<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[the fact that LLM company employees are hiding that they use LLMs in their open source contributions shouldn&#x27;t just give us pause, it should be setting off all the alarm bells, big red flashing lights and the loudest sirens that exist in our heads.]]></title><description><![CDATA[<p>the fact that LLM company employees are hiding that they use LLMs in their open source contributions shouldn't just give us pause, it should be setting off all the alarm bells, big red flashing lights and the loudest sirens that exist in our heads.</p><p>let me lay it out</p><ul><li>LLM contributions have overwhelmed open source maintainers</li><li>maintainers and contributors have been burned out by the harassment received due to pushback against LLMs</li><li>maintainers are quitting open source at a huge rate because of the two previous points</li><li>slop code has tainted the entire free software stack from systemd and the linux kernel to fucking <em>vim</em></li><li>nobody knows where this code is coming from, and there's too much to properly review (as evidenced by the massive pile of slop that is the leaked claude code source)</li><li>LLM companies have purchased and become owners of type checkers, package mangers, and even a javascript runtime</li><li>and now the people working for the companies making LLMs are purposefully hiding their LLM usage</li></ul><p>at best this is an open assault against the commons and free software itself</p><p>at worst this is the xz backdoor being worked into every single large open source project</p><p>i've worked in infosec and opsec. if something like this happened to our software stack, we would've considered the entire infrastructure compromised. we would've re-bootstrapped our os images and build systems using code from before the slop machines appeared, manually backporting security patches. because this situation is not acceptable. because the alternative would be throwing our hands up and accepting that everything is compromised and every one of our users was fucked and that's just life now.</p><p>the takeaway?<br />you're compromised.<br />i'm compromised.<br />your favorite open source project is compromised.<br />almost every machine on the planet is compromised.</p><p>but we're not fucked. we're only fucked if we ignore this and pretend everything is fine. there's always time to rebootstrap and kick the slop machines out. all that's required for evil to prevail is for good people to do nothing. we just have have to do <em>anything</em>. we just have to say that's fucking enough.</p>]]></description><link>https://board.circlewithadot.net/topic/a828f35f-236f-4f9a-953e-52759787a72b/the-fact-that-llm-company-employees-are-hiding-that-they-use-llms-in-their-open-source-contributions-shouldn-t-just-give-us-pause-it-should-be-setting-off-all-the-alarm-bells-big-red-flashing-lights-and-the-loudest-sirens-that-exist-in-our-heads.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 06 Apr 2026 16:39:48 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/a828f35f-236f-4f9a-953e-52759787a72b.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 01 Apr 2026 17:21:07 GMT</pubDate><ttl>60</ttl></channel></rss>