Map

The Bike Shed: Please make my predictions come out wrong

title
The Bike Shed: Please make my predictions come out wrong
author
Poul-Henning Kamp
publication
ACM Queue
retrieved
2026-07-18
retrieved_via
web.archive.org (queue.acm.org behind Cloudflare 403)

The Bike Shed — Please make my predictions come out wrong

Poul-Henning Kamp, ACM Queue, 2026. Final "Bikeshed" column.

Almost 20 years ago, my friend George (aka Kode Vicious) casually mentioned in an email that acmqueue was looking for articles about flash memory. Not thinking through the consequences, I asked, "How many words?"

Careless questions cause homework, and thus started the "Bikeshed" column, if one can call something a column when it appears only about once per year.

When I was a young man, I rapidly tired of old men who had no idea what I was talking about but were 100 percent certain that they had the infallible answer, and I promised myself I would never join their ranks.

So, I will see myself out now.

In this last Bikeshed in acmqueue, I will ponder the far future of free and open source software (FOSS), hoping to upset so many readers that my name will become an obvious addition to the "list of IT people who have predicted something utterly wrong and obviously silly about the distant future."

There are two hot envelopes in the FOSS inbox right now: LLM-assisted code reviews and age verification.

The LLM-assisted code reviews are causing a lot of headlines because this comes out of one of those economic bubbles that seem to automatically inflate as soon as most people have forgotten how utterly stupid and predictable the previous bubble was.

I'm not particularly worried about this.

I have never felt particularly confident in myself as a programmer, so I have always applied all the "code-quality" tools I could lay my hands on, and the pattern has always been the same:

— Day 1-2. Tried $tool out. Oh boy! We have some work to do.

— Day 3-5. OK, there were a couple of solid bugs there, and a fair number of what were technically bugs, but not actually all that bad.

— Week 2. I guess that was it?

This pattern first manifested when I read the Zilog Zeus reference manual from cover to cover in 1984 (while walking barefoot in the snow on the freeway, etc.) and read about lint(1).

I saw the pattern most recently with Clang's quite impressive static analysis facilities.

Just on that repeated experience, I suspect we have already seen more than half of the "worst software bugs found with LLM-tools" list.

Supporting that suspicion is that it would beggar belief that AI bros so desperate to blow hot air into their bubbles would not try to make as big a splash as possible, as soon as possible.

(May I kindly suggest that they give their next LLM model the entire design and as-built documentation for a nuclear power plant? That is guaranteed to give them a lot of publicity and will maybe teach us something about the limits of human engineering complexity.)

When I look at the nature of the bugs found by LLM tools, I see clear parallels to computers playing chess: The LLMs are able and willing to explore the tree both wider and deeper in detail than human brains evolved to economize energy and time, by probabilistically and heuristically searching for food, sex, and comfort only where the odds look most promising.

That's good.

Cyberattacks and defense are by nature a chesslike game, and we also badly need better tools to write the programs that we will increasingly trust with our lives in the future.

The only real question for me is: Are the LLM-code-review tools economically viable outside the bubble?

All the work, and all the cost, comes up front, during "training" of the model. But the resulting artifact, the weights of the model—which you have to sell many million times over before you turn a profit—easily fits on contemporary pocket-sized storage devices.

This is not unlike a major film or video production where millions are spent on sets, actors, costumes, special effects, and marketing to create a 4K video stream that fits on pocket-sized storage devices, and profit is made in increments of fractions of a teenager's allowance.

Where [H/B]ollywood has somewhat successfully managed to wrap itself in a righteous cloak of copyright protections, the LLM industry may have trouble doing that, given how religiously they recite "fair use" in the many lawsuits where they are accused of infringement of copyrights.

So, it is not obvious to me who will be training new iterations of these models once the current bubble explodes, in particular if the returns are diminishing the way I have experienced.

In contrast to the LLMs, I think age verification is going to be a really big deal for the FOSS world. And, spoiler alert: I think we are at the beginning of the end for FOSS as we know it.

Quick recap: In the beginning, nobody important cared about the early store-and-forward communication systems, and the open source phenomena that it begat.

Then some money could be made on store-and-forward, and that funded further development, which gave us online digital communications—where the real money was.

FOSS hitched along for the ride, and, because FOSS is nothing if not unselfishly helpful, that accelerated both the technological development and the moneymaking.

When Edward Snowden revealed that Somebody Important had been taking an interest after all, the tech bros, who had grown up free of adult supervision, felt betrayed and started a campaign to encrypt everything and anything so that prying eyes could never again look them in the cards.

And thus, we find ourselves in the present situation where it is trivial for any criminal to cover their online tracks well enough that only the most incompetent criminals and most economically consequential online crimes are prosecuted, while most digital crimes are not even reported to the police because everybody knows the police can't do anything about them.

I can never remember if it was Sun Tzu or Clausewitz who cautioned not to back your enemy into a corner from which the only way out is over your own corpse, but that is precisely what the tech bros did to nation-states with encryption, and now the nation-states are making their way out of that corner.

Right now, there is a LOT of shrill propaganda from the tech bros, who call themselves "privacy advocates," about how mandatory age checking is the gateway drug to comprehensive identity checks on the entire Internet, and ridiculing the valid civic concerns governments are trying to address as merely "think of the children" strawman arguments.

In comparison, tech sisters advocating for an absolute right to privacy seem to be a very rare, and maybe mythical, species.

It may not quite be a law of nature, but my personal guess is that the opportunities for anonymity on the Internet will shrink until mothers no longer are forced to have "the talk" when their daughters get their first mobile phone. As the parent of a daughter, I am totally on board with that.

And before you ask: Yes, I'm laying this one squarely down before (and partly on the toes of) the tech bros: We could have designed our protocols to be minimally compatible with "a nation of laws," but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary.

But how can age verification even work with FOSS? What's to prevent the kids from changing the source code and recompiling once a fake mustache is no longer enough?

Cryptographically attested software integrity is the only possible answer: Somebody will have to sign on the dotted line to verify that this operating system can be trusted, and nobody is going to do that if the user can change it and recompile it.

The Internet is already fractioning into ever-smaller parts you can access with any browser, on any device, running any software you want. And a growing part of that can be accessed only from an "attested computing platform," which you may or may not have the source code for but surely won't be able to hack.

That brings me to the biggest force of change to FOSS as we know it: accountability.

During the past couple of decades, rampant neoliberalism and "globalism" allowed the U.S. tech industry to capture almost the entire European IT market, including all "social media." This has recently proved to be a ghastly mistake, and now the EU, along with its member states and companies, are scrambling to claw back their digital sovereignty.

If the EU had grown its own tech-bro–infected online monopolies, that would be as easy as changing a few laws. And, in that situation, the EU wouldn't have cared about FOSS any more than the EU cares about any other people's hobbies.

But there is no such thing as a European alternative to Google, Apple, Oracle, Microsoft, Facebook, or Twitter, and therefore you can hear European CIOs wander around at night muttering:

— Is this an IT solution I see before me?

— The source code toward my hand?

— Come, let me clutch thee!

But when, like Macbeth, they reach out, they grasp only the thin air, because there is no supplier to negotiate with, nobody to sign a contract with, and when they wake from their nightmare, they can still hear the voice of Groucho Marx mocking them: "The party of the first part shall be known in this contract as the party of the first part," because almost everybody currently in a position of power grew up in a culture where "blame allocation" was comme il faut because it was seen as more profitable, and therefore obviously better to deflect blame to somebody else, rather than to solve the actual problem.

It's hard enough for them to pretend that blame allocation can work with "The buck stops here" problems such as digital sovereignty, but it clearly won't work with FOSS because if there is one thing FOSS licenses all agree on, it is the "Don't blame me" clause.

So, a bit of a paradigm shift there, and they don't know how to drive stick, because nobody ever got fired for buying Microsoft before.

As the only realistic hope for digital sovereignty, the EU made huge carveouts for FOSS in recent legislation, most notably in the Cyber Resilience Act, but the EU is not stupid: The carveouts end the moment you make a profit. And since it does look like there will be a lot of profit to be made from FOSS in the EU in the coming decade, that is also going to hasten the end of FOSS as we know it.

Even if you give up blame allocation as "methodology," FOSS as we know it is not a particularly solid foundation to build civic society upon because a lot of FOSS exists at the pleasure of a single person, who may not know, and may not care, how much infrastructure other people have stacked on top of it.

Maintainer burnout is already a thing, and maintainer death will increase in frequency since FOSS looks more and more like it was a generational thing, like bell-bottom jeans and flower power.

Attempting to lure in apprentice maintainers to replace my generation of do-gooders is already a losing proposition, and it is not going to happen at all if the role of maintainer is pro bono, while the paint-on-the-sign-is-still-wet "FOSS stewards" and "FOSS manufacturers" rake in the dough from that very same software.

The era of "Benevolent Dictator for Life" FOSS maintainers like myself is coming to an end. In the future, all consequential FOSS projects will be maintained by committees appointed by a FOSS steward or by a FOSS company.

Between the need for an "Attested Computing Platform" to fire the weapons against the crime-enabling "privacy advocacy" tech bros, and the need to have something more legally substantial than "some dude" maintain the IT foundations of EU's digital sovereignty, the wide open spaces my generation roamed over, playing with FOSS as if the sun would never set, are rapidly being replaced by properly fenced, only-as-big-as-the-taxpayers-will-pay-for, health-and-safety-approved, sterile, and uninspiring urban playgrounds in a soundscape free of important commercial traffic.

The only bit left of FOSS as we know it will be that users will be able to read the source code. As reproducible builds catch on, they might even be able to compile that, as long as they make no modifications.

I fear that the path of least resistance to accountability for FOSS will be the "walled-garden-app-store" model, where only cryptographically attested genuine kernels are able to offer the necessary age verification and other legal attestations required to surf the web, and only unmodified programs, downloaded from the FOSS-stewards-approved app store can run outside the sandbox of the browser.

And why would I even think that?

It's because a friend of more than 40 years recently needed my help to install Ubuntu on his new laptop, and as much as I appreciate what Ubuntu has done for the adoption of FOSS, I really hate how much that looked like the future.

Please make my predictions come out wrong.

Author bio

Poul-Henning Kamp has haunted the Unix world for 40 years and written a lot of widely used open-source software, including bits of FreeBSD and the Varnish HTTP Cache. Living in Denmark with his wife, two cats, and three lawn-mower robots, he remains unconvinced that an older/wiser correlation exists.

Copyright © 2026 held by the owner/author(s). Publication rights licensed to ACM.


Lobsters discussion

Submitted as "Goodbye, and thanks for all the Bikesheds" — https://lobste.rs/s/hvuumu — 19 points, 7 comments.

  • mtset (18): the anonymity-shrinking prediction "is going to kill people, mostly queer kids in households that want to suppress that queerness."
    • czarkoff (17): "It will kill all kinds of people. Queer kids is just the obvious tip of the iceberg. Humanity as a species evolved in an environment where anonymity was the natural default. A lot of our survival mechanisms work only while not scrutinized closely... We have never existed in a fully transparent environment, and everything we've built with a pretence of transparency had an escape hatch or a dozen." Eventually people learn to survive or evade it, or put a hard stop on transparency — but there'll be deaths first, hard to predict.
      • mtset (9): "upon reflection I agree with you."
  • apropos (3): doesn't follow the maintainer-death claim.
    • Jan200101 (1): reads it as — existing maintainers fail to find replacements, so once they stop (for whatever reason) the project dies with them.
  • cpurdy (2): good read, raises important questions, but "the future is not set in stone" — we have a role in making it safer for children and also a responsibility to keep liberty a human right; the tension between the two "is a feature, not a bug."
  • Jan200101 (1): "I hate that I share the same sentiment" about being at the beginning of the end for FOSS.