密钥之类的,然后用那个现成的pipeline来获取结果。
27:48
thing in the pie pie you know that was really interesting and we're seeing that more and more
那个饼里的东西,你懂的,那真的很有意思,而且我们越来越常看到这种情况。因为一直都有漏洞嘛,我知道你想说什么,一直都有漏洞,而且这不是那种“以前有、现在没有”的问题。不,现在的问题是,执行层面的漏洞效率高太多了,对吧?没错,现在工具分配得更均匀了,所以知识图谱某种程度上已经下放到每个人手里,只要是生活在某种第一世界环境里的人,都能接触到那些全球最大公司里最顶尖工程师在用的同一个工具,对吧?我们都在用类似甚至相同的工具版本,所以知识图谱被大幅压平了。你说得对,现在那些坏人也拥有了同样的东西。
27:54
and more because there's always been holes right I know what you're trying to say too there's
而且还不止这些,因为一直都有漏洞,对吧——我也知道你想说什么了。
27:57
there's always been holes and it's not you know a then versus not kind of thing no it's that now the
一直以来都有漏洞,而且这不是那种“以前有、现在没有”的情况——不,是现在这漏洞变得更明显了。
28:02
holes execution layers so much more efficient yeah right well the tool is now more evenly distributed
执行层效率高太多了,对,没错,现在工具分配得更均匀了。
28:09
so the knowledge graph has kind of come down to every human being that is in some sort of first world
所以知识图谱这个概念,最终就归结到了每一个生活在某种第一世界里的普通人身上。
28:16
scenario that can afford 20 bucks a month maybe even the free version of it that is the same
那种每月能负担20美元的场景,甚至可能用免费版,也能访问到同一个工具——全球最大的公司里那些最顶尖工程师们正在用的,就是同一个工具。我们全都在用同一个或类似版本的同一类工具,所以这个 knowledge graph 已经急剧扁平化了。你说得对,坏家伙们现在也有了同样的东西。而且他们不只有同样的东西,这个工具还比我们以前任何时候能写的 script 都快。我们以前也一直能写 script,那些东西一直都在;当然,在给定的 CPU 上,它确实一直很快。但现在,写出它、渗透进去、然后直接对 security 做 pen test 的能力——security、security,security researchers 管这叫 vibe hacking,因为你不再……
28:21
access to the same tool that the world's greatest engineers at some of the biggest companies are
能够使用与世界顶级工程师在那些大公司里所使用的相同工具
28:26
using right there we're all using a version of the similar and same tool and so the knowledge
就在那里,我们都在用同一个类似工具的不同版本,所以这些知识
28:30
graph has kind of flattened dramatically and you're right the bad actors now have the same thing
图表增长已经大幅趋于平缓,你说得对,现在那些恶意行为者也拥有了同样的东西。
28:36
and not only do they have the same thing it's a faster tool than we've ever been able to script
而且他们不仅拥有同样的能力,而且这个工具比我们以前能写脚本的速度还要快。以前我们一直都能写脚本,它一直都在那儿,而且当然在给定的CPU上它一直很快,但现在,能够编写它、渗透进去,然后直接做渗透测试——安全、安全、安全研究人员把这叫做“vibe hacking”,因为你不再知道自己到底在干什么,你基本上就是在用跟“vibe coding”一样的方式去指挥那个agent。现在呢,好像每个人的邻居都在用vibe coding写他们的iOS应用,顺便说一句,这挺好的,让技术获取变得民主化了,五大巨头也一样。但问题是,当同样的情况发生——比如妈妈在vibe coding一个iOS应用,而她16岁的儿子在vibe hacking的时候,会发生什么?
28:41
before we've always been able to script back there's always been there and sure it's always been
之前我们总是能编写脚本,背后总有东西在,当然它一直都在。
28:46
fast on the given CPU but now the ability to write it and infiltrate and to just
在给定的CPU上很快,但现在写它、渗透进去,以及只是
28:54
pen test security security security researchers call this vibe hacking because you're no longer
渗透测试 安全 安全 安全研究员们管这叫vibe hacking,因为你不再
29:00
knowing what you're doing like you're literally just instructing the agent the same way you have
知道自己在做什么,就像你只是在用同样的方式指示那个agent一样
29:04
vibe coding and now like everyone's everyone's neighbor is vibe coding their iOS apps which by the
vibe coding 现在就像,每个人、每个人的邻居都在用 vibe coding 做他们的 iOS 应用,这玩意儿吧——
29:10
way is great like democratizing access to technology big five but like what happens when the same
这种方式很棒,像是让技术获取民主化,五大巨头那种,但问题是,当同样的事情发生时,会怎样?
29:18
like when the mother is vibe coding an iOS app and then the 16 year old son is vibe hacking
比如妈妈在用vibe coding写一个iOS应用,然后她16岁的儿子在搞vibe hacking
29:24
the power station nearby right like that's not great so the yeah is this that correctly like the
附近的发电站,对吧,那种不太行。所以,嗯,这个对吗?就是那个。
29:31
the access to technology also means that like malicious hackers have like they are so happy about
技术的普及也意味着,像恶意黑客,他们对此简直高兴坏了,对吧?这就像一份生日礼物。你说“什么意思?我不……”——我不需要再花16个小时去研究代码库了,我直接让AI来搞。
29:38
all of this right they it's it's like a birthday present like what do you what do you mean I don't
如果你运营一个开源的免费GitHub项目,哪怕你跑的是OpenClaw,像OpenClaw并没有一个卖给财富500强的企业版,跑在同一个代码库上。就算他们有,他们大概也不会把它发布在同一个GitHub上。所以,如果你跑的是一个UI框架,或者一个库,我不知道,帮你处理时区的那种,然后你……
29:43
I no longer need to you know do spend 16 hours studying the code base I can just have an AI
我不再需要花16个小时去研究代码库了,我直接让AI来做就行。
29:49
find all the holes for me that's awesome here's my bitcoin address pay me money otherwise
帮我找出所有漏洞吧,那太棒了。
29:54
I publish your data on the dark web like you who yay that's great and even that is probably fully
这是我的bitcoin地址,给我付钱,否则
30:02
autonomously executed including sending the email and opening the wallet and checking whether
我就把你的数据发布到dark web上,像你一样,哇,耶,那太好了。
30:07
the funds got received and yeah this is it's a great it's a great situation right here it's a great
而且那甚至很可能是完全自主执行的,包括发送email、打开wallet,以及检查资金是否到账。
30:14
you seem very grim and not very excited about the future of open source would you would you agree
然后对,这是个——这是个很棒的——这是个很棒的处境,就在这儿——这是个很……
30:21
so I think I think I would I would probably summarize this like if you run a commercial open source
你看起来很悲观,而且对open source的未来并不太兴奋,你同意吗?
30:29
business you have a huge target on your head because you are a business and a business means
所以我想——我想我会——我大概会这样总结:如果你运营一个商业open source公司
30:34
you have customers and the customers mean you have sensitive data and you can potentially be
你脑袋上顶着一个巨大的靶子,因为你是个商业公司,而商业公司意味着你有客户
30:39
extorted if you run an open source free GitHub project even if you run open claw like open claw
如果你运营一个开源的免费GitHub项目,哪怕你跑的是像OpenClaw这样的开源项目,也会被勒索。
30:46
does not have an enterprise edition that they sell to fortune 500 that runs on the same code base
没有面向财富500强销售的企业版,而且跑在同一个代码库上
30:52
even if they had to they were probably not publish it on the same GitHub you go so it's like if you
就算他们不得不发,大概也不会发在你去的那个GitHub上,所以就像,如果你……
30:57
run a UI framework a library that I don't know helps you work with time zones and like you
运行一个UI框架,一个我不太了解的库,它能帮你处理时区之类的问题。
31:05
find like stay open source well unless you find you accidentally import an NPM package that
像保持开源就挺好的,除非你不小心引入了一个NPM包,直接把整个项目给搞垮了——这种事肯定会发生的,所以那显然是另一个攻击向量。但说实话,今天任何一家企业,只要有个开源项目,咱们就这么说吧,任何开源项目最终要是碰了数据库调用,那你就麻烦了。我这么说是在经历了五个私有项目、把所有涉及数据库和加密的东西都重写了一遍之后才得出的结论,这也是我们现在在做的事。就像Colab那样,这算是一个很大的变动,我们在幕后已经做了相当长一段时间了。基本上从4月15号开始,我们要把商业版转为私有,社区版仍然完全开源,你可以自己用,风险自负。
31:12
completely compromises your project which will happen so that's another attack vector obviously
这完全会毁掉你的项目,这种事迟早会发生,所以那显然是另一个攻击途径。
31:17
but like but any business today that has an open source let's call it this way any open source
但是,如今任何一家拥有开源——我们姑且这么叫吧——任何开源业务的公司,
31:24
project that eventually makes a database call you are in trouble and I'm saying this after five
最终要调用数据库的项目,你就麻烦了——我这话是吃了五次亏之后才说的。
31:33
years of being open source and 15 years in the industry you should probably take your project
做了这么多年 open source,在行业里也 15 年了,那你大概应该把项目转成 private,把所有跟 database 和 encryption 沾边的部分都重写一遍——这正是我们现在在做的事。作为 Cal.com,这是一个很大的变动,我们在幕后其实已经做了相当长一段时间,但基本上从 4 月 15 号开始,我们要把 commercial version 转成 private。所以我们仍然会有完全 open source 的 community version,你可以自负风险地使用,可以 self-host,也可以跑在你自己控制的 infrastructure 上,最好是在很多 firewalls 后面。但是跑在 app.cal.com 上的同一套 codebase,以后就不再公开可访问了,因为对我们来说风险太大了。我们确实对 open source 有 commitment,但我们对每一个……也有 commitment。
31:38
private and rewrite everything that touches off database and encryption which is what we're doing
私有化并重写所有涉及数据库和加密的部分,这正是我们正在做的。
31:47
now as color come like this has been a big change we've been doing this under the hood for quite
现在颜色变成这样,这算是个大变化,我们其实在幕后已经做了挺久了。
31:54
some time but basically starting 15th of April we're taking the commercial version private so we
有一段时间了,但基本上从4月15号开始,我们要把商业版转为私有。
32:01
still have the community version fully open source you can use it at your own risk you can
社区版仍然是完全开源的,你可以自行承担风险使用它。
32:05
self hosted you can run it on your own infrastructure ideally behind many firewalls but the same code
自托管的话,你可以跑在自己的基础设施上,最好放在很多防火墙后面,但跑在app.cal.com上的同一套代码将不再公开可访问,因为对我们来说风险太大了。我们既承诺开源,也承诺对每一个客户负责,而且鉴于现在这种大环境的变化,风险收益比真的不太划算了。是的,这就是这个改变的原因,我理解这个改变是基于什么做出的,但这是因为现在对漏洞的可见度更高了,因为工具变得更好更快了,这是不是改变的核心原因之一?我们跟一些安全研究员聊过,我们有好几个这样的合作者,当然也有那些在帮你的好人。
32:13
base that runs on app.cal.com will no longer be publicly accessible because it's just it's too risky
运行在app.cal.com上的base将不再对外公开访问,因为风险太大了。
32:18
for us like we have we have a commitment to open source but we also have a commitment to every single
对我们来说,我们承诺开源,但我们也对每一个单独的……
32:23
of our customers and given this like pandalam swing which is that the risk reward ratio just really
我们的客户,考虑到这种像钟摆一样的摇摆,风险回报比确实非常……
32:29
songs yeah is this is that the change and I understand what the change is predicated on but is it
歌曲,是的,这是那个变化,我理解这个变化是基于什么前提的,但它是……
32:38
because the visibility into the flaws are more visible now because the tool is better and faster
因为现在工具更好、更快了,所以对缺陷的可见度也更高了。
32:46
is that the kind of the one of the kind of core reasons to change so the security researchers we
这是改变的核心原因之一吗,所以那些安全研究人员我们
32:51
spoke to right we have a couple of those and and obviously there's also the good people helping you
我们跟右边那位聊过,我们有几个这样的,当然也有好心人在帮你。
32:57
with providing tools to find vulnerabilities before the black hackers but everybody says if you
通过提供工具来发现漏洞,赶在黑帽黑客之前,但每个人都说如果你有一个开源报告,你被黑的难度比闭源仓库要容易五到十倍,对吧?所以想想五到十倍,这不是10%到15%那种差距,是五到十倍。基本上你需要去猜和逆向工程,比如你调用一个API endpoint,我们试着猜它们,它是干什么的,我怎么攻击它。有了开源,你直接看到后端,看到函数调用,看到这是不是IDOR,或者有没有别的什么,比如有没有办法注入脚本之类的。而且再说一遍,在AI之前,你得花八小时、十六小时、二十小时去研究和学习每一个函数调用,然后才能找到漏洞。
33:04
have an open source report you're like five to ten times easier to to hack than a closed source
有一个开源报告说,开源的东西比闭源的容易黑五到十倍。
33:10
repository right so think about a five to ten times it's not like 10 15% is like five to ten times
仓库对吧,想想看是五到十倍,不是那种10%到15%的提升,而是五到十倍。
33:18
that's a big delta and so the reason it's so much easier is it's called black box hacking like you
那是个很大的 delta,所以之所以容易得多,是因为这叫 black box hacking。你基本上需要去猜、去 reverse engineer,比如你调用一个 API endpoint,我们就试着去猜它到底是干嘛的,我怎么攻击它。而在 open source 的情况下,你真的能看到后台,看到 function call,看到这是不是一个 IDOR,或者有没有别的东西是我可以——你懂的——有没有办法注入 script 之类的。而且 pre-AI 的时候,你得花 8 小时、16 小时、20 小时去研究和分析每一个 function call,手动去发现这些东西,这就是好的 security researchers 会做的事,他们会因此拿到 bounty。而现在则是 black hat hackers 在做同样的事,而且很遗憾地说,通常如此。
33:26
basically need to guess and reverse engineer like you call an API endpoint we try to
基本上就是得靠猜和逆向工程,就像你调用一个API端点一样,我们得试着去搞明白。
33:31
guess them at like what does it do how could I attack this with open source you literally see the
你可以猜猜它们大概是干什么的,我怎么用开源的方式去攻击它,你简直能亲眼看到
33:37
back then you see the function call you see is this an IDOR or is whatever is there something else that
那时候你看那个函数调用,你会想这是不是个IDOR,还是说里头其实还有别的东西。
33:45
I can like you know is there a way I can inject the script or whatever and again pre AI you would
我是说,你知道的,有没有办法让我注入脚本之类的,而且在AI出现之前,你也会
33:55
need to spend eight 16 20 hours to research and study every single function call and find
需要花八到十六甚至二十个小时去研究和学习每一个函数调用,然后找出
34:01
these things you know manually and that's what what good security researchers would do and they
这些东西你手动就能做,好的安全研究员就是这么干的,然后拿赏金。现在呢,黑帽子黑客也这么干了。而且说实话,聪明的白帽黑客通常比那些脚本小子更快更好——那些脚本小子就想着骗你点比特币。这是事实,一直都是事实,对吧?一个值得尊敬的安全研究员,白帽黑客,给你提交漏洞拿赏金,永远比某个坐在随便哪个厨房里瞎搞的蠢货聪明,这从来就是事实。但现在有了AI,这就不重要了,因为两边都只是输入同样的prompt,说“最终漏洞在这里、那里、那个仓库里”,然后跑同一个prompt,你猜怎么着?
34:06
would get a bounty for and now that's what black hackers would do and typically speaking sorry to say
以前会有人为此拿赏金,而现在那就是黑帽黑客会干的事——不过通常来说,抱歉这么说。
34:13
this the smart ethical hackers are faster and better than the script keys which is want to
这里的智能道德黑客比脚本小子更快、更好,而脚本小子正是我们想要的。
34:20
store you some Bitcoin that's just facts that's always been facts right like an honorable security
给你存点Bitcoin,这就是事实,一直都是事实,对吧,就像一种honorable security。
34:26
researcher who's a white hacker who gives you bounties is always more intelligent than some
专门做白帽黑客并给你发赏金的研究员,总是比某些人更聪明。
34:32
dumbass sitting in some random kitchen hacking yourself right that's just always facts
某个傻逼坐在随便哪个厨房里瞎折腾自己,那本来就是铁一般的事实。
34:37
but now again with AI it doesn't matter because both are just putting the same prompt
但现在有了AI,这又无所谓了,因为两者都只是输入同样的prompt。
34:43
final vulnerability in this and this and that repository and run the same prompt and and guess what
最终漏洞在这个和那个仓库里,运行同样的提示词,然后你猜怎么着
34:48
the black had black had hackers usually fast because they have an incentive right they have an immediate
黑帽黑客通常动作很快,因为他们有动机,对吧?他们有即时的勒索动机,去入侵和敲诈,那是个大问题。所以是的,我可能会今天就开工,或者昨天就开工,把所有那些东西都设为私有,不值得冒那个险,直到整个钟摆摆回安全那边——这可能会发生,也可能不会,就是,我们真的不知道。好了朋友们,我身边这位是Build Kite的CTO,现代软件开发时代最具挑战性的问题之一就是持续集成和持续交付。所以,Lockland Donald,Build Kite的CTO,你今天在想些什么?关于现在的团队、他们面临的挑战、他们开发新东西的速度。
34:54
extortion and incentive to to hack and blackmail that's a big problem right so yeah I would be
敲诈勒索,以及黑客攻击和勒索的动机,这是个很大的问题,对吧?所以是的,我会
35:03
really cautious if you have a repository that has a database that has customers in that database
如果你的 repository 里有一个 database,里面有客户数据,那真的要非常谨慎。
35:10
to run that out in public and that doesn't mean you should you should like close your open source
把它公开出去,并不表示你就应该关掉你的 open source。
35:17
we're not shutting down our repository I mean hack it's it's an amazing piece of
我们不是要关闭我们的 repository,我是说,它真的是一段非常棒的 software,
35:21
software that we've published but it just means that you need to internally fork your existing code
我们把它发布了出来,但这只意味着你需要内部 fork 你现有的代码,
35:30
and just make sure that you just rewrite every single function call that is vulnerable like that is
并且要确保你重写每一个有漏洞的 function call,就是那种容易
35:39
you know hackable you know don't care about some random front and library that's fine like a drag
被 hack 的调用。不用担心某个随意的 frontend library,没问题,比如一个 drag-and-drop 组件,
35:44
and drop component keep that but like the way you do all the way you do database calls the way
留着它就好。但问题是你是怎么做 database calls 的,
35:49
it may be you can rewrite your your entire middle layer and the in prisma calls everything like
也许你可以重写你整个 middle layer,还有 Prisma calls 之类的。
35:56
probably like start today or start yesterday and take all of that private it's just not worth the
大概今天开始或者昨天开始,然后把所有那些私有的东西都拿掉,真不值得。
36:02
risk until that whole pendulum swings back into security which you know could happen could have could
这种风险会一直存在,直到整个钟摆重新摆回安全那一端——你知道的,这种情况有可能发生,也有可能已经发生过。
36:10
also not happen it's just it's it's yeah we don't know we really know well friends I'm here with
也不会发生,就是,嗯,我们真的不知道。好了朋友们,今天和我一起的是——
36:20
the CTO of build kite and one of the most challenging problems of modern era software development
Build Kite的CTO,以及现代软件开发时代最具挑战性的问题之一
36:27
is continuous integration and continuous delivery and so lockland Donald build kite CTO what are you
持续集成和持续交付,所以,Lockland Donald,Build Kite的CTO,你怎么看?
36:34
thinking about today's teams the challenges they face the speeds at which they're developing new
思考一下如今的团队、他们面临的挑战,以及他们开发新东西的速度。
36:41
features new code it is just overwhelming how do you all think about that such a good question is
这个新代码的特性真是让人应接不暇,你们怎么看这个问题?问得特别好,这其实是现在每个人都在问的问题,我们所有的大客户现在也都在问,就是说如果我们今年把代码量提升五倍十倍,甚至一千倍,那到底什么会崩、什么时候崩。我的回答其实跟过去二十年一直说的一样,瓶颈仍然在于怎么把这些代码改动整合进去,然后部署、验证它们能跑,再在持续堆更多代码的过程中让它们一直保持稳定。我觉得很多底层逻辑其实没变,只是速度上快了一千倍,而这就几乎改变了每一个变量。对,确实是这样。那咱们聊聊,Build Kite到底在哪个具体环节最擅长?
36:46
the question everyone's asking right now all of our big customers are asking us at the minute like
现在每个人都在问的那个问题,我们所有的大客户这会儿都在问我们,就是——
36:51
you know if we five or ten x are three put this year or a thousand exit what breaks and when
你知道的,如果我们今年把算力提升五倍或十倍,或者做到一千倍,那什么会先崩,以及什么时候崩?
36:57
and you know my answer is kind of same as it's been for the past 20 years which is that the
你知道的,我的答案跟过去20年一直以来的差不多,就是说——
37:02
bottleneck is still trying to integrate those code changes in and then deploy them and check
瓶颈仍然在于尝试整合这些代码改动,然后部署它们并进行检查。
37:08
they work and then keep them working as you keep throwing more and more code at it I think a lot
它们能正常工作,然后在你不断往里面堆更多代码的时候还能一直保持正常,我觉得这很关键。
37:13
of the fundamentals are the same but we're just a thousand x in the speed of it and you know that
基础原理是一样的,但我们只是把速度提升了一千倍,你懂的。
37:18
changes nearly every variable yeah for sure okay so we're where does build kite thrive what particular
这几乎改变了每一个变量,是的,当然。好,那我们说到哪儿了——Build Kite在哪些方面特别有优势?
37:26
type of team or enterprise do you thrive in the area that build kite is always thrived in is
你属于哪种团队或企业,你在Build Kite一直擅长的领域里能如鱼得水,那就是——世界上最快的科技公司那种类型。我们在这个小圈子里一直做得特别突出,就是Shopify那一类、Uber那一类,你知道,还有OpenAI那一类公司,它们都有一个核心问题,就是迭代速度要非常非常快。而且关于这些公司,有一点就是,它们各自的需求都微妙地不同,问题也微妙地不一样。所以我们历史上一直倾向于做那种工程上非常扎实的乐高积木块,扩展能力比我们最接近的竞争对手要高好几个数量级。所以我觉得,这就让我们的系统处在一个张力之中,因为你知道,你花在组装这些积木块上的时间,是有代价的。
37:32
is like this like fastest moving tech companies of the world's like we've been disproportionately
就像是这样的,世界上最顶尖的那些科技公司,我们其实有点被不成比例地……
37:37
successful in that small niche they're kind of Shopify class Uber class you know open AI class of
在那些小众领域里做得成功的,基本上就是Shopify那一类、Uber那一类,你懂的,还有OpenAI那一类。
37:45
fakes that have this key problem around iterating really really fast and you know the thing about all
所有这些伪造品都有一个核心问题,就是迭代速度得非常非常快,而且你知道,关于这一切的关键在于
37:50
those fakes is they all have subtly different needs subtly different problems and so we've
那些假货的问题在于,它们都有细微不同的需求、细微不同的问题,所以我们已经
37:55
tended historically towards building like really well engineered Lego blocks that scale like orders
从历史上看,我们更倾向于构建那种像精心设计的乐高积木一样、能按数量级规模扩展的模块。
38:03
of magnitude more than what our nearest competitor does so you know I think that that puts our
比我们最接近的竞争对手高出一个数量级,所以你知道,我觉得这让我们处于一个很有利的位置。
38:08
system in this tension where you know you've got a spence of time assembling those building blocks
系统在这种张力之中,你知道自己有一段时间在拼装那些积木。
38:13
that those Lego blocks to get the thing that you want but the end results is far and away
那些乐高积木拼出你想要的东西,但最终结果远远更高效、更可扩展,体验也比现成方案好得多。所以我觉得我们是从一套真正精心设计的乐高积木出发,然后反过来朝着创造一个能缩小到适合初创公司的东西努力——从一个人加十个agent开始,下周就这样。好了朋友们,去buildkite.com看看吧,buildkite.it.com,你值得拥有更好的CI工程师,面对我们共同的前沿挑战,那些定调子的团队都信任它。再说一次,buildkite.com,buildkite.com。所以,如果我没理解错的话,你刚才说的是,你们做这件事的具体机制是……
38:19
more performant and scalable and the experience is better than what you get from something that's
性能更强、扩展性更好,体验也比那种方案要好。
38:24
off the shelf so I think we've started from a position of really well engineered Lego blocks
开箱即用的,所以我觉得我们是从一个工程化得很好的乐高积木块的位置出发的。
38:29
and then are kind of working backwards towards kind of creating the thing that scales down to
然后有点像是在反向推导,试图创造出那种能缩小规模的东西。
38:34
a startup that starts with one person and 10 agents next week. Well friends go to buildkite.com
一家初创公司,下周可能就一个人加10个agent起步。朋友们,去buildkite.com看看吧。
38:41
at buildkite.it.com you deserve better CI engineer for the frontier we are all facing trusted by
在buildkite.it.com,你值得拥有更好的CI工程师,来应对我们共同面对的前沿挑战,深受信赖。
38:50
the teams setting the pace again buildkite.com once again buildkite.com
再次领跑节奏的团队,buildkite.com,再次是buildkite.com
39:02
so the way you're if I understand correctly which just said that the mechanics of how you're making
所以,如果我没理解错的话,你刚才说的是你们做这件事的具体机制是怎样的。
39:07
this change the change we understand what the change is influenced by but then on the how you're
这改变了我们对变化受什么影响的理解,但在“怎么做”这个层面,你说的是内部fork,而你的情况是商业开源公司,所以你们之前那套说辞——那套说辞现在已经不足以让客户觉得有价值了,它成了一个不必要的攻击面。但这不代表我们不再开源了,我们仍然是开源的,只是我们有一个内部fork,就像很多其他公司一样,比如WordPress.com就是WordPress.org的一个内部fork。WordPress还是用同一套插件系统,但如果你今天登录WordPress.com,体验跟拿到开源版WordPress是不一样的。所以他们某种程度上也做了那个改变,可能更多是出于商业上的考虑。
39:11
saying to internally fork and in your case your commercial open source company and so you've had
说到内部进行分支(fork),而在你的情况里,你们是一家商业开源公司,所以你已经——
39:18
all of your code out there your open source has been licensed one way but if you go a certain way
你所有的代码,你那些 open source 项目,现在是一种授权方式;但如果你走某条特定的路线,
39:23
there's certain features that were always available open and open source source available
有些功能本来一直是开放可用的,是 open source 或 source available 的形式,你能看到。
39:28
that you can see you're saying that you're changing that so that all of that code base will
你是说你会改变这一点,好让整个 code base 继续保留在那里,free open source license 也保持不变,
39:34
remain there the license of free open source will remain the same but internally your mechanism
但内在的机制是把它 fork 出来,重写那些有风险或者说风险最大的 surface areas。
39:40
is to fork it and rewrite the areas the surface areas that are at risk or at most risk yeah correct
对,没错。
39:48
and we also obviously point the production URL to the private repository right so like right
而且我们显然也会把 production URL 指向 private repository,对吧?
39:55
because you know what you see on GitHub today is what we've run on the website that's just how
因为你知道,今天你在 GitHub 上看到的东西,就是我们在网站上实际运行的东西。
40:00
open source works right that was the whole point like you see the code that runs my service that
open source 本来就是这样,对吧?重点就是你能看到运行我服务的代码。
40:05
was the whole spiel so that spiel is no longer safe enough to be valuable for your customers like
所以整套说辞的意义就在于,那套说辞对你的客户来说已经不再安全到有价值了,对吧?
40:13
it's it's an unnecessary attack vector so that doesn't mean we're no longer open source we are
这是一个不必要的攻击向量,所以这并不意味着我们不再是开源的,我们依然是。
40:19
still open source it's just that we have an internal fork the same way other many companies
仍然是开源的,只是我们有一个内部fork,很多其他公司也是这么做的。
40:25
like WordPress.com is an is an internal fork of WordPress.org I get still WordPress uses the same
就像WordPress.com是WordPress.org的一个内部fork,我明白WordPress还是用同一套东西。
40:32
plugin system but if you sign into WordPress.com today it's a different experience than if you get
插件系统,但如果你今天登录WordPress.com,体验跟你自己搞一个是不一样的。
40:37
the open source WordPress so they kind of like did that change well probably more from a commercial
开源的WordPress,所以他们算是挺成功地完成了那个转变,可能更多是从商业角度来说的。
40:45
point of view not from a security point of view but I think they internally most definitely have
从安全角度来看不是这个观点,但我觉得他们内部系统里肯定有跟外面完全不一样的东西,这我不怪他们,但那种“一套代码给所有人用”的说法,你知道的,自托管和生产环境,真的已经说不通了。就是从安全角度来说,它从“哇,开源所以很安全”变成了“作为一个有客户、想保护客户安全的公司,这真的是最聪明最安全的决定吗?”确实。我想问题可能是,为什么还要保持开源呢?我不是说反开源,我更多是从一个“图灵测试”的角度来说——如果你已经有了一个自己的代码分支。
40:53
different things in their all system than what's out there which I don't blame them but the narrative
他们整个系统里做的事情,跟外面公开的不太一样——这我也不怪他们,但叙事上确实是这样。
41:01
of like one code base for everyone you know self-hosted and production environment just no longer
就像是一个适用于所有人的统一代码库,你知道的,自托管和生产环境都不再是问题了。
41:08
makes sense it's just it's it's it's it's from a security point of view it's it it went from
有道理,只是从安全角度来看,它从……
41:15
wow this is safe because we're open source to is that really the smartest safest decision you
哇,这很安全,因为我们是开源的——那真的是最聪明、最安全的决定吗?
41:22
should make as a business that has customers and that you want to keep them safe you know yeah
作为一个有客户的企业,你当然应该确保他们的安全,对吧?
41:28
I guess the question might be why even remain open source at all and I don't mean that is like
我想问题可能是,为什么还要坚持开源呢?我并不是说这就像……
41:39
anti open source I mean more from a tour standpoint so if you've got a fork your own code base
反开源,我更多是从教程的角度来说,所以如果你要fork自己的代码库的话。
41:46
and now you don't want your vulnerabilities out there so that means there's a buffer layer
而且现在你不想把自己的漏洞暴露出去,所以这就意味着在开源和闭源之间得有一层缓冲,也就是你内部维护的那个fork,你得想办法让这两套代码库哪怕只是远程同步都别脱节,还得避免开发者在那儿玩杂技似的折腾。那对商业开源公司来说,开源的意义到底在哪?你也是过来人,但你这次没做这个改变。我的意思是,这真的是……真的是个特别糟糕的局面,就像,对,这就是两瓶毒药选一瓶。我觉得吧,保留一个开源项目的理由——顺便说一句,我们也在把它改名为cal.dy,我们已经拿到那个域名了——基本上就是“你自己动手”的意思。
41:51
between what is open source and what is closed source i.e the fork that you have internally the
在开源和闭源之间,也就是你内部的那个分支,
41:57
tour it must be to keep those two code bases and even remotely in sync and not have you know
要让这两套代码库哪怕只是勉强保持同步,那肯定是个噩梦般的工程,你懂的。
42:04
developer gymnastics playing around like what's the point of open source then for a commercial
开发者们翻来覆去地折腾,那开源对商业来说还有什么意义呢?
42:09
open source company that was you know has been in your shoes but you're not making this change
一家开源公司,你懂的,也经历过你现在所处的境地,但你不是在做这个改变
42:15
I mean it is it's it's it's a really it's a really terrible situation you know it's like yeah
我的意思是,这真的是,真的是,真的是一个非常糟糕的情况,你懂的,就是这样。
42:21
this is pick your poison um I would argue the reason to keep an open source project and by the way
这是“Pick Your Poison”,嗯,我认为,保持一个开源项目的原因——顺便说一句——
42:31
we're also rebranding it to cal.dy we got that domain so like do it yourself essentially like
我们也在把它重新命名为cal.dy,我们拿到了那个域名,所以基本上就是“自己动手”的意思。
42:36
oh like that it's it it's a whole it's there's going to be big red letters like use at your own
哦,就像那种,整个就是,会有大红字写着“自行承担风险使用”,不是生产就绪的,你可以自己托管来玩玩,或者搞点小生意什么的。如果每个节点都跑同样的软件,那你就可以搞那种大规模攻击,但对黑客来说,攻击你邻居的理发店根本不划算,所以理论上讲——你知道它不安全,我们只是知道它就在那儿,但假设它比私有分支稍微不安全一点——确实,但它的安全性来自于它在分发上太分散了,对吧?这边五个人,那边十个人,这儿五个,那儿一个,所以你其实是通过让自己不那么像目标来把安全性找回来,你懂的,目标更小。
42:44
risk not production ready like you can self-host this for your whatever hobby or maybe small business
风险不在于生产环境是否就绪,比如你可以自己托管这个,用于你的什么爱好或者小生意。
42:53
um I think the benefit is if people end up self-hosting a quote-unquote community edition
嗯,我觉得好处在于,如果人们最终选择 self-hosting 一个所谓的 community edition,
42:59
it's they are not gonna be the one being hacked right like it's us it's the largest company that
他们就不会是被黑的那个人,对吧?被攻击的是我们,是最大的公司,是钱最多、名声最大的那个。
43:07
gets attacked the one with the most money the most reputation your neighbor barber who self-host
你隔壁那个自己 self-host 的理发师——你需要先找到那台服务器,你得确切知道你在针对谁。
43:14
cal.dy y like a you need to find that server b you need to know exactly who you're targeting who you're
这就有点像 security by distribution,对吧?当你 self-hosting 的时候,你不会成为目标。
43:23
like it's it's kind of like security by distribution right like when you're self-hosting you're not
除非某样东西很容易同时攻击多个节点,比如每个节点都跑同一个软件,那你就可以搞这种 mass attack。
43:29
going to be the target unless it's like a very easy to attack multiple multiple nodes in a way like
但对 hackers 来说,去攻击你隔壁理发店在商业上根本不可行,所以理论上来说……
43:35
if it's if every node runs the same software then you do like this like mass attack but it's
如果每个节点都运行相同的软件,那就像这样,像大规模攻击一样,但它是……
43:40
just not commercially viable for hackers to hack your neighbor's barber shop so theoretically speaking
从商业角度来看,黑客去攻击邻居家理发店根本不划算,所以理论上讲——
43:47
yes the cal.dy version will have the code base off today right the potentially we we don't even
是的,cal.dy 版本今天就会把 codebase 放出去,对吧?而且可能我们甚至都不知道它是不是 insecure,我们只知道它确实已经公开了。但就算说它比 private fork 要稍微没那么 secure,它也能靠 distribution 把安全性找回来,对吧?就是这边五个人、那边十个人、这边五个、那边一个,所以你等于靠这种方式把安全性补回来了——你懂的,自己不是那么明显的一个 target。同时呢,我们显然也随时可以——而且严格来说我真的只讲 auth、database、middle layer 这些——如果 community 做出了很好的 features,我们可以直接采用,并且给他们 credit;如果我们自己做出来很屌的 features(我们确实会做),我们……
43:55
know if it's insecure we just know it's out there but let's say it's slightly less secure than
不知道它是不是不安全,我们只知道它就在外面,但假设它比原来稍微没那么安全一点。
44:00
the private fork sure but it gains its security by being just so relevant in terms of distribution
私有分支确实如此,但它的安全性来自于它在分发方面的巨大相关性。
44:09
right like five people here 10 people there five people here one person there so you're kind of
对,就是这里五个人,那里十个人,这边五个,那边一个,所以你就有点……
44:14
like gaining that security back by just being more like less of a target you know less of a
像是重新找回了那种安全感,就是让自己不那么像个目标,你懂的,少一点那种……
44:20
targeting your back and then at the same time we can always obviously and I'm only strictly
针对你的后背,然后同时我们显然可以——而且我只是严格
44:28
strictly talking about like auth and database and middle layer etc like if the community builds
严格说的是像认证、数据库和中间层这些,如果社区建了
44:35
great features we can we can adopt them and credit them if we build sick features which we do we
很棒的功能,我们可以采纳并给他们署名;如果我们自己搞出了很牛的功能——我们确实有——他们
44:41
push them back into the open source community edition so I hope to keep that relationship strong
把它们推回 open source community edition 里,所以我希望继续保持那种紧密关系
44:46
the same way WordPress has been doing it for many years so it's not like a unique idea like we've
就像 WordPress 这么多年一直在做的那样,所以这不算什么新鲜点子,我们一直
44:52
always had private and public folks of open source projects Docker has its own enterprise edition
都有 open source 项目的私有和公开 fork,Docker 也有自己的 enterprise edition
44:57
that's private source yeah but like I think and if I'm being honest with you all of these
那是 private source,是啊。但我觉得,如果跟你说实话,所有这些
45:05
forks have been for commercial reasons some investor has pushed you some IPO some bank looked at
fork 都是出于商业原因——某个投资人推了你,某个 IPO、某个银行看了你
45:11
you and be like we need some proprietary code because of whatsoever so it looks better in our
然后跟你说:“我们需要一些 proprietary code”,因为不管怎样,这样在我们的
45:17
brochure but trust me with my fullest heart this is not a commercial like we are we are growing
宣传册上更好看。但请你掏心掏肺地相信我,这不是商业目的,我们正在增长,我们正以
45:25
7 to 12 percent month over month we are not in any way short on cash we have no investors who
每月 7% 到 12% 的速度增长,我们完全没有现金短缺,我们也没有任何投资人会……
45:31
are bullying us to go private source we have the most open source friendly investors on our
逼我们转成闭源。我们的股东名单上是史上最支持开源的投资者,
45:36
cap table we had to convince them this is the right decision this is like a a a a like
我们还得说服他们这是正确的决定。这就像,呃,一个
45:46
nuclear problem for commercial open source you know and so it's um I wish it was a commercial
商业开源领域的核弹级问题,你懂的。所以呢,我希望这是个纯商业决策,
45:53
decision because then I can like say okay this is only affecting us but this is this is affecting
因为那样我就能说“好吧,这只影响我们”,但这不是,这影响的是
45:58
the entire industry this is like a yeah like the quantum computing cracks encryption type of level
整个行业。这就像,嗯,量子计算破解加密那种级别的事。
46:07
you know yeah that quantum what do they call that quantum safe or quantum ready in terms of security
你知道吧,那个量子——他们管那个叫quantum safe还是quantum ready,就是安全方面的那个。
46:15
and what not exactly yeah exactly I mean that's that's really insane thing too what other examples
对对对,没错,我是说那真的太疯狂了。那还有什么别的例子?
46:19
can you give I know that you kind of give a couple but what are some explicit examples of other
你能再举几个吗?我知道你之前提过一些,但有没有其他商业开源公司,跟你们想法一样,或者遇到同样问题的?你能公开讲讲他们面临的挑战吗?嗯,我可以——我确实有很多对话,但真的没法公开,因为涉及安全,就是那种固有的风险。那X上呢?你在X上看到什么?嗯,你会读到什么?我是说,我肯定可以聊那些公开的情况,对吧,像这种。而且我也不想——
46:26
commercial open source companies that think like you do or have the same problems you do and can
那些商业开源公司,他们的想法跟你一样,或者面临的问题跟你相同,而且他们能够
46:32
you enumerate their challenge in the public that's being showcased well I can I can I have many
你在公开场合列举了他们所面临的挑战,这一点展示得很好。我可以说,我有很多……
46:38
conversations you know that I really cannot make public because of security and like it's just
你知道的,有些对话我真的不能公开,因为涉及安全问题,就是那种……
46:46
the risk inherent risk and what's on x what do you see on x yeah what would you read I mean
固有的风险是什么?在X上你有什么看法?对,你会怎么解读?我的意思是——
46:52
well I mean I can definitely talk about public situations right like this and I also don't want to
嗯,我肯定可以聊聊公开的情况,对吧,像这种,而且我也不想——
46:57
throw anyone under the bus but there's you know there's um there's tooling around logging right like
不想点名批评谁,但你知道,嗯,日志相关的工具确实存在,对吧?就是那种锁定用户活动的系统,这类产品通常都是开源的,因为它本质上是个开发者工具包,你得导入SDK才能用。所以这些已经被AI攻破了,这真的很糟糕,因为现在攻击者能拿到你所有用户的操作记录。这说得通,就是他们发送的那些事件数据。对他们来说真的完蛋了,因为他们为了做开发者工具,必须保持开源。所以我觉得有两家公司是直接受影响的,而且我还知道有个CMS,也是开源的,现在真的很难受,因为作为CMS,你根本没法把内部系统暴露给全世界,我是说——
47:03
lock systems that lock user activity those products are usually open source because it's it's a
锁定用户活动的系统,这类产品通常是开源的,因为它是……它是……
47:12
developer package you need to like need to import the SDK so those have been hacked by AI which
开发者包,你需要导入SDK,这些已经被AI攻破了
47:18
is really bad because now that attacker has access to all your users actions that makes sense
这真的很糟糕,因为现在攻击者已经能访问你所有用户的操作了,这就说得通了。
47:24
like the events that they send um for them they're really screwed because they they have to be open
比如说他们举办的那些活动,呃,对他们来说真的完蛋了,因为他们必须得公开。
47:30
source for the sake of being a developer kid right um so I I would say that's two companies that
为了成为开发者小子的缘故,嗯,所以我会说那是两家公司。
47:39
are directly affected and I know of um there's a CMS which is open source which is really struggling
直接受到影响,而且我知道有一个开源的CMS,现在真的很难撑下去。
47:47
because when you're a CMS um you simply cannot expose your internal systems to the world I mean
因为作为一个CMS,嗯,你根本不能把内部系统暴露给全世界,我是说——
47:55
just think about how much knowledge is locked up in a in a CMS and or the risk of of of somebody
想想看,有多少知识被锁在CMS里面,或者说,万一有人——我也不知道,被黑客攻击了——比如你拿到了某个人的CMS权限,然后在Nike.com上发东西,你懂的,那就不太好了。所以呢,市面上有很多商业开源公司,它们必须得开源才能运转下去。从这个角度来说,我们算是比较幸运的,因为我们不像别人那样那么依赖“可以自托管”这件事。再说,我们99%的收入都来自SaaS,就是app.cal.com,我们不是那种卖一段代码片段让你塞进自己业务里的公司。所以,嗯,就是这样。然后呢,还有几家支付服务商,它们自称是“开源版的Stripe”。
48:03
I don't know hack like imagine you get right access to someone CMS and you're publishing
我不知道怎么黑进去,比如想象一下你直接拿到了某个人的CMS权限,然后你正在发布内容。
48:08
something on Nike.com you know like that's just not great um so uh there's uh there's a lot of
耐克官网上的某些东西,你知道,就是不太行,嗯,所以呢,有很多——
48:15
commercial open source businesses out there that um that have to be open source in order to to run
市面上那些商业开源公司,嗯,它们必须得开源才能运营下去。
48:21
um in that regard we're almost somewhat lucky that we don't depend as much as others to be
嗯,从这个角度来看,我们其实算是有点幸运的,因为我们不像其他人那样依赖那么多。
48:29
self-hostable again 99% of our revenue comes from our SaaS you know app.cal.com it's not like
再次可以自托管,但我们99%的收入来自SaaS,就是app.cal.com,并不是说
48:37
um we sell a code snippet that people inject in their business um so yeah it's um and then um
嗯,我们卖的是一个代码片段,人们把它嵌入到他们的业务里。嗯,对,就是这样,然后……
48:44
there's a couple payment providers that that like call themselves the open source version of stripe
有几个支付服务商,自称是Stripe的开源版本。
48:50
obviously anything that touches payments is hypercritical you know that's that's always tricky um
显然,任何涉及支付的东西都是至关重要的,你知道,那总是很棘手,嗯
48:56
I don't even want to talk about crypto because I really don't like crypto but all of these crypto
我甚至不想谈加密货币,因为我真的不喜欢加密货币,但这些加密货币
49:00
projects are being cracked open that open source um it's it's a wild west out there and so
项目都被开源破解开了,嗯,那里简直是狂野西部,所以
49:10
you're if you are a doctor doctor peer yeah uh your your prescription for these commercial
你——如果你是个博士——博士同行,呃——你对这些高影响领域的商业化 open source 公司开出的处方是:重新思考它们的模式,然后像你一样,在内部 fork,跟 open source 版本建立起一种新关系——如果你们还保留它的话。就你而言,你保留着它,你知道,cow.diy 或者 DIY,我觉得这超酷。嗯,刚才我有一点阅读障碍,不过 cow.diy 又做到了。DIY,DIY,对,cow.diy,自己动手嘛,Adam,拜托。嗯,好的一面是——好的一面,对,好的一面,也许坏的一面是——比如 open source 的就是一直 open source,对吧?就像我们——我们明天就消失了,你就不太酷了,这个……
49:16
open source companies in these high impact areas is to rethink their model and follow you
开源公司在这些高影响领域要重新思考他们的模式,并跟随你
49:24
in terms of forking internally creating a new relationship with the open source version if you
在内部进行分叉,与开源版本建立新关系,如果你
49:29
even keep it in your case you're keeping it you know cow dot DIY or DIY which I think it's super
甚至保留它——在你的情况下,你保留了它,你知道,cow dot DIY 或 DIY,我认为这非常
49:35
cool um had a little case of uh of dyslexia there for a moment there but uh nonetheless cow dot
酷,嗯,刚才有点口误,但是嗯,尽管如此,cow dot
49:42
DIY did it again DIY DIY yeah cow dot DIY do it yourself come on Adam well on the bright side
DIY 又做到了,DIY,DIY,是的,cow dot DIY,自己动手,加油 Adam,好的一面是
49:52
on the bright side yeah on the bright side and maybe on the bad side like what's open source
往好的方面看,对,往好的方面看,可能往坏的方面看就是,开源的东西会一直开源,对吧?就像我们,如果我们明天消失了,那其实也不太酷。
49:58
stays open source right like we we went up disappearing tomorrow you're not really cool this
对对对,更像是把石头清理干净,然后好好吸一下石头上的灰。
50:04
yeah yeah more like cleaning the rock and making okay vacuuming the rock okay
吸尘,我们在给石头吸尘,然后把门关上不让你进去,你可以看着它。
50:12
vacuuming the we're vacuuming the rock and and closing the door to access it to you can look at it
它很美,是一块很美的石头,但你再也不能踩上去了。嗯,因为你看,
50:18
it's beautiful it's a beautiful rock but you can no longer step on it um no because like look
外面有这么多人,telecom 不会消失的,我们合法上不可能,
50:24
there's like so many folks out there telecom is not going anywhere like we can legally not
物理上也不可能把代码删掉。我们能做的就是优雅地往前走,
50:29
know we can physically not get rid of the code what we can do is move forward gracefully and
确保任何软件里最脆弱的部分不公开。我觉得这才是关键。
50:38
make sure that the most vulnerable pieces of any piece of software is not public i think it's a
确保任何软件中最脆弱的部分不公开,我认为这是关键。
50:44
very fair statement to say because back in the days you would have those public because it's just
这么说很公道,因为以前那些代码都是公开的,因为那时候真的很难被黑。现在很容易被黑,所以我才需要把这些东西私有化。而且顺便说一句,有私有代码并不代表你就不会被黑,没人觉得那是万能解药,但很多安全研究员都说,你开源的话被黑的难度会低五到十倍。你得听安全专家的,如果你不听,那你基本上——搞不好还能拿这个当理由,要是真被黑了说不定还得进监狱。我不知道,我不是律师,但如果你无视了专家多次的警告,那你真该重新想想自己凭什么当这个联合创始人。
50:49
really hard to hack them now it's easy to hack thereby i need to take these things private
现在真的很难破解它们了,以前很容易黑进去,所以我得把这些东西私有化。
50:55
and by the way having private code does not protect you from being hacked i don't nobody thinks
顺便说一句,拥有私有代码并不能保护你不被黑客攻击,我觉得没人会这么想。
51:00
that that's the golden solution but it is security researcher of many security researchers say
那是黄金解决方案,但很多安全研究人员都这么说。
51:05
it's five to ten times easier to hack you when you open source you have to listen to the security
开源之后,黑客攻击你的难度会降低五到十倍,你就必须得听安全团队的了。
51:11
experts if you don't listen to them you're literally well probably you could use that as a
专家们,如果你不听他们的,那你基本上——好吧,可能你可以把这当作一个……
51:19
way to even go to jail if you get hacked i don't know i don't i'm not a lawyer but like if you ignore
连被黑客入侵后甚至可能进监狱,我不知道,我不是律师,但如果你无视的话……
51:25
multiple warnings from experts you should probably rethink why you're even the co-front of the
多位专家的多次警告,你可能真该重新想想,自己为什么还要站在风口浪尖上。
51:29
business right so um my recommendation my medicine is um first don't freak out there's a high chance
好吧,那么,嗯,我的建议,我的药方是,嗯,首先别慌,有很大可能
51:37
you're not compromised most likely you run a really small project you're not a big target um
你并没有被入侵,很可能你运行的只是个小项目,你不是什么大目标,嗯
51:45
second is to run many of these AI scanning tools and and and just see what the blast radius is today
第二是跑很多这类AI扫描工具,然后就是,就是看看现在的爆炸半径有多大
51:57
most likely it is quite high like every single project i've talked to was experiencing an
很可能相当大,比如我聊过的每一个项目都正在遭遇某种
52:03
uptake of reports by these AI tools but like tenfold like it's just messy it's really bad
这些AI工具带来的报告激增,而且是十倍
52:10
turns out humans are really bad at coding for many years including
事实证明人类在写代码这件事上真的很差劲,很多年都是这样,包括AI出现之前的所有东西,所以很可能你本来就有漏洞,这就是事实。
52:16
everything before AI so chances are you just have vulnerabilities that's just that's just a fact
然后我的建议是,至少暂时把仓库设为private,先把这些问题都处理掉。
52:22
and then my recommendation would be to at least temporarily go private and work on all these
然后再一次性合并回去,你知道吧,就是那种一个大的chunk,最好是这样,就像commit一样,别零零碎碎的。
52:28
vulnerabilities because use another problem and this this really
因为存在漏洞,因为利用另一个问题,而这这真的
52:32
my brain right when there's a hacker who actually wants to compromise your project
让我脑子一转,当真有黑客想要攻陷你的项目时
52:39
they are also running code scans against your own pull requests right so
他们也在对你的 pull requests 跑 code scans,对吧。
52:45
so they today probably if if let's say you really want to screw someone right
所以他们现在可能,如果你真想整某个人,对吧,
52:52
you would run code scans against their own pull requests and if you detect a pull request that fixes
你会对目标自己的 pull requests 跑 code scans,如果你检测到一个 pull request 修复了
52:59
a previously known vulnerability that you potentially found or ready or maybe not right
一个之前已知的 vulnerability——这个漏洞你可能是自己发现的、或者早就知道的、也可能不是,对吧。
53:06
like an AI can understand whether a pull request is a feature or a fix of a vulnerability
就像 AI 能判断一个 pull request 是 feature 还是修复 vulnerability,
53:12
right like you you give an AI just random code and and ask it like what is this PR about and it will
对吧,你随便给 AI 一段随机代码,问它这个 PR 是干嘛的,它就会
53:19
tell you this is fixing a vulnerability so they're using that I I mean whatever is technically
告诉你这是在修 vulnerability。所以他们就在用这个,我是说,任何技术上
53:25
possible will happen right I'm not making this up I don't know what personally any hackers but
可能发生的事情都会发生,对吧。我不是在编,我个人不认识什么黑客,但是。
53:30
I am that's what I would do if I was evil you would scan the PR you would identify this PR
如果我是邪恶的,那就是我会做的事——你会去扫一遍 PR,识别出这个 PR 是在修 vulnerability,然后就在那一秒,我会利用这个 vulnerability,给他们发一封勒索信,对吧?这就是可怕的地方。我不该变成一个典型的 Marvel 邪恶超级反派,但不管怎样,再说一遍,所有事情在技术上都是可能的,而且已经真的在发生了,所以我并不是在给你什么 playbook——那些 dark web forums 上讨论的大概就是这些。所以你今天最好的办法就是把 repo 设成 private,在 private 里把这些问题全部修掉,再合并成一个 chunk,那差不多就是 commit,不要...
53:37
is fixing the vulnerability and in that second I would abuse that vulnerability and send them an
就是在修复漏洞的那一刻,而就在那一秒我会滥用那个漏洞然后给他们发一封
53:41
extortion letter right that's just the that's just a scary part right that's not you think here
勒索信对吧,那只是那只是可怕的部分对吧,那不是你认为的
53:49
right that's I should I should not become a Marvel evil model super villain but anyway
对吧,那是我,我不应该变成一个漫威邪恶模型超级反派,但反正
53:57
again everything is technically possible is out there and it's happening so I'm not I'm not
再说一次,所有事情在技术上都是可能的,它正在发生,所以我并不是,并不是在
54:02
giving you the playbook that's literally what's probably discussed in these dark web forums
给你提供操作手册,那基本上就是那些暗网论坛上讨论的东西
54:07
and so your best shot today is to take the repo private fix all of these things in private and
所以你今天最好的选择就是把仓库设为私有,私下修复所有这些问题,然后私下
54:14
then merge it back into one you know chunk that's just you best like it's quite like commit don't
他们不会勒索你要Bitcoin的,你知道吧,嗯,我不知道你之前是不是在聊这个。
54:21
give them a exact path to change don't feed don't feed the machine don't feed the machine that's
给他们一条明确的改变路径。别喂——别喂那台机器,别喂那台会拿Bitcoin来敲诈你的机器。
54:27
going to extort you for Bitcoin you know well if I don't know you were talking about this when
也许我们不应该,也许我们不应该把这段发出去,我是说这内容挺好的,我觉得这给一些事情带来了新的视角。
54:33
you came on this podcast that's probably not invited you got me down over here man
你知道,要是我早知道你上这个podcast的时候会聊这个,我大概就不会请你来了——你把我弄到这儿来了,老兄。
54:38
maybe we should not maybe we should not publish this I mean this is good stuff I think this is
如果你不介意的话,我想回到之前那个话题,倒不是说完全要回到那个poor request的tab。
54:43
this is truthful I mean this is where my head's been at as well yeah um and you're bringing some
也许我们不该,也许我们不该把这段发出去。
54:48
new light to some things with me I'm gonna go back to if you don't mind uh not so much to fully
对,原因就是——所以你看到的那些关于commercial的东西,就是你现在看到的那些。
54:52
backtrack but I'm gonna go back to your poor request tab and not specifically just yours but the
我是说,这内容确实好,我觉得这是……这是真实的。
54:58
poor request tab yeah and the reason why I mean so you're seeing what you're seeing about commercial
糟糕的请求标签,没错,而且我之所以这么说是因为——你看到的那些关于商业化的东西,其实就是这样。
55:03
open source companies I don't think open source is dying I do think poor requests may be changing
open source 公司这块,我不觉得 open source 在消亡。但我觉得 pull requests 可能正在改变——它们不是变得无关紧要,而是充满了大量人们不想处理的垃圾。
55:09
and are becoming not irrelevant but just fraught with a lot of slop that people don't want to deal with
并且正在变得不是无关紧要,而是充满了大量人们不想处理的垃圾内容
55:16
so even projects like ghosty they're not taking on poor requests like they were before a lot of
所以即便是像 Ghostty 这样的项目,他们也不再像以前那样接受 pull requests 了。很多人知道,Ghostty 是个很棒的 terminal,而且出于很多原因,它需要也想要保持 open source,为了 open source 真正的本质——但他们现在是 open source,不是 open to contribution。
55:23
folks that you know like ghosty is a great terminal and for a lot of reasons it needs to be
你知道,像ghosty这样的工具是个很棒的终端,而且出于很多原因它需要是
55:28
and wants to be open source for the for the true nature of what open source is but they're being
所以我想在这里抛出一个思想实验:这种变化对 GitHub 有什么影响?GitHub 作为一家企业,会不会处于危险之中?
55:33
open source not open to contribution so I want to I want to pose this thought experiment here
开源的,但不是开放贡献的,所以我想在这里提出一个思想实验
55:39
how does this change get up is it is get up at jeopardy in any way as a business
也许不会,因为他们很多商业功能都构建在那些并不在那样的东西之上,但……
55:45
maybe not because a lot of their commercial features are on top of things that aren't there but like
也许不是因为他们很多商业功能都建立在那些还不存在的东西之上,而是因为
55:50
if a lot of us are on GitHub because that's where open source is and if the relationship we have
如果我们很多人都在GitHub上,因为那是开源所在的地方,而如果我们与
55:55
with open source changes or open source changes enough you know is GitHub in a risky scenario
开源的关系发生了变化,或者开源本身变化得足够大,你知道GitHub是不是处于一个风险境地
56:03
because I mean they're banking almost everything on co-pilot right I mean that's the large majority
因为我的意思是他们几乎把所有东西都押在co-pilot上了,对吧,我的意思是那占了他们
56:07
of their their infrastructure even npm I don't know they have some changes coming out and I'd love
基础设施的绝大部分,甚至npm也是,我不知道他们有一些变化要出来,我很想知道
56:12
to talk to them at members working at GitHub behind the scenes or in front of the scenes if there is
去跟GitHub幕后工作的成员聊聊,或者幕前如果有人的话也行。在npm那边,我并不是说那些人有任何不好,我只是知道那里确实有疏忽,npm那边确实有疏忽。要知道,地球上人类已知的最大包管理器和注册中心就是npm,它太重要了。我的意思是,那正是事件发生的地方,而我们都清楚后来是怎么收场的,对吧?如果这一切都变了,GitHub会是什么样子?你对这个有什么看法?嗯,我觉得这对商业开源来说不太乐观,我可以告诉你。所以如果你显然在运营包之类的,走freemium开源路线,那你可能还好。当然,你要是搞个新的React替代品,那又是另一回事了。
56:18
any on npm I'm not saying anything negative about those folks at all I just know that there's
npm 上那些包我没有任何负面意思,我就是知道有这回事。
56:22
there's neglect there's neglect there around npm see even of the things that is
在npm方面确实存在疏忽,甚至包括一些……
56:28
the largest package manager and registry known to man on planet earth is npm it's so important I
地球上最庞大的包管理器和注册中心就是npm,它太重要了。
56:36
mean that's where the act is act just happened and we know how that went down right you know what
意思是,那就是事情发生的地方,而且我们也都知道后来结果如何了,对吧?
56:42
is the picture of github if all this changes what are your thoughts on that well I mean it's not
如果这一切都变了,GitHub会是什么样子?你对此有什么看法?嗯,我的意思是,不是这样的。
56:48
it's not it's not bright for commercial open source I can tell you that so like if you obviously run
说实话,商业开源的前景不太光明,我可以这么告诉你。所以如果你显然是在运营……
56:53
packages etc freemium open source you're probably more okay sure you build a new react alternative
软件包之类的,freemium 模式,开源的话你可能更接受,当然可以,你做一个新的 React 替代品。
56:59
or self-kid whatever and tell when alternatives um but GitHub obviously has to rethink its own
或者自我欺骗什么的,然后告诉别人替代方案,嗯,但GitHub显然得重新思考它自己的——我不会说经济模式,但就是它在AI时代世界里的位置。而且这个我觉得甚至超出了安全范畴,因为你看,如果像Peter那样的人连自己的diff都不看,而隔壁用vibe coding搞iOS应用的人,大家真的在乎源代码吗?你想看源代码吗?可能已经有项目了,社区看你代码的次数比你自己发布那个仓库的人还多,对吧。嗯,就是说,对,完全同意,这种事肯定会发生,维护者看过的代码量加起来可能还不如整个社区看的多,通常就是这样。
57:09
like I wouldn't call it economic model but like place in the world with AI where
我不会称之为经济模式,但更像是AI在世界中的位置。
57:17
and this I would even say this goes beyond security because like look if somebody like Peter
而且我甚至会说,这已经超出了安全范畴,因为你看,如果像Peter这样的人——
57:24
doesn't read its own diffs and the neighbor who vibe codes it's iOS app do people really care
不读自己的diff,还有那个用vibe coding写iOS应用的邻居——人们真的在乎吗?
57:32
about the source code do you want to see the source code like there are probably already
关于源代码,你想看看源代码吗?可能已经有很多了。
57:39
projects out there where the community has looked at more of your code than you yourself who publish
有些项目,社区看你代码的次数比你自己发布代码的人还多。
57:45
that repository right um simply I mean that yeah totally I mean that that's going to happen right where
那个仓库嘛,嗯,简单说就是——对,完全会这样,这事儿肯定会发生的,对吧?
57:53
the maintainers have seen less of the code based than than the community combined usually it's like
维护者看到的代码库通常还不如整个社区加起来多
58:00
the maintainer who writes the code knows the code but now it's like I can prompt any project
维护代码的人懂代码,但现在感觉我可以随便给任何项目写个prompt,然后发到GitHub上,结果我自己可能连发出去的代码表面都没怎么看过,对吧?只要它能跑、看起来不错,我干嘛还要去读代码呢?而且这样也安全,安全得很。所以很明显,分发代码在某种程度上几乎就像分发二进制文件一样了。如果大家都只发二进制,GitHub根本没法用——虽然它还能运作,但谁会去读那些东西?或者你就把字节码、汇编代码、随便什么二进制代码扔上去,0 0 1 0 0 1,挺好的,酷。所以如果源代码变得没人能读懂,因为没人真的去读——虽然听起来挺可悲的,我也不喜欢这样——但现实可能就是这样。
58:06
and publish it on GitHub and then chances I I barely scratch the surface of the code that I've
然后在GitHub上发布,之后我基本上只是对代码略知皮毛,连表面都没怎么深入。
58:11
published right it's like as long as it works and it looks good why would I read the code you know
发布得对,就像只要它能跑、看起来不错,我干嘛还要去读代码呢,你懂吧。
58:17
and it's safe safe so obviously distributing code almost feels like distributing binary at some
而且这很安全,很安全,所以显然,分发代码在某种程度上几乎感觉就像分发二进制文件一样。
58:26
point and GitHub wouldn't work if people just published their binaries you know it still works
point和GitHub要是人们只发布二进制文件的话就行不通了,你知道的,它现在还是能运作的。
58:34
but like who's going to read that or like you just put the the bytecode the assembly code whatever
但谁会去读那个呢?或者你直接放字节码、汇编代码什么的就行。
58:38
the binary code up there you know 0 0 1 0 0 1 that's great cool so if source code as sad as it sounds
上面那些二进制代码,你知道的,0 0 1 0 0 1,挺酷的。所以,如果源代码听起来有点惨兮兮的,
58:45
really listen like I'm not a fan of this but if source code becomes unreadable because nobody knows
说实话,我不太喜欢这样,但如果源代码变得没人能读懂,因为没人知道……
58:51
what the doing anyway so if if nobody knows programming anymore if new students come out of
反正现在到底在干嘛呢,如果没人再懂编程了,如果新毕业的大学生出来,他们读不懂源代码,他们不知道if语句是什么,他们不知道GitHub除了当个CDN分享zip文件之外还有什么意义——如果那时候zip还存在的话,或者DMG文件什么的,你基本上就是把所有东西都翻了个底朝天。2027年、2030年,代码的意义到底是什么?2030年代码到底意味着什么,对吧。然后很明显,这根本不是AI优先的思路。我的意思是,我刚才说的那些,任何人都能随便给任何人开pull request,这就不对。应该有护栏,应该有规则,规定谁能贡献代码,毕竟我们用的是这些第三方的东西。
58:58
university and they don't they can't read source code they don't know what they don't know what if
大学里,他们读不懂源代码,他们不知道,万一……
59:03
statement is they don't know what a you know what what point has GitHub besides being a CDN to share
他们的说法是,他们不知道GitHub除了当个分享用的CDN之外还有什么意义。
59:12
zip files if zip even is around that time or you know or DMG files like you you're basically turning
zip文件,如果那时候zip还存在的话,或者你知道,DMG文件之类的,基本上你就是在转换
59:20
into a mega upload where people just throw up all their garbage so yeah they 100% have to rethink
变成一个 mega upload,每个人都把垃圾往上扔,所以是的,他们 100% 必须重新思考一切,比如在 2027 年、20……2030 年,代码的意义是什么?2030 年代码的意义是什么?你知道吧。然后显然这根本不是 AI first。我的意思是,你知道我刚解释的,任何人都能给任何人开 pull request,你知道,应该有 guardrails,应该有规则来规定谁能贡献。比如我们用的那些 third party 的 GitHub actions,会自动关闭那些未验证的人的 pull request,那都只是 hacks。你知道,那应该是 GitHub 的 first party 功能。为什么我得装各种 third party plugins 来确保只有合法的人才能开 pull request?那才应该是……
59:28
everything about like what is the meaning of code in 2027 20 2030 what is the meaning of code in
关于2027年、2030年代码的意义是什么,代码的意义是什么
59:34
2030 you know yeah and then obviously it's not in any way AI first I mean the fact that you know
2030年,你懂的,是的,然后显然这根本不是AI优先,我的意思是,你知道
59:42
what I just explained anyone can open pull requests for anyone you know there there should be
我刚才解释的那些,任何人都可以提交pull request,你知道的,应该这样。
59:48
guardrails there should be rules who can contribute like we're using these third party
护栏应该是有规则的,谁能贡献,比如我们用这些第三方的东西。
59:53
GitHub actions that like auto-close pull requests from people who are not verified that's all just
GitHub actions 里那种自动关闭未验证用户提交的 pull request 的功能,说到底都是 hack,你知道吧,这应该是 GitHub 自己原生就该有的功能。为什么我得装各种第三方插件才能确保只有合法的人能开 pull request?这应该是你的活儿啊 GitHub。朋友们,我回来了,今天请到了我的好朋友 Michael Grinich。Michael,我知道我很喜欢 work OS,我们的听众可能不太了解 work OS,但开发者开始一个新项目时会面临哪些挑战?选对工具、选对数据库、选对方向——带我了解一下。当开发者开始一个新项目时,他们在最开始做的那些决定,最终会产生长期的影响。你用哪种语言开发,用哪个平台,这些都很关键。
59:59
hacks you know that should be first party coming from GitHub why do I have to install different
你知道的那些本该是GitHub原生功能的小技巧,为什么非得让我装各种不同的插件?
60:05
third party plugins to make sure only legitimate people are opening pull requests that should be
第三方插件用来确保只有合法的人才能打开那些本应打开的pull requests。
60:13
your job GitHub you know friends I'm back with a good friend of mine Michael Grinich
你的工作GitHub你知道的朋友们,我回来了,和我的一位好朋友Michael Grinich一起。
60:22
Michael I know that I love work OS our audience may not know about work OS but what are the challenges
Michael,我知道我喜欢Work OS,但我们的听众可能不太了解Work OS。那么,挑战是什么呢?
60:27
developers face starting a new project choosing the right tools choosing the right database choosing
开发者面对启动一个新项目时,要选对工具,选对数据库,选对
60:32
the right off take me there when a developer starts a new project the decisions that they make at
当开发者开始一个新项目时,他们所做的那些决定,会直接决定项目的走向。
60:37
the very beginning end up having long lasting consequences what language you build in what platform
在最开始的时候,最终会产生长期的影响——你用哪种语言构建,在哪个平台上构建。
60:43
you build on top of what database you choose these are things that are very hard to change later on
你选什么数据库,是在那上面继续搭建的,这些东西后期很难改
60:47
so they have like major consequences and especially if they limit your ability to grow and scale at
所以它们影响很大,尤其是如果它们限制了你增长和扩展的能力
60:53
some point as the product starts to take off you're going to have to stop developing new product
等到产品开始起飞的时候,你就得停下新功能的开发
60:57
features and go re-architect to rebuild your system and that might be a killing blow right at the
回去重新架构、重建系统,而就在你最需要加速的那一刻,这可能是致命一击
61:04
moment you need to accelerate so these decisions are really on are really really important and I think
所以这些决策真的非常非常重要,我觉得这就是为什么开发者会倾向于选那些成熟、他们知道能扩展的方案
61:08
that's why developers gravitate towards solutions that are mature things that they know that will
哪怕是开源的东西,你也会选像Planet Scale这样的数据库服务商
61:12
scale even things that are open source you're going to pick you know something like planet scale
不是因为它最便宜,也不是因为它最好玩
61:17
for your database provider not because it's the cheapest or because it's the you know most fun to use
因为你的数据库提供商,不是因为最便宜,也不是因为你知道的,最好玩。
61:22
but because you know it's going to be a durable provider that you can scale on for years
但因为你清楚它会是一个长期稳定的服务商,能让你放心用好几年
61:26
and work OS is like that for off you know at the earliest earliest days if you look across all
而Work OS从一开始就是这样的,最早最早的时候,如果你把所有这些不同的服务放在一起看
61:31
these different services they kind of look very similar but at day 1000 or day 2000 or day 10,000
它们看起来都差不多,但到了第1000天、第2000天或者第10000天
61:37
you're going to want to have made sure that you picked a platform that could scale with you
你肯定会希望自己当初选的是一个能跟着你一起scale的平台
61:41
and today work OS is powering off an identity and security and permissions for all of these AI
而今天Work OS正在为所有这些AI公司提供identity、security和permissions的支持
61:46
companies literally the fastest growing companies in the world like opening in and dropping
基本上就是全球增长最快的那些公司,比如OpenAI和Anthropic
61:50
in person or complexity work OS is under the hood there so I think when people pick work OS early
不管复杂度多高,Work OS都在底层跑着。所以我觉得当人们早期选Work OS的时候
61:55
on really what they're doing is trying to pick the defaults to allow them to grow in rapidly scale
他们真正在做的事情,其实是选一套默认配置,好让自己能快速成长、快速scale
62:01
and there's no platform other than us that's that's done that at the same level well friends the
而且除了我们之外,没有其他平台能在同一水平上做到这一点。好了朋友们,下一步就是去 work os.com,今天就注册看看吧,一百万活跃用户以内都是免费的。今天就试试,没有任何理由不选它,它就是你的默认选择,所以赶紧去 work os.com。再说一次,work os.com。你有没有碰巧在 X 上看到 Mitchell Hashimoto 那篇帖子?你能大概复述一下吗?我帮你总结一下吧,他发了好多条,其实没多久之前,就是今年 3 月 25 号。他开头说的是,如果我来负责 GitHub,我会按这个顺序做。然后他说要确立一个北极星目标,就是成为关键基础设施,因为之前宕机太多了,你知道的,他们又回到了两个九的可用性。
62:05
next step is to go to work os.com sign up today check it out free for a million active users
下一步是前往work os.com注册,今天就试试吧,对一百万名活跃用户免费开放。
62:14
try it today there's no excuse not to it is your default you should choose it so do so work os.com
今天就试试吧,没有任何理由不选它。它就是你的默认选项,你应该选它。所以,去 work os.com 看看吧。
62:21
once again work os.com did you catch that post from Mitchell Hashimoto by any chance on x
再次收听work os.com,你看到Mitchell Hashimoto在X上发的那条帖子了吗?
62:34
uh can you give it a recap probably give you a recap so many of them it wasn't long ago it was
嗯,你能给它做个总结吗?大概给你总结一下,好多这样的内容,其实没过多久之前,也就是
62:40
March 25th of this year and he started off by saying here's what I would do if I was in charge of
今年3月25号,他一开场就说,如果让我来负责的话,我会这么做。
62:47
GitHub in this order and he says established north star around being critical infrastructure
GitHub按照这个顺序,然后他说确立了以关键基础设施为核心的北极星目标。
62:52
because there's been a lot of downtime yes and you know they go they go to double nines back with
因为确实有很多停机时间,你知道的,他们又回到了双九(99.99%)的可用性标准。
62:58
the aid in front yeah he taught us by coming back uh establishing north star around being critical
前面那个援助,对,他回来教我们的方式就是先确立一个北极星目标,围绕成为代理代码生命周期的关键基础设施,然后定出一套衡量标准。第二件事就是,把那些做co-pilot或者支持co-pilot的人都开了,然后把项目关掉。这不是针对人的问题,他是在尽量客气地说,我肯定有很多细节没讲到。收购了Carza,收购了Carza,对,不管多少钱都付,然后他说买Pierre,就是那个计算机相关的,我们之前在播客里聊过,你可能也知道。然后推出代理式repo托管,作为第一个代理产品。如果还需要的话,我可以再转述更多,但最后一条就是重新评估所有东西。
63:05
infrastructure uh for agent code life cycles and determine a set of ways to measure that number two
基础设施,呃,用于agent代码生命周期,并确定一套衡量这一点的指标。第二点,
63:11
was whatever that fire everyone who works on or advocates for co-pilot and shut it down
不管是哪个项目,把所有从事或支持co-pilot相关工作的人都解雇,然后把它关掉。
63:18
it's not about the people he's trying to be kind here uh I'm sure there's many telling
这不是关于人的问题,他在这里是想表现得友善一些,呃,我敢肯定有很多人在说。
63:23
acquired carza acquired carza right pay whatever money it's possible yeah and he says buy
acquired carza acquired carza 对,能付多少钱就付多少钱,有可能的话就买下来,然后他说买。
63:30
Pierre which is computer we've talked about that on the pod before you may be aware of it as well
Pierre,就是那台计算机,我们之前在播客里聊过,你可能也知道它。
63:36
here um buy Pierre and launch agentic repo hosting as the first agentic product
这里,嗯,买下Pierre,然后推出agentic repo托管,作为第一个agentic产品。
63:44
and I could paraphrase more of it if I needed to but then the last one was re-evaluate all
如果我还需要的话,我可以再转述更多内容,但最后一条是“重新评估一切”。
63:49
product lines and initiatives against the new north star which is really predicated on being
产品线和各种新举措,现在都要对齐这个新的北极星目标,而这个目标本质上是要成为关键基础设施。我当然把那几个九的可用性还回去了,然后他说,我怀疑有50%会被砍掉,好给那些不一样的东西腾出空间。对,所以我的意思是,我不确定他说的准不准、对不对,但确实有很多人对那个可用性和宕机稳定性很不满。我之前提到过GitHub,我知道他们赚很多钱,他们也拿了更好的估值,但我觉得他们真正押注的是GitHub Copilot。我刚刚还请了Berk Holland上播客,他是GitHub Copilot团队的开发者 advocate 之一,所以他对那边的情况了解得比较多。不过现在的情况是,Copilot的 advocate 比 Copilot的用户还多。
63:54
critical infrastructure I gave back those nines of course and he says I suspect 50 percent
关键基础设施,我当然把那几个九还回去了,然后他说我怀疑是50%。
64:00
get cut to make room for the different ones yeah and so I mean I'm not sure if he's accurate wrong
被砍掉,好给不同的那些腾出空间,对。所以我的意思是,我不确定他说得准不准确。
64:06
or right but uh there's a lot of folks who are upset at the uptime and downtime stability
或者说,嗯,确实有很多人对运行时间和宕机的稳定性感到不满。
64:12
get hub I mentioned before there I know they make a lot of money I've get a better prize as well
我之前提到过的那个hub,我知道他们赚了不少钱,而且他们那边的奖金也更高。
64:19
but I think they're really banking on uh get up co-pilot and I just had Berk Holland on the
但我认为他们真的押注于那个,呃,Get Up Co-pilot,而且我刚刚请了Berk Holland上节目。
64:25
podcast he's one of the developer advocates on the uh get up co-pilot team so he's largely aware of
他是GitHub Copilot团队的一名开发者倡导者,所以他对这方面了解很多。
64:31
what's going on there uh has no more I know more co-pilot advocates than co-pilot users
那边到底是怎么回事,嗯,我认识的co-pilot拥护者比实际用co-pilot的人还多。
64:37
you know I'm not a get up co-pilot user I'm also not you know I'm not a hater really I mean either
你知道,我不是GitHub Copilot的用户,我也不是黑子,真的,我意思是,两边都不是。
64:49
it's just I don't think you're trying to be I also I also don't hate polar bears I just don't see
只是我觉得你不是在试图……我也不讨厌北极熊,我只是看不到那个基础。
64:54
that basis sure I love polar bears um what I think is interesting if we look back uh because I've
当然,我爱北极熊。嗯,我觉得有意思的是,如果我们回头看,因为——
65:04
also had a podcast with Emilia Wattenberger and if you recall do you know Emilia Wattenberger
我还和 Emilia Wattenberger 录过一期播客,如果你记得的话——你知道 Emilia Wattenberger 吗?
65:10
by the chance of the name regabelle to you she works on the get up next team which is where
这个名字你碰巧有印象吗?她在 GitHub Next 团队工作,也就是
65:16
get up co-pilot came out of oh my co-pilot was already in place and in motion before she got there
GitHub Copilot 就是从这里出来的。哦对了,在她来之前 Copilot 就已经启动并运行了。
65:22
but she was a role she played a role in get up next which was sort of an offshoot of the office
但她在 GitHub Next 里确实扮演了一个角色,GitHub Next 有点像那个办公室的一个分支,也就是
65:29
to the CTO I get up so it became this area to innovate uh and that office of the CTO is
GitHub 的 CTO 办公室。所以它变成了一个创新领域,呃,而那个 CTO 办公室之所以成立,
65:35
predicated on Jason Warner Jason Warner's idea was get up actions get up actions as largely why
是基于 Jason Warner 的想法。Jason Warner 的想法是 GitHub Actions,而 GitHub Actions 在很大程度上是
65:40
get up got acquired by a Microsoft I'm compressing a lot of the history here just for the dovetail
GitHub 被 Microsoft 收购的原因。我在这里把很多历史都压缩了,只是为了衔接起来。
65:46
and so this get up next area was this laboratory where a lot of the innovation came from
所以这个 GitHub Next 领域就像一个实验室,很多创新都是从那里出来的。
65:50
that's where get up co-pilot came from and a lot of the race and current status of the race
那就是GitHub Copilot的由来,以及很多竞争和当前竞争格局的现状——
65:56
of where we're at was was uh you know around get a co-pilot being tab completion they were the first
其实是围绕GitHub Copilot的tab completion展开的,他们是第一个,
66:05
they were the first while factor and here they are the the late runner not the front runner
他们是第一个真正的转折点,而现在他们成了后来者,不是领跑者。
66:10
of this yeah it's just kind of wild to see the picture kind of come full full pendulum
对,就是挺魔幻的,看着这个局面像钟摆一样完全摆回来了。
66:18
there on that and you know Microsoft this Microsoft has any race in the coding
而且你知道,微软,微软在这场编码竞赛里也有参与。
66:24
industry right now besides just co-pilot right I mean is that the story of co-pilot is so you know
除了co-pilot之外,现在行业里其实还有别的,对吧?我是说,co-pilot的故事就是那种承诺,然后我们有Chris,我们有Chris,我们有来自Chat的Codex,我们有Claude,或者叫Claude Code,主要是终端用的,显然,然后还有那个叫什么来着,Windsurf,我记得是,而且我挺确定Windsurf——等等,它是不是被收购了?是被Microsoft收购的吗?我记得好像有什么反重力之类的,反正,对,还有Replit,对,真的,Replit有些挺酷的东西,我还没用过他们的产品,但我认识一些人在用,所以这个领域其实是有格局的,不是只有两家,但我觉得,我对Microsoft真正感到遗憾的是——
66:33
the promise and we have Chris uh we have Chris uh we have codex from chat to begin we have Claude
这个承诺,我们有Chris,呃,我们有Chris,呃,我们有来自Chat的Codex来开场,我们有Claude。
66:39
or Claude code which is primarily terminal obviously um and then we have what's the
或者Claude Code,它主要是终端工具,显然,嗯,然后我们还有那个什么来着——
66:45
called windsurf I believe and I believe winds are pretty sure didn't it no I just have got acquired
叫 Windsurf,我记得是。Windsurf 挺确定的,不是吗?没有,它刚被收购了。
66:54
but what's it acquired by Microsoft I remember there's some anti gravity anyway and everything is
但它是被微软收购的,我记得好像有点反重力什么的,反正就是那样。
67:01
yes co- and replete yeah true yeah and then the replete is some pretty cool stuff I haven't
是的,对,还有replete,确实,然后replete有些挺酷的东西我还没见过。
67:07
used their stuff yet but I know some people who are and there is a landscape there is a landscape
还没用过他们的东西,但我认识一些人在用,而且那边确实有一片天地,确实有一片天地。
67:12
it's not only two but but but I think um what I what I really find sad about Microsoft is that
不仅仅是两家的问题,但我觉得,嗯,关于微软,我真正感到遗憾的一点是——
67:19
I think they have the head screwed in the right place but they just don't have the execution right
我觉得他们脑子是清醒的,就是执行上没跟上。
67:25
like yeah they they came up with co-pilot they were the first investors in open AI the first big ones
对,你看,他们搞出了 Copilot,也是 OpenAI 最早的一批大投资人。
67:36
that they made it big they fully banged on it and now they seem like they profit the least of
他们当时是全力押注了,结果现在看起来反而是赚得最少的。
67:43
yeah I'm not really sure but uh I just think it is kind of well to look back at you know we were
对,我也不太确定,但我觉得回头看挺有意思的,我们当时都特别迷 GitHub Copilot 的 tab 补全、函数补全那些东西。
67:50
all enamored with get up co-pilot tab completion function completion things like that
现在它反而不是这场竞赛里的主要玩家了,但 GitHub 好像还是在这上面押了很大的注。
67:56
and and now it's not really the major player in the race but it seems like get up is banking big on
不过作为团队和个人,像你、像我,我们都对 GitHub 的未来不太确定。
68:04
that but as a team and individuals like you bar and we are that have have we're not
我也不知道,我真的不知道,但我知道他们……
68:12
sure of the future of get hub and I don't know either I just don't know but I know that they're
我对GitHub的未来也不确定,我也不知道,我真的不知道,但我知道他们……
68:18
they seem to be largely focused on co-pilot and their inf their uptime has been down dramatically now
他们似乎主要把精力放在co-pilot上,而且他们的正常运行时间最近大幅下降了
68:27
more woodward who's a developer advocate for you know the dev team there he's come out and talk to
还有Woodward,他是开发者布道师,你知道的,就是开发团队那边的,他出来聊过这事
68:32
about it uh Ryan Dagle COO not CEO because there is no CEO of get up anymore
嗯,Ryan Dagle,COO,不是CEO,因为GitHub现在已经没有CEO了
68:39
uh came out of the woodwork and started talking on twitter about slash x around these things
他突然冒出来,开始在Twitter上聊这些事,用斜杠X什么的
68:43
and it's cool please talk about it but there's something going on there and there's something changing
聊这个没问题,但那边确实有点事在发生,有些东西在变
68:48
there and uh there's codeberg now which I'm not even sure who's moving to codeberg
然后现在还有Codeberg,我甚至不确定谁在往Codeberg迁移
68:53
I think a lot of it might be potentially self-hosted so what keeps you at get up these days if
我觉得很多人可能更倾向于自托管,所以如果你们不是开源项目的话,现在还有什么让你留在GitHub上的理由呢
68:58
you're not open source you know if you can have a commissary this is more dramatically open source
如果你能自己搭一套的话,那开源属性反而更彻底了
69:04
like you were before what keeps you what keeps get up your epicenter it's it's not really
像你之前那样,是什么让你——是什么让你撑下去的,你的核心动力是什么?其实这跟你的节目关系不大。哦不,你看,如果GitHub的用户群变成了agents,那这生意就不太好做了。是啊,你知道,整个社区——因为我纠结的原因在于,嗯,做那种高端的开源项目,或者你可能想改进某个你公司依赖的库。我的意思是,就算在今天,cloud code已经能分析你的代码库了,它能发现你依赖的某个开源组件有潜在漏洞,然后它可以自主地去访问那个仓库项目,自己开一个PR,试图把你的修复合进去——这种事在今天并不是不可能。我不太确定它是不是已经在大规模发生了,但绝对是有可能的。
69:08
much of your episode oh no and look what what happens if if the user base of get hub is agents
你节目里大部分内容,哦不,你看,如果GitHub的用户群变成agents会怎么样?
69:16
it's not a really nice business yeah you know the whole community because the reason why I struggle
这不是一门特别好的生意,是的,你知道,整个社区之所以这样,是因为我纠结的原因。
69:23
with that one and I want to maybe and maybe you can draw this line too is largely agents but is
关于那个,我想说——也许你也会这样画线——这些很大程度上是 agents,但确实,
69:29
largely agents they're on behalf of a human so that's where I I draw the line because I've
它们是在代表人类行动。所以我的分界线就在这儿,因为我有
69:36
got agents and I'm a human being and so I have intent right and those agents are acting on my
agents,而我是人类,所以我有 intent,对吧?这些 agents 是在替我
69:41
behalf and so bots versus agents maybe a little bit different and I'm not sure how do you draw the
做事。所以 bots 和 agents 可能有点不同,我不确定你会怎么划那条线。
69:48
one there well how how much is it a human intent if you ask Claude like research the top 10
一个是有那么,嗯,到底有多少是人类的意图,如果你让Claude去研究前十名
69:55
frameworks and and and then of those repositories pick the most popular issue and open a PR for it
好吧,那条线上到底有多少是 human intent?如果你让 Claude 去 research top 10
70:03
is that really your intent I mean it's no different than search right and search would still be
frameworks,然后再从那些 repositories 里挑最热门的 issue 并开一个 PR,
70:09
you would still say it's a top search results right it's just a new way to search
那真的是你的 intent 吗?我是说,这跟 search 没有区别,对吧?search 仍然会
70:16
you're skipping a lot of intention that's what I'm saying like your agent makes a lot of assumptions
你跳过了很多意图,这就是我说的,你的智能体会做很多假设
70:21
and decisions that detach you from it I would say yeah that line will continue to be examined and
和决定,让你和它脱节,我会说是的,那条线会继续被审视和
70:32
blurred in my opinion I think I sit on the side that if I were making that search to say hey
模糊化,在我看来,我觉得我站在这一边——如果是我发起那个搜索,说嘿
70:38
go out and find me the top 10 repositories and help me learn how to commit a PR I think that's
出去帮我找前十的代码库,帮我在学会怎么提交一个PR,我觉得那
70:45
still user intent I would probably still draw that back to user intent I think that's cool and I
仍然是用户意图,我大概还是会把它归结为用户意图,我觉得那很酷,而且我
70:49
think everybody should do that but if that AI makes that decision for you and just makes it for you
觉得每个人都应该这么做,但如果那个AI替你做那个决定,直接替你做完了
70:57
the PR and everything you no longer have any emotional connection to that you might not even know
PR和所有一切,你就不再有任何情感连接了,你甚至可能都不知道
71:03
which repository your agent committed to yeah I suppose if it's fully autonomous and there's no
你的代理提交到了哪个仓库我猜如果是完全自主的而且没有
71:09
awareness and the intent is very thin then it does get thinner obviously I think I think it's more
意识和意图非常薄弱,然后显然会变得更薄弱。我觉得这不仅仅是AI agent的问题。我认为整个agent这种东西——首先,agent是个糟糕的名字,因为从理论上讲,agent意味着一个有自己目标和自主决策的人格,对吧?其他一切对我来说就像是被AI放大的人类,对吧?比如tab completion和autonomous coding是不同的,对吧?就像你还在写代码,但你有auto completion——我们已经有词句的auto completion 15年了,这其实没那么夸张。但是,我认为在编程领域真正的创新是它真的能用了,而不仅仅是胡扯。我们应该……但是,对很多人想象的那个autonomous future,就是……
71:16
than AI agent only I think this whole agent thing well first things first agent is a horrible name
比AI代理我认为整个代理的东西首先代理是个很糟糕的名字
71:23
because agent theoretically means there is a persona that has its own objectives and autonomous
因为代理理论上意味着有一个人格拥有自己的目标和自主的
71:31
decisions right everything else to me is like a human scaled with AI right like tab completions
决策对吧其他一切对我来说就像是人类用AI扩展了能力对吧就像标签补全
71:38
are different to autonomous coding right like you are still writing codes but you have auto
和自主编程是不同的对吧你仍然在写代码但你有自动
71:43
completion we've had auto completion for words since 15 years like that's just not that crazy
补全我们15年前就有词语自动补全了这其实没那么神奇
71:51
but but I think the innovation came for coding that it was actually working and not just
但但我认为创新在于编程上它真的有效而不只是
71:58
brambling we should but to the the the autonomous future that a lot of people are imagining is
胡言乱语我们应该但那个很多人想象的自主的未来是
72:07
what I just said that you have this coding agent who wakes up at 8 a.m well doesn't sleep doesn't
我刚才说的是,你有一个 coding agent,它早上 8 点“醒来”——好吧,它不睡觉也不需要睡,然后就拼命干活,接赏金任务,在网上四处搜索目标。
72:13
need to and and grinds did have bounties searches the web for whomever probably probably the most
可能最赚钱的 agent 会是 hacker agent,你知道的,就是那些把“赏金 vs 敲诈”当作 metric 来尝试敲诈你的家伙。
72:24
profitable agents will be hacker agents you know that try to extort you on a bounty versus extortion
但假设你是个 white hat hacker agent,嗯,你大概会自主地在网上搜索,找那些有意思的 repositories。
72:34
metric but let's say you're a white hack white hat hacker agent um you would probably autonomously
也许你在找你公司正在依赖的 repositories,试着把你公司的 policy 塞进那个偏门的优质开源项目里。
72:43
serve the web you would find interesting repositories um maybe you are looking for repositories
或者你可能想改进某个公司依赖的 library。
72:49
that your company is depending on you try to maybe put your own company policy into that
我的意思是,现在其实 cloud code 已经能分析你的代码了。
72:57
fringe um premium open source project or you want to maybe you're trying to improve a certain
边缘的、优质的开源项目,或者你可能想改进某个特定的东西。
73:05
library that your company depends on I mean even today already cloud code could analyze your code
贵公司所依赖的库,我的意思是,即便在今天,cloud code 已经能分析你的代码了
73:10
base today and it could find a potential vulnerable open source dependency you depend on and it would
基于今天的情况,它可能会发现你依赖的一个潜在有漏洞的开源依赖,然后它会
73:18
then it could autonomously visit that repository project and open a PR itself on that project trying
然后它可以自主访问那个repository项目,自己开一个PR,尝试在那个项目上做修改。
73:26
to get your fix into like that is not impossible today that's I'm not sure if it's happening at scale
要在今天做到这一点并不是不可能,我不确定这是否已经在大规模上实现了。
73:33
it's probably happening in installation but theoretically speaking your agent could hit a wall and
这很可能发生在安装过程中,但从理论上讲,你的agent可能会撞到一堵墙,然后自主地提交一个PR到那个依赖仓库里,对吧,那就不再是你的决定了。你的决定是改进你的产品,但agent自主决定跑出去,在别人的仓库里开一个PR。对我来说,这和自动补全差得太远了。你说“Adam,我想改进我的产品”,对吧?所以你是支持还是反对那种情况?那种特定的情况,我觉得看起来挺利他的,虽然它可能——你知道的——离我最初的意图隔了一两步。最初的意图是了解我依赖图的安全性,然后隔了两步之后,就是去搞清楚哪些依赖有问题。
73:39
then autonomously raise a PR and that dependencies repository right that's not no longer your decision
然后自动提交一个PR,那个依赖仓库的事就不再由你决定了。
73:45
your decision was to improve your product but the agent made the autonomous decision to go out and
你的决定是改进你的产品,但agent自主决定走出去
73:51
hunt and open a PR and someone else's repository yeah that to me is very detached from
去hunt并给别人的仓库开一个PR,是的,那对我来说非常脱离实际。
73:58
tap completion you Adam wants to improve my product yeah so are you for that against that then
点击完成,Adam想改进我的产品,是啊,那你对此是支持还是反对呢?
74:05
that that particular I mean that seems altruistic like while it may not it's you know one step
那个特定的,我是说,那看起来挺利他的,虽然可能不是——你知道,只是一步而已。
74:11
or two steps removed from my original intent original tent is to learn about the security of my
或者离我最初意图差一两步,我最初是想了解我自身的安全问题。
74:16
dependency graph and then the two steps removed is you know figuring out which ones have
依赖图,然后去掉两步之后,就是你知道要弄清楚哪些有
74:22
its issues and correcting them or finding a correction and submitting a PR are you for that against
它的那些问题,以及修正它们,或者找到修正方案然后提交一个PR——你是支持还是反对这个?
74:28
that well I think us as this the the the tech community we need to find we need to find peace with
嗯,我觉得我们作为技术社区,需要找到一种和解的方式,去接受一个事实,就是即使这个GitHub用户有个真人头像,那个PR里其实一个字都不是他写的,对吧?因为这就是现实。所以首先,我们得接受这一点。然后第二件需要和解的事是,那个人在开这个PR的时候,到底有没有想过我的项目?他们知道这个项目吗?认识我吗?喜欢我吗?他们有相同的价值观吗?他们的利他动机是什么——是为了改善他们自己的依赖关系,还是为了找工作,因为他们跟Claude Code说,嘿,我失业了,帮我找最好的20个……
74:41
the fact that like even though this GitHub user has a human avatar this GitHub user has not written
尽管这个GitHub用户用的是真人头像,但他其实什么都没写过。
74:48
a single word of that PR right because that's just a reality right so we need to be first we need
PR里的一个字对吧,因为这就是现实,对吧,所以我们必须得是第一个,我们必须得——
74:54
to be okay with that and then the second thing we need to make peace is did that person even think
首先要接受这一点,然后第二件我们需要释怀的事情是,那个人到底有没有想过这件事。
75:00
about my project when they opened this PR like are they aware of it do they know me do they like me
关于我的项目,当他们开这个PR的时候,他们知道这事儿吗?他们认识我吗?他们喜欢我吗?
75:07
do they have the same ethics what is there altruistic intent is it to improve their own dependency
他们是否有相同的伦理观?他们的利他意图是什么?是为了改善自身的依赖性吗?
75:15
or is it to find a job because they ask cloud code like hey I'm unemployed like find the best 20
还是为了找工作,因为他们会问云代码,比如“嘿,我失业了,帮我找最好的20个”。
75:20
repositories and and get my name out there or is it even trying to build it back door or a break
在仓库里刷存在感,让我的名字被看到,还是说干脆试着走后门,或者搞个破坏性功能,或者改一个以前点击率最高的按钮,现在你懂的,你也可以这样——你不一定要是黑客,对Calacom提一个让产品变差的PR并不违法,对吧?现在这不违法,但非常不道德,不过你不会因此进监狱。如果你让Cloud Code把Calacom搞差,它会说,好啊好啊,没问题,我把登录按钮删了吧。你知道的,咱们干脆猛打右舵,聊聊你取得的成功。我在节目里提过,我看到你投了一笔很小的钱,当然,我当时很乐意投,因为你知道的,我一直在用County,我更喜欢叫它Better。
75:28
feature or change a button that was previously most clicked and now it's you know you can also you
功能或者改动一个之前点击最多的按钮,现在你知道你也可以——
75:34
don't have to be a hacker to it's not illegal to raise a PR against calacom that makes our product worse
不必是黑客,对Calacom提一个让我们的产品变得更差的PR也不违法。
75:41
that's not illegal right now um highly unethical but you don't go to prison for that if you ask
这目前并不违法,嗯,非常不道德,但如果你去问的话,你不会因此坐牢。
75:48
cloud code to make calacom worse yeah it'd be like okay dokey sure let me let me remove the login button
云代码让calacom变得更糟,是啊,那就会像是,行吧行吧,没问题,那我把登录按钮删掉好了。
75:57
you know let's dovetail hard core to the right if you don't mind and let's talk about the success that
你知道的,咱们干脆直接往右硬切一下,如果你不介意的话,来聊聊那个成功案例吧。
76:06
you've had I mentioned in the show I see you'd invest for a very small check of course but I was
你在节目里提到过,我看到了,你当然是用一笔很小的投资投的,但我当时就……
76:13
very happy to do that because you know I was using county I like to call out better I like
非常乐意,因为你知道我之前一直在用County,我喜欢把它叫作“更好的选择”。
76:18
your mission we had you on the podcast I like your mission I like you know this was a lot of the
你的使命,我们之前请你上过播客,我很认同你的使命。你也知道,当时以商业开源公司的身份出来,确实是个很热门的方向。我们都认识JJ,我记得你最初那轮融资,OSIS capital那边也有参与和支持,所以其实是有一些历史渊源的。但跟我说说,作为一个种子投资人,给我一个幕后视角,看看现在正在发生或者说一直在发生的这些成功,到底是怎么回事。嗯,其实我觉得我们很幸运。我们第一次聊的时候的话题就是,这些商业开源创业公司都是从哪儿冒出来的,而且从我看到的来说,它们都做得很好,我也是尽量跟那些人保持接近。开源这个东西,当时几乎就像——怎么说呢——就像一种被期待了太久的东西。
76:24
rage at the time to come out as a commercially open source company we both know JJ I think you
当时以商业开源公司的身份出来,确实让人抓狂。咱俩都知道,JJ,我觉得你——
76:28
were part of OSIS capital in terms of your initial raise and support there so there's some history
你们在OSIS Capital的早期融资和支持方面有过合作,所以算是有一些渊源。
76:33
there but tell me about uh give me as a maybe a seed investor give me a give me a glimpse behind
但跟我说说,嗯,作为一个可能的天使投资人,给我一个,给我一个幕后的 glimpse。
76:40
the scene of the success that is happening or has been happening yeah um look I mean we we are blessed
成功正在发生或已经发生的场景,嗯,你看,我的意思是,我们很幸运。
76:47
in terms of timing and the the Renaissance of open source I believe that might even
就时机和 open source 的复兴来说,我相信那甚至可能就是我们第一次对话的话题,比如这些商业 open source 创业公司都是从哪来的。而且据我所见,那些我想要走得近的人都做得很好。open source 几乎就像——呃,怎么说呢——就像是我们渴望了太久太久的东西,而它依然在打拼。我觉得现在又更难了,但就我这一代的 open source 公司来说,我觉得它们做得相当成功,也收获了很多好结果。呃,而且,你看,open source 很棒,我爱 open source,我真希望我们不要处于这种让人无法视而不见的威胁之下。但是,嗯,所以 calicom 一直在成长。
76:52
been the topic of our first conversation like where do all these commercial open source startups come
这是我们第一次对话时就聊过的话题,比如这些商业开源初创公司都是从哪儿冒出来的。
76:57
from and and they all doing great from what I've seen the people that I'm trying to be close to
而且,而且他们都做得很好,就我所见,那些我想亲近的人。
77:03
open source was almost like uh like what do you call it like um wish that for way too long and
开源在很长一段时间里几乎就像——呃,怎么说呢——就像一个愿望,而且这个愿望持续得太久了。
77:11
it was still striving I think now it's getting harder again but I think my vintage of open source
它当时还在努力,我觉得现在又变难了,但我认为我那一代的开源公司,在做的这些事上还是挺成功的,有很多好的结果。而且,而且,开源真的很棒,我爱开源,我希望我们不用面对这种威胁,就是那种你没法视而不见的东西,但,所以Calicom一直在增长,我当时特别惊讶,他们营销里直接说“我们要吃掉手续费”,我觉得这对营销来说很棒,因为你的市场会想,哇太好了,这是个特别好的诱饵,咱们追吧,吸引点人过来,但你实际上是在告诉市场,我们要亏钱,我们不投资,我们拿手续费,你基本上是在说,别投我们。
77:19
companies has been um pretty successful with what they're doing there's many good outcomes
这些公司在他们做的事情上算是相当成功了,有很多不错的结果。
77:25
um and and and and look open source is awesome I love open source I wish we would not be
嗯,而且,而且,而且,你看,开源真的很棒,我很喜欢开源,我真希望我们不会……
77:32
under this threat which just like can't close your eyes to it but um so no calicom has been growing
在这种威胁之下,就像你没法对它视而不见,但嗯,所以Calicom一直在增长。
77:39
fantastically um we're very happy the teams teams happy we're reaching I'd say like the milestones
太好了,嗯,我们非常开心,团队、团队都很满意,可以说我们在达成,我想说,那些里程碑
77:46
we we set for us very low-chirn um high growth you know sars high margin sars we we don't have a single
是我们给自己设定的,非常低的流失率,嗯,高增长,你知道,SaaS 高毛利,SaaS。我们连一个
77:55
AI product that's catching on which also means we're not burning any AI tokens which means our margins
能火起来的 AI 产品都没有,这也意味着我们没在烧任何 AI tokens,也就是说我们的毛利
78:01
are great still great it's uh it's quite funny when I talk to founders who like oh my god we're
依然很好,还是很好。嗯,挺有意思的是,我和创始人聊天的时候,他们会说,天哪,我们
78:07
doing five million and and they are now and I'm like okay and how much what's the bottom line and
做了五百万,而且他们现在……然后我就说,好吧,那你们的 bottom line 是多少?然后
78:13
like oh I mean we we're burning 10 million so like wow fantastic so it's like um I mean look
他们说,呃,我是说,我们烧了一千万。所以我就说,哇,太棒了。所以,嗯,我是说,你看
78:22
every business is great if you're selling uh like a dollar worth of AI credits for 10 cents you know
每个生意都很棒,如果你把价值一美元的 AI credits 卖十美分的话,你知道
78:30
like that every business is fantastic if that's your business model right like if you and then
就像那样,如果那是你的商业模式,那每个生意都会很棒,对吧?就像如果你……然后
78:37
you've seen this on twitter you know like all of these coding assistance are like adding rate
你在 Twitter 上肯定见过,你知道,这些 coding assistance 都在加 rate limits、削减 usage,还想把你升级到 200 美元的套餐。
78:42
limits and reducing usage and trying to upgrade you into two hundred dollar plans and you know
AI 领域的 economics 根本说不通——至少现在说不通。
78:49
like the economics don't make sense in the AI space they they don't make sense yet I maybe they
也许以后能说通吧,但这就是 Uber 那种事。
78:55
will but it's a it's it's an uber type thing what's like how is this uber so cheap about
就像在问“Uber 怎么会这么便宜?”废话,有人掏钱补贴呗。
79:02
duh somebody's paying for it you know 15 dollars from sf airport to the city yeah right
你想啊,从 SF 机场到市区只要 15 美元,对吧?
79:11
yeah that doesn't have any more but it did what it did fantastic times I was loving it that was
是啊,现在没这好事了,但当时确实有,那真是神仙日子。
79:18
great that was for good times you know it's like oh god 80 bucks for that ride wow one dollar delivery
我可太喜欢那时候了,特别棒。
79:25
door dash right that was good I saw some recently they said we'll eat I can't recall what it was but
那真是好时光。
79:33
I was so surprised by it they literally said in their marketing we'll eat the fees I don't
我对此感到非常惊讶,他们真的在营销里说“我们会吃掉这些费用”,我当时就想,这不可能吧。
79:39
like that's great for marketing because your market is like sweet you know this is a great carrot
这营销上很棒,因为你的市场会觉得,哇,这真是个诱人的胡萝卜。
79:45
let's chase let's get some people attracted but you're literally telling the market we're going to
咱们得吸引点人过来,但你这是在明摆着告诉市场,我们要……
79:50
lose money we're not investing we're taking the fee you're basically saying do not invest in
亏钱我们不投资,我们只收手续费,你基本上是在说别投资
79:56
this business unless you like to lose money yeah I thought it was kind of funny I was I told my wife
这门生意除非你喜欢亏钱,不然别碰。对,我觉得挺搞笑的,我跟我老婆说,宝贝,这基本上就是说,咱们就是烧钱来抢这个市场,就当是营销补贴了。Adam,你要是想搞一个增长最快的创业公司,搞AI流的话,你可以上个落地页,写“拿一个能用的Claude API key,价格只要一半,我们补贴50%,但你照样得付钱给我”。然后你把它发到Hacker News上,第一年就能做到一个亿的营收,但你得烧掉两个亿,因为你知道,你付一半嘛,但你作为一家第一年就做到一个亿的初创公司,你可以去跟所有投资人吹。
80:02
I'm like babe that that basically says let's we're just gonna lose money here to get this business
我就像在说,宝贝,这基本上就是说,咱们就是在这儿亏钱来把这家公司做起来。
80:07
we're gonna subsidize it as marketing Adam if you want to have the fastest growing startup
我们会把它当作营销来补贴,Adam,如果你想要成为增长最快的创业公司的话。
80:12
into stream you could launch a landing page and you say get a clogged API key that works
进入流媒体后,你可以发布一个落地页,然后说搞到一个能用的API密钥就行
80:22
for half the price we pay 50% of it but still pay me right so so you're gonna have you
我们付一半的价格,也就是50%,但还是得付给我,对吧?所以你就得……
80:29
pull this on the hack or news and you're gonna make like a hundred million in the first year
把这个发到Hack或News上,第一年你就能赚个一亿左右。
80:35
and you're gonna burn two hundred million because that's the amount you know you pay 50% of it
而且你会烧掉两亿美元,因为你知道,这个数额里你有一半要付出去。
80:39
but you're gonna be a startup making a hundred million in the first year and you can go to every
但你会是一家第一年就赚一亿美元营收的创业公司,然后你可以去找每一家……
80:43
podcast and and and say this is how we made a hundred million in the first year without saying you
播客里说,和和和,然后说这是我们第一年怎么赚到一个亿的,但就是不提你烧了两个亿。对,但说实话,这基本上就是现在很多创业公司在干的事。他们加一点风味、一些提示词、一些系统提示、一些界面、一些侧边栏、一些编排逻辑,还有拖拽功能。但很多这类创业公司其实就是在做这些,不是五五分账那种,而是……你知道的,去搞清楚它到底为什么这么好用。但AMP,你碰巧用过AMP吗?嗯,在Sourcegraph开源之后吧,AMP本来是Sourcegraph的一个子产品,当时已经挺火了,然后就独立出来成了自己的公司,所以现在叫AMP Code In或者AMP In One,具体哪个我记不清了。一个免费模型,靠广告来买单,现在改成那样了,大概一天十美元。
80:49
burn two hundred million yeah but that is essentially what sadly a lot of startups are doing right now
烧两亿美元,没错,但可悲的是,这基本上就是现在很多初创公司在干的事。
80:55
they add some flavor some prompts some system prompts some UI some side bars some orchestration and drag
他们加了一些风味,一些提示词,一些系统提示,一些界面,一些侧边栏,一些编排和拖拽操作。
81:01
and drop but a lot of these startups are simply doing that not with a 50 50 split but you know
但很多这类初创公司并不是按50比50的比例来做这件事,你懂的。
81:07
maybe a 5% to 95 or 10% split so in my eyes it's not a great business but for some it works if
可能是5%对95%,或者10%的分成,所以在我看来这不是一门好生意,但对某些人来说,如果能
81:17
you can raise billions of dollars you can do that for quite some time yeah the one agent that
你筹到几十亿美元,那你就能撑很长时间。对,就那一个agent,它没有
81:21
hasn't done that and has done it hasn't done it to the degree what am I trying to say there
做到那一点,而且它也做了,只是没做到那个程度——我在说什么来着?那里
81:30
they haven't they famously come out and said we're not gonna sell it for less than it should
他们没有。他们曾公开说,我们不会以低于它应有价值的价格出售它
81:35
it's actually expensive and we're charging appropriately as our friends over at AMP code
它其实很贵,而我们收费合理,就像我们在AMP code的朋友们一样
81:42
now they're wrapping open the eyes APIs they're wrapping anthropics APIs they're giving you versions
现在他们在封装OpenAI APIs,封装Anthropic APIs,给你各种版本
81:50
of GPT 5.4 codex etc they're giving you versions opus 4.5 at all the different variations of it
比如GPT-5.4 Codex等等,还给你Opus 4.5的版本,全部不同的变体
81:59
and they're sprinkling their own abilities on top of that and AMP is I don't know if it's
然后他们在上面叠加自己的功能。至于AMP,我不知道它是否
82:05
source graph because that's where its roots came from but um what makes it so good I'd love to
Sourcegraph,因为它的根就是从那里来的。但,是什么让它这么好用?我特别想搞明白它为什么这么好。
82:12
like learn what makes it so good but AMP I have you play with AMP by any chance here well after
比如去了解它为什么这么好,但AMP的话,你玩过AMP吗?
82:20
this podcast go and play with AMP AMP code.com I believe it was so successful for them that they spun
不过 AMP——你有没有玩过 AMP?
82:26
this out of source graph so AMP was a sub product of source graph which was already largely popular and
这是从source graph中衍生出来的,AMP是source graph的一个子产品,而source graph本身已经相当流行了。
82:33
very successful and they built their own agent called AMP and it was so successful they had to
这期播客结束后,去玩玩 AMP 吧。AMP code.com。
82:40
like spin it to its own company so now it's AMP code in or AMP in one of the two I'm not sure
把它拆出来成立了自己的公司,所以现在叫AMP code in,或者AMP in,这两个名字里我不太确定是哪个。
82:45
and if I have a really hard problem I just know I want to get right I've got to use AMP and they have
我相信它在 Sourcegraph 那边太成功了,所以他们把 AMP 从 Sourcegraph 里独立了出来。
82:52
a free model which is paid for by ads and now that's changed to that's it's like 10 bucks per day
一个免费模型,靠广告来付费,现在变成了那样,大概每天10美元。
82:59
you get and they basically said it wasn't successful it was they actually put a 10 million
他们基本上说那个不成功,他们其实在广告销售上做到了每年一千万美元的业务,最后还是关掉了。但总的来说,他们并没有在补贴token,而是合理定价并且从中盈利。
83:04
dollar per year business in ad sales on that and they close it down but like by and large they're not
嗯,其实没多少生意会对所有人都这样补贴,但它还是在稳步增长。对,另一个业务也是,我的意思就是,这取决于你想多激进地增长。我是说,你可以在AI和Rapid上加上自己的特色,做个好UI,然后转售,不亏钱就能赚钱,这完全没问题。只是这是个编码领域,竞争太激烈了,基本上没人真的……
83:11
subsidizing the tokens they're charging appropriately and profiting on it.
对他们收取的token费用进行适当补贴,并从中获利。
83:15
Well not a lot of businesses that don't ever do that to everybody else's but it's still growing
嗯,不是很多企业会对其他所有人的业务都这么做,但它还在增长。
83:19
quite well. Yeah well another business yeah I mean exactly it's it's like how aggressive do you
相当不错。是啊,另一个业务嘛——对,我的意思就是,这就像是你得多激进。
83:24
want to grow I mean again you can add your flavor on an AI and rapid and make a good UI
想要成长,我的意思是,你可以在AI和Rapid上加入你自己的风格,然后做一个好用的UI。
83:31
and resell it and and make make money without losing money like if that's perfectly fine it's just
转卖出去,然后在不亏钱的情况下赚钱,如果那样完全没问题的话,那就只是……
83:38
the it's a coding space it's just so competitive that like nobody's really
这其实是一个编程领域,竞争太激烈了,基本上没人真正……
83:43
in it for the UI it's just like where can I get the most comfortable lift
做这个就是为了UI,就是想着哪儿能获得最舒服的提升
83:47
money and but I mean companies that have not done this also is like mid-journey you know like
钱的问题,但我的意思是,那些没这么做的公司,比如Midjourney,你知道的
83:53
they've always been profitable to boot shop business they never raised funding and I don't
他们一直是盈利的,就是个开店做生意的模式,从来没融过资,我也不知道
83:58
know what revenue mid-journey is today but they found a way to profitably sell subscriptions and
Midjourney现在营收是多少,但他们找到了一个能盈利地卖订阅的方式,并且
84:07
rate limit accordingly I mean they pretty early built I mean they always built their own AI right
相应地做速率限制。我的意思是,他们很早就自己建了AI,对吧
84:12
I feel like they've ever bought other AI so maybe the margins make more sense for them because you
我觉得他们从来没买过别人的AI,所以也许他们的利润率更有意义,因为你
84:18
use a your own supplier you don't need to buy tokens you just need to buy just buy infrastructure
用的是自己的供应商,你不需要买token,你只需要买基础设施就行了
84:23
yeah they have that inference and the infrastructure and the cost to maintain the infrastructure
对,他们有推理能力、基础设施,还有维护基础设施的成本
84:29
keep it up supply but you're cutting out one you're cutting out one middleman for sure yeah
继续加油,供应方面没问题,但你确实砍掉了一个中间环节,肯定的
84:34
the one with your own market yeah it is a big mess there I think with I mean it's a big
对,你有自己的市场,我觉得那地方挺乱的,我是说管理起来很麻烦,但某种程度上你是自己管自己的烂摊子,对,所以你的成本中心不一样,你不是在买token,你是在买人工工时来生产和维护,还有硬件本身,管理硬件的正常运行时间,真的是硬件基础设施,就是实打实的裸机硬件,像他们说的那样,哦哇,Midjourney,Midjourney自称是第一个社区资助的AI研究实验室,这不错,我喜欢这个说法,看,我们很精简,自筹资金,团队一直在招人,Midjourney没有投资人,我们由自己的社区资助,这听起来像
84:39
mess to to manage but it is you're sort of in charge of your own mess yeah so your your cost
一团乱需要管理,但某种程度上你得自己收拾自己的烂摊子,对,所以你的成本……
84:46
center is different you're not buying tokens you're purchasing manhours to produce and to sustain
中心是不同的,你不是在买tokens,你是在购买manhours来生产和维持。
84:52
and hardware itself and managing that hardware is uptime yeah literally hardware infrastructure
而硬件本身,以及管理这些硬件的运维,说白了就是硬件基础设施的可用性。
84:57
like real hardware bare metal as they say um oh wow mid-journey mid-journey calls itself first community
就像真正的硬件裸机,正如他们所说,嗯,哦哇,Midjourney,Midjourney自称是第一个社区。
85:04
funded AI research lab that's nice I like that look we are lean self-funded to see the team
资金充足的AI研究实验室,不错,我喜欢那种风格。我们团队精简、自筹资金。
85:13
always hiring mid-journey has no investors we are funded by our own community that sounds like
一直在招人,中途加入也没问题,我们没有投资人,资金来自我们自己的社区,听起来像是——
85:20
the community has ownership which they do not so I'll break it to you but that's the same
社区有所有权,但他们并没有,所以我得跟你直说,但这是一样的
85:27
my customers are my investors which does yeah well I mean yeah non-dilutive capital means
我的客户就是我的投资人,这确实,嗯,对,我是说,非稀释性资本意味着
85:33
I own the ship anyway but I mean look it works I mean look it works for them and I think that's
反正船是我开的,但我是说,你看它行得通,我是说,对他们来说行得通,我觉得那
85:40
something like incredible that you can build AI businesses without burning credits burning
挺了不起的,你能在不烧积分、不烧掉整个——反正的情况下建AI业务,那我们怎么走到那一步呢?对,电信,我们不卖token,你还是没有啊
85:47
burning the whole anyway how do we get there I mean yeah telecom we don't sell tokens you still
对,我本来不想再提这个的,但如果你没有的话,那你的增长从哪来呢
85:53
don't have any yeah I wasn't gonna come back to say if you don't have any I what where's your
对,谁会想到人们还在用酱料,酱料没那么——不是,我是说
85:57
growth coming from yeah like who would have thought people still use sauce sauce is not that no I mean
嗯,是的,我是说,我觉得我们就是继续做好本职工作,打造一个好产品就行了
86:05
um it's uh yeah it's I think we just continue to do a good job and build a good product that
嗯,我觉得我们就是继续把产品做好,把活儿干漂亮就行。
86:12
people love and pay money for it's not everything else to be AI surprise surprise where where you
人们喜欢它并愿意为之付钱——它不是所有其他东西都得变成AI。真是意外意外。在哪儿在哪儿,你……
86:22
again another pun here but not on on purpose where are you spending your time in terms of product
这里又有一个双关,但不是故意的。就产品而言,你把时间花在哪里?
86:27
like where is the innovation happening that that contributes to growth what is making that happen
比如,推动增长的创新发生在哪里?是什么在促成它?
86:35
I personally I spend every every day at work um looking at product related topics um so pretty much
就我个人而言,我每天工作时都在看产品相关的话题,嗯,所以基本上
86:44
every major product decision goes over my desk or comes from my desk um which means not only you know
每个重大的产品决策都要经过我的办公桌,或者从我这里发出,嗯,这意味着不仅,你知道的,
86:53
larger new initiatives whether it's like an iOS app or browser extension but also um looking at
更大的新项目,不管是像 iOS app 还是 browser extension,而且嗯,还要看
87:00
existing features that we need to sharpen the edges not sharpened edges softly the edges
现有功能,我们需要把边缘锐化,而不是柔化边缘。
87:08
sharpened obviously border radius zero um and um yeah like fix tons of bugs um make sure to
很明显是锐化,border radius 为零。嗯,然后对,修复大量 bug,确保……
87:17
um you know get enough buy-in in the company and and assign resources so I would say um
嗯,你知道,要在公司内部获得足够的支持,然后分配资源,所以我会说,嗯,
87:24
I'm mostly responsible for the product quality today so if there's something inherently broken
我目前主要负责产品质量,所以如果有啥本质上坏了的东西,
87:30
please send it to me um I recently started to do sales again just because I enjoy doing it
请直接发给我。嗯,我最近又开始做销售了,纯粹是因为我喜欢做这个,
87:37
not because it's um like not because we're short staff but because I really just want to have this
不是因为,嗯,不是因为我们人手不够,而是因为我真的想跟客户
87:43
conversation with customers and learn from them and understand what they what they go through
有这样的对话,从他们身上学习,了解他们到底经历了什么。
87:48
it's more like a product exploration than necessarily closing the money um that's how I spend most
这更像是产品探索,而不一定是为了签单赚钱。嗯,我大部分时间
87:54
of my time with really just talking to customers and then trying to bring that to life
其实就是在跟客户聊天,然后试着把那些东西变成现实。
88:00
you want to take a uh I wouldn't call it a bug uh a bug fix maybe an issue let's call it an issue
你想处理一个——我不会叫它bug——也许算bug修复,或者一个问题,我们就叫它问题吧。
88:07
we do you want to take an issue to have in the air for me for sure yeah for sure isn't it my user
我们是不是该把这个问题拿出来聊聊?当然要,当然要,这不是我常干的事嘛。
88:13
I'll spin up my clock code and submit a PR um so we reschedule a lot uh we have in the past so we
我会把我的时钟代码跑起来,然后提交一个PR,嗯,所以我们经常改期,过去也一直这样。
88:20
either as change log we use uh cow.com to schedule all of our podcasts our entire workflow for
不管是做更新日志,我们都用cow.com来排所有播客,整个工作流,只要是跟播客相关的新活动都走这个,我在销售那边也一样,所有销售电话都是。
88:27
creating any new event that is podcast related and I do as well in sales so all my sales calls
我会跟很多创始人、CEO、还有我们广告客户那边的核心产品负责人聊很多,我们通过语音把他们请上播客,展示他们是谁,不是光我一个人念广告,这很特别也很有信息量,我们的听众特别喜欢,所以我做了大量排期工作,覆盖我们这边所有的业务面,嗯,所以改期就是核心中的核心。
88:34
I do a lot of conversations with founders CEOs key product leaders in companies that advertise
我经常和做广告的公司里的创始人、CEO以及核心产品负责人交流。
88:41
with us we have them on the podcast via voice and so we showcase who they are it's not just me reading
今天我们请到了他们,通过语音连线的方式参与播客,所以我们会介绍他们是谁,而不是光我一个人在那念。
88:47
an ad it's very unique and informative and our audience loves that uh so I do a lot of scheduling
这则广告非常独特,信息量也很大,我们的观众很喜欢。所以我做了很多排期方面的工作。
88:53
for all the surface area of what we do here and uh so rescheduling is at the core of the crux
就我们在这里所做的所有方面而言,重新调度确实是核心中的核心。
89:00
of what we do scheduling and also rescheduling because not everybody can show up and we even had a
关于我们做的 scheduling 和 rescheduling,因为不是每个人都能到场,我们甚至还 reschedule 过——你和我就有过。所以我面对的挑战之一,关于 rescheduling 的挑战就是:它本身运作得很好,唯一不太好的地方是,如果我想 reschedule,而我的 availability 决定了我能怎么 reschedule,我就没法突破这个限制,除非我进到 garden 里创建一个 override。比如我清楚自己的 schedule,我想 reschedule,而且想在自己的 schedule 上任选时间,而不是非得去折腾我的 availability,把它开放,再创建 override。我觉得这个流程可以更顺滑一些。而这是一个持续多年的挑战,因为它从来没被改过,而我也从来没告诉过你——我就只是默默干活。
89:05
reschedule uh you and I did uh and so the challenge that I face one of the challenge I face with
重新安排时间,呃,你和我之前聊过这个。所以我面临的一个挑战,或者说其中一个挑战是,重新安排这件事本身很好用,唯一不太好用的地方是,如果我想重新安排,而我的可用时间又决定了我能怎么重新安排,那我就没法打破这个限制,除非我进到日历里去创建一个override。比如我知道我自己的日程,我想重新安排,而且我想能在自己的日程里随便挑一个我想要的时间,而不是非得先去改我的可用时间,让它空出来,然后再创建一个override。我觉得这个流程可以更顺滑一点。而且这已经是个多年的挑战了,因为从来没改过,我也从来没跟你说过。我就是当天改当天,同样的逻辑,但我连这个都没法用简单的方式做到。我会告诉别人的是,直接去……
89:12
rescheduling is one it works great and the only part that doesn't work great is that if I want to
重新安排日程这个功能很好用,唯一不太好用的地方是,如果我想……
89:17
reschedule and my availability dictates how I can reschedule I can't break that unless I go into
重新安排时间,而我的日程安排决定了怎么重新安排。我不能打破那个安排,除非我进入……
89:24
the garden and create an override like I know my schedule and I want to reschedule it and I want to
花园里创建一个覆盖,比如我知道我的日程,我想重新安排它,我想
89:30
be able to pick whatever time I want on my own schedule not have to go jack with my availability
可以自己随便挑时间,按自己的日程来,不用去折腾我的空闲时间
89:37
to then have it open and create an override I feel like that could be a little smoother and that's
然后让它打开并创建一个override,我觉得那一步可以更顺畅一些。
89:42
been a multi-year challenge because it's never been changed and I've never told you I just worked
多年来一直是个挑战,因为从来没改过,而且我也从没跟你说过——我就是这么干的。
89:48
around it so here we are on the podcast how do you how do you feel about that that kind of change
所以我们就围绕这个来聊这期播客。你对那种变化感觉怎么样?
89:54
what have you experienced at yourself what do you think about that you know what I think I have
你自己有什么体会?你怎么看?
89:58
this on my never ending list of tickets for like at least a month and I think today is the time
你知道我怎么想吗?
90:05
where I finally get to ship that I'm I'm always annoyed I always talk about it with the team and
这事在我的 ticket 列表上已经躺了至少一个月了,而且那列表永远清不完。
90:15
then some it hits the fan and it gets deported but I do have to fix this and I do agree it's
我觉得今天终于能把它 ship 了。
90:21
very annoying and we will the UX has to be spotted maybe keep it keep it in the same UI that you
我一直都很烦。
90:28
do like a normal user would don't take me back to admin do it in the same reschedule
我老是跟团队说这事,然后每次一出状况,它就被 deprioritize 了。
90:35
and I'm not sure I would give that ability to the invited no do it to the inviting
但我确实得修它。
90:41
the one who's in charge yeah yeah because we've even had the reschedule podcast and we largely
负责的人是我,对对,因为我们甚至连播客的录制时间都改过。我们一般下午两点录播客,这个时间已经固定很久了。
90:48
record our podcast at 2 o'clock p.m. and that's been a standard for us for a long time it's where we
到了那个点,我们就会特意把当天的时间空出来,好让自己能真正投入到播客里。
90:54
mentally block off our own day to even be present in our podcasts but at the same time it may be
但与此同时,对方可能在欧洲,甚至在澳大利亚、新西兰、南非,或者在某个时区比我这边早12到15个小时的地方。
91:02
somebody who's in Europe or maybe even Australia or New Zealand or South Africa or somewhere in
我这边是 Austin, Texas,用的是 Central Standard Time,你懂的。
91:10
the region where the time is far ahead 15 12 to 15 hours in advance of my time here in Austin
所以可能会想把时间改到早上,同一天,还是同样的安排——但我也没法很轻松地去改。
91:17
Texas which is central standard time you know we'll want to reschedule to weigh out in a morning
我会跟大家说:直接放到日历上就行,我自己手动改。对,就在我自己的日历上改。
91:22
same day same same concept but I can't even do that in an easy way what I will tell folks is go
同一天,同一个概念,但我甚至没法轻松做到这一点。我会告诉人们的是,去吧。
91:30
ahead and put on the calendar and I'll manually change yeah exactly in my own calendar that's
好,直接放到日历上就行,我会手动改。对,就是改我自己的日历,这样一直没问题,我也能接受。但我想说的是,你懂的,界面还是同一个界面,因为那个 UI 确实很好用,功能也顺畅,但你要意识到我是管理员,给我多一点权限。甚至可能提醒我一下,比如“嘿,你懂的,我还没搞清楚这里是怎么回事”,但问题就是应该在那儿解决。你知道吗,我刚把这个写进我的 coding agent 里了,说不定接下来两分钟就能搞出一个 PI 来,那也太爽了,真的太爽了,赶紧跑起来。那会很棒。你是想说这会是个好产品吧?对,完全就是,完全就是我们刚才在聊的那个意思。你跟我讲一个特别让人抓狂的事,我同意,这确实特别让人抓狂。
91:34
been okay and I've been fine with that but I would say you know keep it in the same UI because it's
一直还行,我也能接受,但我想说,你知道的,还是保持在同一个UI里比较好,因为那是
91:39
great UI it functions well but recognize I'm an admin and give me a little bit more ability
界面很棒,功能也不错,但请识别出我是管理员,然后给我多一点权限。
91:44
and maybe even warn me like hey you know I don't know figured out here figured out but that's
甚至可能会提醒我,比如“嘿,你知道的,我还没搞明白,这里还没搞明白,但那是——”
91:50
where it should happen you know what I I just wrote this in my coding agent so maybe we get a
你知道的,应该在哪里发生——我刚刚把这个写进我的coding agent里了,所以也许我们会得到一个
91:58
PI in the next two minutes man that'd be so awesome that'd be so awesome kick that off so great
PI,接下来两分钟之内搞定的话,那就太牛了,太牛了,赶紧开始吧,太棒了。
92:05
I would be good product is what you're trying to say yeah that's exactly exactly what we were just
我会说,好的产品才是你想表达的意思,对吧?对,这正是我们刚才说的。
92:11
doing you know you tell me something that's really frustrating I agree it's really frustrating and
你知道,我跟你说个特别让人抓狂的事。我同意,这确实太让人抓狂了。
92:15
then it's my job to make that not so frustrating anymore I know you do that and then you just do
那之后我的工作就是让这件事不再那么让人抓狂。我知道你确实在做这个,然后你就直接做下去。
92:21
that and then you just do that over and over again until people really really like your product
对,然后你就一遍又一遍地这么做,直到人们真的真的喜欢上你的产品。
92:26
yeah make them happy make them happy right I know you just tweeted about this um on March 25th
是啊,让他们开心,让他们开心,对吧。我知道你刚在3月25号发推文说过这个,嗯。
92:34
just hit six oh no seven million ARR and I think you mentioned in the pre-call that numbers
刚刚达到六百万——哦不,七百万 ARR,而且我记得你在 pre-call 里提过那个数字。
92:43
north of that number by a little bit because your growth rate is 10 12 percent per month you said it
比那个数字稍微高一点,因为你的月增长率是10%到12%,你说过。
92:47
was the yeah I mean every month is different between five and 10 you know good months and that
呃,是的,我的意思是每个月都不一样,在5%到10%之间,你知道,有好的月份和差的月份。
92:53
months but yeah I'll never we were hoping to 3x per year as kind of like always been the agenda
但,对,我们一直希望能每年 3x,差不多这始终是我们的目标。
93:00
the milestone we want to go for which is yeah so we are looking now it was soon to eight million
这是我们想要去实现的里程碑,是的,所以我们现在看,很快就要到八百万了。
93:09
hopefully soon to crack the 10 and open some champagne and go to bed at 12 30 instead of 10
希望很快就突破一千万,然后开瓶香槟,在12点半就去睡觉,而不是10点。
93:16
three in the morning will you have a party and can I be able to come I'd love to celebrate hopefully
凌晨三点你会开派对吗?我能来吗?我很想庆祝一下,希望可以。
93:24
yeah we should yeah we we have a company retreat in Japan which we're really excited about so maybe
是啊,我们应该的。我们有个公司团建要去日本,我们特别兴奋,所以也许吧。
93:32
maybe that that would be safe if that overlaps with the 10 million milestone that would be really sweet
maybe that that would be safe if that overlaps with the 10 million milestone that would be really sweet
93:38
it would be so we'd be in June so April may June yeah maybe June of this year okay so you're
如果那能和1000万里程碑重叠的话就太棒了
93:44
thinking by June of 2026 potentially 10 mil ARR probably not probably not potentially it's
it would be so we'd be in June so April may June yeah maybe June of this year okay so you're
93:53
policy from the realm it's in the realm of possibilities yeah okay what what would what would
那就会是在六月,所以四月五月六月,嗯也许今年六月,好吧所以你
94:02
make you grow more and what would change your growth like one of the things that keep you up at
thinking by June of 2026 potentially 10 mil ARR probably not probably not potentially it's
94:07
night in terms of positivity and negativity I know open source was one of them and a threat there
觉得到2026年6月可能做到1000万ARR?大概不会,大概不会,但有可能,这
94:12
and we've talked about that but what are the positive sides and potentially some of the negative
我们聊过这个话题了,但积极的方面是什么?又可能有哪些负面的地方让你睡不着觉?
94:15
sides that keep you up we do have large customers right like we have a lot of grassroots but we also
我们确实有大客户,对吧?我们有很多草根用户,但也有大客户。
94:24
have large customers and I think there's a bit of a like a SaaS shop going through the industry where
我觉得整个行业现在有点像在经历一场 SaaS 洗牌,
94:31
like a lot of companies are really deeply looking at their vendor list and and try to cut corners
很多公司都在非常认真地审视自己的供应商名单,想尽办法偷工减料、压缩成本,
94:41
and cut costs and and come with the argument like oh but like we're paying you too much we can
然后抛出这种说法:“你们收太多了吧,我们一个周末就能把 code 写出来。”
94:46
buy code you in a weekend you don't have to buy code color come we literally open source just
根本不用买 code,我们本来就是 open source 的,直接 fork 我们就行了,又省钱又省 tokens。
94:51
fork us it saves you money and tokens like if you think that's the cost-cutting approach like
如果你们觉得那才算降本路线,那干脆 self-host 就好了,那反而容易得多。
94:57
just self-hosted portfolio like that's much easier but yeah that's still thing right so like I would
不过这种心态确实还是存在,对吧,所以我会……
95:04
say the entire SaaS industry is experiencing some sort of SaaS shop where you know just under
policy from the realm it's in the realm of possibilities yeah okay what what would what would
95:13
more due diligence than in the golden days of 21 where you know the pockets were a bit deeper and
在可能性范围之内,是的,好吧,那什么会
95:19
the money was flowing like champagne but I mean that's just not something that I only look at
钱当时像香槟一样哗哗地流,但我的意思是我看的不仅仅是那个。
95:27
that's pretty much everyone's looking at budgets and allocations and what to bring in house
基本上每个人都在看预算、资源分配,以及哪些东西要自己做。
95:33
scheduling up to this day is still really freaking hard like it's not something you can just
排期这件事到现在还是真的特别难搞,它不是那种你随便就能搞定的。
95:38
one shop like some other SaaS companies like we have internally stopped using certain products because
不像其他一些SaaS公司,我们内部已经停用了某些产品,因为。
95:45
it was a weekend of cloud code to to get to 70 80% of that functionality yeah sketching is just
那是一个周末的cloud code,才能达到那个功能的70%到80%。对,sketching就是这样。
95:54
like even the first 20% is just still really really hard so I think AGI has achieved the moment
哪怕是最初的20%也依然非常非常难,所以我觉得AGI实现的标志是
96:00
you can one-shot cal.com without forking that's my benchmark so yeah I bet it is that's pretty funny
你能一次性搞定cal.com而不用去改代码,这就是我的基准,所以没错我打赌就是这样,挺搞笑的
96:10
yeah I guess you know even as an investor in Cal and as a user of Cal because like anybody I've
是啊,我想说,即使作为Cal的投资人,也作为Cal的用户,因为像所有人一样,我也
96:19
thought about where do we spend our money now I don't think we spend a lot of money I think I'd
想过我们的钱该花在哪儿。我觉得我们花的钱不算多,我想大概
96:23
be like 30 maybe 60 bucks a month I don't know what the number is I want to say it's at least 30
是30,可能每月60美元吧,我不知道具体数字,但我想说至少是30
96:27
bucks though yeah for Cal and yeah even though we're an investor we're a paying user that does
美元吧,对,就Cal来说。而且即使我们是投资人,我们也是付费用户,这
96:32
make sense because why would you not but I think in any case I'm like maybe I can self-host I love
说得通,因为干嘛不呢。但我觉得不管怎样,我就在想也许我可以自己托管,我超爱
96:40
the self-host I'm a home lover maybe I can actually just go a different angle to Cal and not so much
自托管,我是个宅家的人,也许我其实可以换个角度来用Cal,而不是那么依赖它
96:46
say the 30 bucks that was not my concern I was like how much can how much change can actually
30块钱不是重点,我当时想的是,这东西到底能对我的利润产生多大影响。虽然一个月30块不算什么,但你知道,我真正关心的是,如果我自己托管Cal.com,我能获得多少控制权。你开源它是有原因的,你甚至都认可了那个Docker镜像,我可以直接跑,所以你把它做得超级简单,几乎没有任何不方便的地方,只要我想,随时都能自己托管。这事我确实想过,但没真去执行,它一直在我待办清单里,打算研究一下,但更多是作为一种“我能不能做到”的练习,而不是“我该不该做”。我觉得这正好是一个有意思的角度,来审视SaaS这件事。你一直在增长,但你有感觉到收缩吗?是不是那些自托管的人真的跑去自己搞了?我觉得不太可能是那种情况。
96:51
influence in my bottom line and while 30 bucks a month is not dramatic um you know what control
影响我的底线,而且虽然一个月30美元不算什么大数目,嗯,你懂的,控制权
96:58
can I get over self-hosting Cal.com you offered open source for a reason you even blessed the
我能理解你不想自己托管Cal.com的心情——你开源它是有原因的,你甚至为此祝福过它。
97:04
Docker image I could run so you make it super easy barely any convenience to self-host Cal if I want
Docker镜像我可以直接运行,所以你把它做得超级简单,几乎没什么门槛就能自托管Cal,如果我想的话。
97:11
to it's definitely crossed my mind I didn't execute on it it was in my to do list to look into it
这绝对在我脑子里闪过,但我没去执行,它一直在我待办清单上,想着哪天去研究一下。
97:16
but only as an exercise of could I not so much should I and I think that's an interesting place to
但这只是作为一种练习,看“我能不能”而不是“我该不该”,我觉得这是一个很有意思的出发点。
97:22
being around SAS do you have you felt because you're growing but have you felt a retraction and
在SAS周围,因为你在成长,你有没有感觉到一种收缩?
97:29
has it been that has it been self-hosters going and doing it I don't think that's going to be a case but
是自托管用户自己去搞的吗?我不觉得会是这样。
97:33
like no one's going to self-host Cal unless they really really want to well there's I think there's two
没人会自己去自托管Cal,除非他们真的真的想。我觉得人们自托管有两个原因,正如你正确指出的,一个是“我想折腾它、玩玩它、改改它”,另一个是安全方面的,比如把它放在自己的防火墙后面。这类人一直都存在,我们确实有政府和医疗行业的客户在自托管,对吧。而且他们——新的,或者说也包括——会付钱给我们,因为他们需要支持,需要反馈和帮助,还需要开发者办公时间以及合规方面的协助,这些我们都提供了。他们付的钱不少,所以我们确实有一小部分自托管并且付费的用户。他们现在绝对是我们最“小丑牌”式的客户群,我很久没看那个数据了,Cal。
97:40
reasons people self-host as you correctly identify one of them is um I want to tinker with it and
人们自己托管的原因,正如你正确指出的其中之一是,嗯,我想摆弄一下它。
97:46
play around with it and make changes um and the other one is security and like putting it behind
随便玩玩,改一改,嗯,另一个就是安全问题,比如把它放在后面。
97:52
your own firewall uh those people have always existed we we do have governments and healthcare
你自己的防火墙,呃,那些人一直都存在。我们确实有政府和医疗体系。
97:59
that self-host right um and they new slash also pay us because they want to and they need support
自己托管的话,嗯,他们新的那个斜杠功能也会付钱给我们,因为他们想要,也需要支持。
98:07
and they need feedback and help and developer our office hours and and compliance help is set up
他们需要反馈和帮助,还有开发者答疑时间,合规方面的帮助也都安排好了。
98:15
um they pay us well so we do we do have a really small amount of people who self-hosts and pay us
嗯,他们给的钱不少,所以我们确实有一小部分人自己托管并付费给我们。
98:22
now they're most certainly our joker file I haven't checked at it in a long time Cal
现在它们肯定是我们的小丑牌文件了,我很久没看过了,Cal。
98:29
come has um many polls has over a million installations so take it or leave it that's a really big
嗯,有很多投票,安装量超过一百万,所以信不信由你,这真的是很大的规模。
98:40
number we're not in totality or by a certain measure uh whatever docker hub tells me I don't know
这个数字——我们不是从整体上或者按某个衡量标准来的——呃,Docker Hub 告诉我什么我也不知道。
98:48
the it's the analytics of docker hub are really opaque but it's been pulled a million times now
Docker Hub 的分析真的很不透明,但现在已经有一百万次 pull 了。
98:55
is that a million customers no but it's also not ten um yeah so anywhere between ten and a million
那有一百万个客户吗?没有。但也不是十个。嗯,对,所以就在十到一百万之间。
99:02
people are using uh the self-hosted file container um so there's a big number it's not it's not
有那么多人在用那个 self-hosted file container。所以这个数字很大,不是,不是毫无意义。
99:10
nothing it's it's obviously not a billion people but it's you know it's a million polls um but um
显然不是十亿人,但你知道,是一百万次 pull。嗯,但是。
99:17
we don't charge them that's okay they would probably be on a free tier you know if these are
我们不向他们收费,没关系。他们可能本来就会在 free tier 上,你知道,如果这些是个人用户的话。
99:23
individuals there would be on a free plan our free plan is as liberal as the open source version
他们会用免费 plan。我们的免费 plan 和 open source 版本一样宽松。
99:30
we always wanted to be like you don't have to be self-hosting in order to get the product for free
我们一直想做到的是,你不一定要 self-host 才能免费得到这个产品。
99:37
right you can be on a SaaS tier and be for free right um I think where where the revenue is coming from
对,你可以用SaaS的免费层级,完全免费。我觉得收入的来源主要是,大家想快速推进,公司想快速推进,自己部署很花时间,而且把安全、更新和维护的责任都压在你身上,很多人就是不想干这些事。
99:43
is just um people want to move fast companies want to move fast self-hosting takes time it puts
我的意思是,为什么租房这么流行?因为有时候你就是想租,花钱请人搞定,然后水槽坏了有人来换,你懂的。
99:50
the burden on you to keep it safe and updated and and maintained and a lot of people just
对,限制你的负债,限制你的责任。对,限制你的问责,限制限制限制。
99:57
simply don't want to do that I mean why is renting popular sucks I'm it's just sometimes you
我也喜欢这样。我虽然不租房,我是房主,但我确实喜欢限制自己的责任。
100:05
just want to rent and pay people money and then when the sink is broken it's being replaced you know
就想租个地方,花钱雇人干活,然后水槽坏了有人来换,你懂的。
100:10
yeah limit your liabilities limit your responsibilities yeah limit your accountability limit limit limit as
对,限制你的负债,限制你的责任,对,限制你的问责,限制限制限制。
100:17
I like to do that I mean I don't rent purse in my homeowner but I do like to limit my
我喜欢这么做,我的意思是,我在自己家里不会去租什么名牌包,但我确实喜欢给自己设一些限制。
100:21
liabilities who doesn't that's just exposure right yeah yeah I mean even that I own my own cars to
负债谁不想要呢,那不就是敞口嘛,对对对,我的意思是,连车我都是自己买的,我不租,我会租服务什么的,但那些大件东西真不太会租。而且我认识一些人说过,这都是明智的,这不是非此即彼,或者说这可以是,你知道的,许可证密钥——你有没有仔细看过那个东西,当谈到闭源和源码可用的时候,唯一能真正使用它的方式就是靠一个许可证密钥,否则它就处于那种演示模式。我从来没见过TL draw的许可证,而且那其实是他们自己编出来的,这太有意思了,对,我前不久请他上过播客,那真是一次很好的对话,我给你一个TL;DR,我现在正看着它呢。
100:31
like I don't lease I lease services and things maybe but not really like those kind of large items
比如我不会租,我可能会租服务之类的东西,但那些大型物件真的不太会租
100:37
and I know people that have said all this is wise this is not one or or this can be you know
我知道有些人说过,这一切都是明智的,这不是一个或或,这可能是你
100:41
this goes from a cap X to a you know whatever X I mean simple I like to own things like yeah yeah
这从一个上限X到你懂的随便什么X,我是说我喜欢拥有东西,是啊是啊
100:49
I mean you can go either way so I imagine this shift from how you're forking your own code base
我是说你可以走任何一条路,所以我想象这种从你自己复刻代码库方式的转变
100:58
I imagine you've thought to some degree and maybe you haven't have you considered just literally
我想你在某种程度上已经想过,也许你还没想过——你有没有考虑过干脆
101:02
going close source completely and going like the TL draw route where they have TL draw license
彻底闭源,走tldraw那条路线,他们有tldraw许可证
101:13
it is literally not open source it's not even using e source available license it's just source
那真的不是开源,甚至不是用那种源代码可用的许可证,它就只是源代码
101:18
available and issuing out a license key and being very I guess smooth with how you might
可用,然后发一个许可证密钥,而且我猜在授权方面做得非常
101:28
license something so you might have an experimenter who's trying to figure it out maybe you've got
圆滑,所以你可能会有一个想搞明白的实验者,也许你有一个
101:33
a home lever who literally wants to home lab and host self-hosted and you just give an instant
家庭实验室玩家,他就想在家里搭个实验室自己托管,然后你直接就给他一个即时
101:38
license key have you ever examined that that wrote it all when it comes to close source source
许可证密钥——你有没有仔细看过那个东西?它把一切都写明白了,尤其是在闭源软件方面。
101:45
available and the only way you can really use it is literally with a license key otherwise
可用,而且你真正能使用它的唯一方式,实际上就是通过一个许可证密钥,否则不行。
101:51
it's in like a demo mode I have never seen the TL draw license and they actually made it up
这就像是在演示模式里,我从来没见过TL画许可证,而且他们真的是自己编出来的。
101:59
themselves that's so interesting yeah it's I had him on the podcast a little while ago it was
他们自己,这太有意思了。是的,我之前在播客里采访过他,那是没多久之前的事。
102:04
a really good conversation I'll give you a Tio a Tio DR of the I'm looking at it right now
这真是一场很棒的对话,我给你一个Tio对Tio的DR,我现在正看着呢。
102:11
those violations the TL DR of their success they largely sell an SDK so they don't even sell
这些违规行为,TL;DR成功的要点就是他们主要卖的是SDK,甚至都不卖成品软件。我们在播客里打了个比方,就像浓缩橙汁,你放冰箱里,加水才能喝,对吧?它甚至不是完整的产品,是个完整的SDK。他们卖的就是这个,而且是闭源的,只是源码可见。还有一些讨论,你知道的,他们在X上很出名地撤回了test week,因为你可以轻松从test week复制出TL;DR的结果。我肯定你也走过那条路,我见过那些威胁之类的东西。但我觉得那是因为威胁,我不是因为威胁而反对开源,而是因为那种威胁和想要保有的欲望。
102:17
you finished software we we came with the analogy during the podcast it's like orange juice concentrate
你完成了软件,我们在播客里打了个比方,就像浓缩橙汁一样。
102:23
that you put in your freezer you add the water right like it's not even a complete product it's a
你放在冰箱里的那个,加水就行,对吧?它甚至都不算一个完整的产品,它只是一个——
102:28
complete SDK right and that's what they sell and they sell it as close source it's source available
完整的SDK做对了,那就是他们卖的东西,而且他们是以闭源形式卖的,只是源码可获取。
102:35
and there's been some talk even you know they were out there on x famously pulling back their
甚至有一些讨论,你知道的,他们在X上很出名地撤回了他们的……
102:41
test week because you can easily replicate TL draw from the test we you know that's I'm sure
测试周,因为你可以轻松地从测试中复现TL的抽签结果,你知道的,我敢肯定。
102:45
you've been down that route I've seen that the threats and stuff like that but I think it's
你走过那条路,我见过那些威胁之类的东西,但我觉得那是
102:51
because of the threat I'm not anti-opensable because of the threat and the desire to have a
由于威胁,我并不反对开源,是因为威胁以及拥有一个……的愿望。
102:56
sustainable commercial company and have source available because of the reasons why source available
一家可持续的商业公司,同时把源码开放出来,因为开放源码这件事本身,从信任角度是说得通的,但你需要建立那种联系。所以在这种情况下,许可证密钥能让你做到的是,基本上每个用户都能拿到一个许可证密钥,而且你在分发这些非付费密钥时非常宽松。你会希望在这方面非常开放,甚至可能即时发放,比如给一个家庭实验室的密钥。但你会拿到一个邮箱和一个名字,这样你就能建立一种关系,这和“这是我们的免费开源代码”是完全不同的。你知道,cal.com,d-y-d-y-d-y-y-y,Adam你今天到底怎么了,cal.com,d-y。说真的,如果你不主动去建立关系或者不想要这种关系,你其实跟任何使用它的人都没有真正的联系。
103:02
makes sense for trust but have that relationship so what a license key let you do
这对于信任来说是合理的,但要有那种关系,所以许可证密钥能让你做什么呢?
103:09
in this case is literally everyone who is a user gets a license key and you're very
在这种情况下,基本上每个用户都会拿到一个license key,然后你就非常……
103:16
liberal with how you distribute those license keys that are non-paid so you want to be very open
在分发那些非付费的license key时要慷慨一些,所以你要非常开放。
103:20
with it maybe even instant with a home lab key for example but you get an email and a name and
有了它,甚至可能即时就能用,比如一个家庭实验室的密钥,但你只会收到一个邮箱和一个名字,然后——
103:27
you can forge a relationship that's very different from here's our freeing up and source you know
你可以建立一种非常不同的关系,而不是那种“我们开源了”的模式,你懂的。
103:33
cal dot d y d y d y y y what is wrong with you today Adam cal dot d y you know you don't have a
cal dot d y d y d y y y,你今天怎么了,Adam?cal dot d y,你知道你没有……
103:42
relationship with anybody who uses it really unless you force the relationship or desire the
与任何使用它的人之间的关系,除非你强迫这种关系或渴望这种关系。
103:46
relationship or get that inbound issue which you don't even really want I mean maybe want the
或者说那种你其实并不想要的入站问题——我是说,也许你想要那些issue,但不想要那些糟糕的请求。所以你怎么看那个license key的世界?你有没有认真想过这个问题?就目前而言,或者说现在这个repository拆分的方式是,你可以完全self-host cal.com,然后有几个pro功能确实需要license key,而且这些功能是在那种resource available license下的,所以这跟你说的其实挺像的。唯一的区别是,往后走,那个source available会变成private source,所以明天的calicon会严格是HPLv3,甚至可能是MIT——我们甚至可能会改成MIT,因为它已经不再被我们商业使用了,就是它在那儿,是公开的,但它只是……
103:51
issues but not the poor requests so what do you think about that license key world have you have
问题不在那些糟糕的请求上,而是别的问题。所以你对那个license key的世界怎么看?你有过这种经历吗?
103:56
you examined this thought at all so as of today or whether the current way the repository split is
你仔细想过这个问题吗?到今天为止,或者说现在这个repository的拆分方式,你有没有认真考虑过?
104:04
that you can fully self host cal dot com and then there's a couple of pro features that do require
你可以完全自托管Cal.com,然后有几个专业功能确实需要
104:10
a license key and that are like on the resource available license so it's pretty similar what you're
一个许可证密钥,然后这些是在可用资源许可证上的,所以跟你的情况挺像的。
104:16
explaining the only difference moving forward is that that source available will go private source
解释一下,从现在开始唯一的区别就是,那个source available会变成private source
104:24
so the the calicon of tomorrow will strictly be an hplv3 potentially even MIT I'm we might even
所以明天的Calicon将严格采用HPLv3,甚至可能是MIT,我甚至觉得我们可能会……
104:31
change the MIT because it's no longer commercially used by us like it's it's there it's public but it's
把MIT改掉,因为它已经不再是我们商业上在用的许可了——它还在那儿,是公开的,但……
104:39
more of a public good than a commercial asset so the but the source available part will go
这更像是一个公共产品,而不是商业资产,所以“源代码可用”那部分会走私有化路线,因为它已经是商业化的,而且非常敏感。产品中那些不该让公众看到的部分,我觉得,我们做的决定是——我们不会,首先这也不可能,我们永远不会把之前开源的任何东西私有化。但我们确实会私有化的,在某种意义上,是那些不再提供源代码的商业部分,各种可用的东西,我们把它们变成私有源代码。我觉得,但你最初问的那个问题,回到最开始,就是为什么还要坚持开源。我觉得归根结底,
104:49
private source because it's already commercial and it's very sensitive
私有来源,因为它已经商业化了,而且非常敏感
104:58
parts of the product that should not be for the public eye let's kind of like the I think the
产品的某些部分不应该公之于众,我觉得有点像那个——
105:04
decision we made we're not so we we would never take anything well first it's not possible what
我们做的决定是,我们不会——我们绝不会接受任何东西。首先,这根本不可能。
105:11
we would never take anything private that's previously open source but what we do take private
我们绝不会把之前开源的任何东西私有化,但我们确实会把一些东西转为私有。
105:17
in a sense is that we no longer have the source available commercial parts all sorts of
从某种意义上说,我们不再有可用的源代码了,商业部件什么的都是这样。
105:24
available we take that private source and I think what the but the initial question you had
可以,我们拿那个私有数据源,然后我觉得——但你最开始问的那个问题,其实是……
105:31
just to go back to the initial start was why even stay open source I think at the end of the day
回到最开始的问题,为什么还要坚持开源?我觉得归根结底,
105:41
we are forced to make a decision here whether it's to write over on one time we'll tell the market
我们被迫在这里做一个决定,是选择一次性覆盖过去,我们会告诉市场,我们会告诉技术界,我们不知道,只是感觉这是对的选择。行业里很多人同意我的看法,而且确实也有人同意我,这让我觉得——说真的我讨厌这样,我不喜欢,但事实就是如此。所以我们不想放弃开源的初心,我们继续把 cal.dii 开放给任何有兴趣贡献、想加入这个社区的人。只是说,这并不代表我们会把它跑在我们的生产环境里,那真的只是在 tier DR 或者 tier DR 这个层级上,但 tier DR 唯一的区别就是,开源代码现在是一个完全开源的项目。
105:48
we'll tell on the technology we'll tell we don't know it's just it feels like the right one a lot
我们会聊技术,也会聊那些我们其实不知道的事——只是很多时候,感觉对了就对了。
105:54
of people in the industry agree with me and secure it extra it's agree with me which is
行业内很多人都同意我的看法,而且这还额外加固了这一点——就是同意我的那些人。
106:00
said I hate it like I don't like it but that's just what it is so we do not want to give up the
我说过我不喜欢它,但事实就是这样,所以我们不想放弃。
106:07
open source ethos we keep cal.dii for cell posters for anyone who's you know excited to contribute
开源精神让我们保留了cal.dii,供任何有兴趣贡献的人使用
106:16
and and be part of this community it's just simply not that instance that we would be running
并且成为这个社区的一部分——这根本就不是我们在运行的那个实例。
106:21
on our production environment right that that's really just in a tier tier DR or tier tier DR
在我们的生产环境里,对,那其实就只是在一个tier级的DR,或者tier级的DR环境里。
106:27
but tier DR like the only differences the open source code is now fully open source project
但Tier DR,唯一的区别就是开源代码现在完全是开源项目了。
106:34
we don't run it ourselves we give it to you you can run it yourself if you want to but we have
我们自己不运行它,我们把它交给你,你想自己跑也可以,但我们有数据在处理,对吧。比如人们在哪里、跟谁见面、在某个时间点要见谁,而且我不知道你有没有那种按会议收费的能力。光是这一点,你就能知道他们有没有在赚钱,我是说,你能从中挖出很多东西,然后跟其他数据交叉验证。
106:40
a commercial fork of that thing that can do a little bit more and is a little bit more safer
那个东西的commercial fork,能多做一点事,也更安全一点。
106:47
so in a way it's not like we're a private source company now we just use our own like we use
所以某种程度上,我们现在并不是private source公司,我们只是用我们自己的,就是用我们的
106:55
our community addition as the foundation and then we put some locks on it you know given what you
Community Edition作为基础,然后在上面加了一些锁,你知道,鉴于你
107:04
share with me and what I've also been seeing myself in terms of how things are changing I'm
跟我分享的,以及我自己也看到的那些变化,我
107:10
I'm sad too by that but I'm not the state is what it is I suppose and I'm I'm sad by the fact
我也为此感到难过,但我不……现状就是这样吧,我想。而且我难过的是,
107:17
that's the fact but I'm okay with how it makes sense to protect the investment the company that
事实就是这样,但我可以接受,因为保护投资是合理的——也就是这家公司——是我们
107:27
you have our responsibility to run well the customers right like the customers right yeah for sure
有责任经营好的。客户,对吧?就是说客户是对的?是啊,当然。
107:33
the the the data we're processing is no longer fun like we have really like in like like important
我们处理的data已经不再好玩了,就像我们有真的很……有点,就是,很重要的东西。
107:43
data we're processing right like people are worse away is going to be at with who they're going to
没错,但可惜的是,这些都不是——你看,如果你跑一个很轻松的开源项目,比如做一个鼠标悬停时按钮变绿发亮的那种,那跟你有几百万个互相交互的客户,比如聊天机器人,完全是两码事。
107:47
meet with at a certain time and I don't know you have like abilities to charge for meetings this
在某个时间见面,但我不知道你还有那种给会议收费的能力。
107:54
the way that's like even that you know whether they're making money I mean there's a lot of things
甚至就连他们是否在赚钱这件事,你知道,也有很多因素要考虑。
107:58
you can get from that that that you can you know cross examine with other data that
你可以从中看出,你可以用其他数据来交叉验证。
108:03
exactly none of this none of this is sadly like look if if you run a chill open source project that
可悲的是,这些完全都不适用。你看,如果你运营一个轻松的开源项目,
108:12
I don't know makes a button green and glow when you hover over that's very different to
我不知道是什么让按钮在悬停时变绿并发光,这和那个非常不同。
108:16
having millions of customers who you know interact with each other whether it's a chatbot
拥有数百万客户,你知道他们会彼此互动,无论是通过聊天机器人还是其他方式
108:25
you know whether it's discord imagine discord gets broken open tomorrow and every single
你知道,想象一下Discord,如果明天Discord突然被攻破了,然后每一条私信都变成公开的,那真的会惨到爆。所以,开源并没有死,但它正在改变。嗯,你同意这一点吗?是的,百分之百同意。我也觉得,商业开源其实并不是说,你知道,开源就是开源,商业开源是另一个子类。如果你跑一个框架,或者跑一个包,那你大概没问题,只要你的依赖是安全可靠的。但如果你跑一个商业开源项目,那最好确保它跟你生产环境上跑的不是同一个东西,这通常是个好建议。不过商业开源依然非常有效、有意思,而且就是,嗯,挺好的。
108:29
DM this public that would freaking suck so what suck so open source is not dead but it's changing
跟公众说这个,那可真够糟的。所以,开源没死,但它正在变。
108:38
well would you agree with that yeah hundred percent I think I also don't think that commercial
嗯,你同意这个说法吗?百分之百同意。而且我觉得商业化的……我也不觉得商业化……
108:46
open source is that you know open source is framing open source and commercial open source you
开源就是,你知道的,开源是在定义开源,以及商业开源。
108:52
know the sub categories if you run a framework you find if you run a package you're probably
了解子类别。如果你运行一个框架,你会发现;如果你运行一个包,你可能是。
108:58
fine as long as you have your dependencies safe and secure if you run a commercial open source project
只要你的依赖项安全可靠就没问题,如果你运营的是一个商业开源项目的话。
109:06
probably make sure that it's not the same that's running on your production environment and that's
大概要确保它跟你生产环境里跑的那个不是同一个,而且那个……
109:11
usually good advice but commercial open source is still really valid valid and fun and and just
通常这是好建议,但商业开源仍然非常靠谱、非常有意思,而且而且就是
109:22
fulfilling place to be in it's it's it's it's a lot of fun yeah all righty well pure thank you so much
这是个让人很有成就感的地方,就是,就是,就是,真的很开心。好嘞,Pure,太感谢你了。
109:31
for this situation is depressing it's not it's not a happy ending yet but I do think you know
现在这个局面确实挺让人沮丧的,还不是个圆满结局,但我确实觉得,你知道的。
109:39
I think what I also hope is that people just simply understand I think there's always
我也希望的是,大家能单纯地理解这件事。总会有那些黑子想过度解读,但我的希望就是大家能懂,就是,对对,说得通,挺难受的,但我应该看到这一点。
109:45
haters out there who try to read into things but I think my hope is just people just
我们确实处在一个很独特的位置上,我觉得有些艰难的选择必须得做。
109:52
just get it like yeah yeah make sense sucks but I should see it yeah we are at a
而且我觉得周围的一切都在明显变化,最后会落在哪儿,还是个未知数。
109:59
at a unique position in place for sure and I think there's hard choices to be made
我长期看好开源,真的。希望有一天我们能回到那个状态。
110:06
and I think things are definitely changing all around and it's a TBD on where it lands in terms
我觉得事情肯定在各方面都在变化,最终会落在哪里还是个未知数。
110:14
of that change I'm long open source same yeah really and I hope one day we get back to where it
对于这种变化,我一直是开源的坚定支持者,没错,真的。而且我希望有一天我们能回到那种状态。
110:21
you know we can be even more forthcoming with with details but I know when you're a high value
你知道,我们其实可以透露更多细节,但我也明白,当你是个高价值
110:27
kind of property it makes sense obviously to do what you need to do to protect yourself
类型的项目时,显然有必要做你该做的事来保护自己
110:32
and your customers and no one can really value for that and I certainly appreciate the non-road pull
和你的客户,这一点没人能苛责,而且我真的很欣赏这种不搞“road pull”的
110:39
aspect of it you know I think there's a lot of folks who would just simply road pull and it's not
做法。你知道,我觉得有很多人可能就直接road pull了,但
110:45
at all the case and then you know if you were starting fresh and green and brand new
你完全不是这样。然后你知道,如果你是白手起家、全新起步的话,
110:52
maybe you never even go open source at all maybe you start literally as close source
也许你根本就不会走开源路线,可能一开始就直接闭源
110:56
proprietary and you prove yourself in the market or you don't you know I think that the
专有,然后在市场上证明自己,或者证明不了。我觉得
111:03
lore to being a commercial open source company these days is dramatically different than I was
如今做一家商业开源公司的这条路,跟以前相比已经大不一样了。
111:07
four years ago yeah and and we don't even know where coding comes out in a year from now yeah so
四年前,对,而且我们甚至不知道一年后coding会变成什么样,所以
111:15
like I think it's I think the most important skill for any founders you know like you have to adapt
我觉得,我认为对任何founder来说最重要的技能就是,你得适应
111:21
and we're adapting now and you need to be okay with that change you know we're no longer a
而且我们现在就在适应,你需要接受这种变化,你知道,我们不再是
111:26
a buck we're turning into a private butterfly so you just need to be okay with that transition
一个蛹了,我们正在变成一只私人蝴蝶,所以你只需要接受这个转变
111:33
yeah yeah well here thank you for keeping me on time with all my time with Cal.com big fan
对对,好吧,谢谢你一直帮我把时间安排得井井有条,用Cal.com,我是大粉丝
111:40
as you know a big user as you know daily active user of Cal and I love it I when we started
你知道的,我是重度用户,每天活跃用户,我超爱它。我们刚开始
111:48
using it when we first invested never look back I've you know hit a couple scenarios but you've
用的时候,是我们第一次投资的时候,就再也没回头过。我遇到过几次问题,但你
111:53
fixed things over time it's gotten smoother easier better up time has been always amazing and
随着时间推移一直在修,变得越来越顺、越来越简单、越来越好,uptime一直都很棒
111:59
for me five stars I would only knock you maybe a quarter of a point on the one thing I mentioned
对我来说是五星,我只会因为你提到的那一点扣你四分之一分吧。但可能过了那之后又回到五星了。它知道的,而且我刚收到我的coding agent的通知,它已经把你那个PR给部署了,覆盖了hosts——真的假的!对,就是在我说的那段时间里,对,就是那段时间,而且我们大概就是在那几天里,我啥都没干,结果看起来太棒了。得了吧你。我们走着瞧吧,走着瞧。嗯,我很期待用那个功能。等不及了,真的等不及了。你会是第一个测试的人,我会发给你……什么都不发。好吧,那再次感谢你来上这个pod,跟你聊得很开心。谢谢你,也谢谢你。好了朋友们,外面变化真大,我不知道你们怎么想。
112:05
in this pod but maybe after that it's back to five stars again it knows and I just got a notification
在这个播客里,但也许在那之后它又回到五星了,它知道,而且我刚收到一条通知。
112:10
from my coding agent who shipped your PR to override hosts get out of here yeah so during the
从我的coding agent那里,它帮你把PR合并了,用来覆盖hosts——别逗了,好吧,所以在那期间——
112:18
time I said during the time right and I guess we were in these days and I didn't do a single thing
当时我说,在那段时间里,对吧,我觉得我们那时候就在那些日子里,而我什么都没做。
112:24
and it looks amazing come on now we shall see what happens we shall see well I look forward
看起来棒极了,来吧,我们拭目以待。我们拭目以待。嗯,我很期待。
112:31
to using that feature I can't wait yeah I can't wait you'll be the first one to test I'll send you
用到那个功能的时候,我等不及了,真的等不及了。你会是第一个测试的人,我会发给你的。
112:36
nothing all right here well thank you again for coming to the pod it's been good talking to you
没什么,好的。再次感谢你来参加这期播客,跟你聊得很开心。
112:40
I appreciate you thank you well friends a lot is changing out there I don't know about you but
感谢你,谢谢。好了朋友们,外面变化挺大的,我不知道你们怎么想,但……
112:49
every single day I open up X with trepidation and anticipation at the same time like oh I don't
每天我打开X的时候,既忐忑又期待,就是那种“哎我不知道”的感觉,能不能让我重置一下?不是说你的问题,但我个人真的很喜欢codex。我现在对cloud不太感冒,也还没怎么去探索其他开源的地方。
112:59
even know you know can I get a reset here it's not about you but I'm loving codex personally
甚至你知道的,能给我重置一下吗?这不是针对你,但我个人超爱Codex。
113:04
I'm not really digging cloud right now I haven't really ventured out to other places open source
我现在对云服务不太感兴趣,我还没怎么去探索其他平台,开源方面倒是还行。
113:09
models are doing cool stuff but by and large codex codex app server and the fun things happening
models are doing cool stuff but by and large codex codex app server and the fun things happening
113:16
in and around the open AI codex world chat GPT pro world has just got me lasered in gravitational
模型在做很酷的事情,但总的来说,Codex、Codex 应用、服务器,以及那些有趣的事
113:24
focused in and I'm liking it so I'll be in San Francisco here in a few weeks September 14th
in and around the open AI codex world chat GPT pro world has just got me lasered in gravitational
113:30
through September 18th if you're in SF I would like to say hello I'm trying to plan an
在 OpenAI Codex 世界和 ChatGPT Pro 世界内外发生的一切,让我彻底专注、深深沉浸
113:36
IRL yes a change log IRL if we could do it fingers crossed at planet scales headquarters I'm
focused in and I'm liking it so I'll be in San Francisco here in a few weeks September 14th
113:44
really hope we can do that if the stars align we're making it happen if you're not yet a member
其中,我很喜欢这种感觉。几周后,也就是9月14日到9月18日
113:49
go to change log dot com slash community it is free to join get in the loop get notified
去 changelog.com/community 吧,免费加入,进入圈子,获取通知
113:56
of all the things happening and I'll see you there big thanks to the sponsors of this podcast
所有正在发生的事你都能第一时间了解到,我们到那儿见。非常感谢本期播客的赞助商,
114:01
coder dot com work oh s and build kites and of course our partners in crime fly dot i oh okay
coder.com、WorkOS 和 Buildkite,当然还有我们的好搭档 Fly.io。好了,
114:10
friends that's it the show's done thank you for tuning in we'll see you again soon
朋友们,这期节目就到这里,感谢大家的收听,我们很快再见。