The end of software secrecy is almost upon us. The death of closed source, and the final triumph of open source.
I should have realized this a few months ago when I successfully decompiled the game of Firefighter from an ancient DOS shareware binary. My robot friend was able to tell it had been written in Borland Pascal from looking at the data layout; it gave me back very readable Pascal code with sensibly chosen function and variable names. I transpiled it to Rust and now ship it as part of my heritage games collection.
The thing is, I thought of this as a fun stunt but didn't have any confidence that the technique would scale up to large, real programs. I have since learned that people are now doing this sort of thing with entire AAA games, which are among the most complex software artifacts ever to be shipped as a binary. If they can be decompiled, anything can be.
This has implications. Massive implications. We need to think about what the world is like when, in general, there is no longer a secrecy moat around almost any software at all.
1/2
Eric S. Raymond
@esrtweet
[continued]
I say "almost" because there is going to be one way to maintain secrecy. Software as a service with the executable hiding behind a network connection to the cloud. But as of now, we must assume that anything shipped as an executable, or even a firmware image, is as transparent as glass. It won't keep its secrets for any longer than it takes for somebody to be motivated to throw an LLM at it.
I did not see this coming. When I wrote down the theory of open source, 30 years ago now, I thought closed source would be gradually driven towards extinction by cost gradients, but survive indefinitely in certain niches. I did not foresee it being wiped out in a technoapocalypse.
Ironically, I thought one of the application areas in which closed source would persist longest was games.
There are still some obstacles. In US law, decompilation of a binary is a derivative work of the binary that falls under whatever copyright it had. However, it is also settled law that if you decompile binary code to a precise specification of what it does, then generate fresh code from that without looking at the decompiled stuff, you're in the clear. This was the case law that allowed PC clones to exist, after Phoenix Technologies reverse engineered the original IBM PC BIOS.
The two-step process - binary to specification to unencumbered code - will no longer takes a large number of programmers and years of development time. With an LLM, it's now a thing you can do in a day. Ubiquity will make it impractical to prosecute all the people who might skip the specification step.
Source code can also be covered by patents. You can be able to see their source code for a patented technique and not be able to use it without violating the law. Linux has evolved practices for dealing with this problem - one is not shipping patented video codecs, but requiring you to download them as plugins from jurisdictions where U.S. patents can't be enforced. This presents patent holders with the impractical challenge of individually suing millions of end users, assuming it can even figure out who they are. To date, AFAIK, this has not been attempted.
And that's about it. If there are any other ways left to retain software secrecy and lock-in than SaaS or patents, I can't think of any. Well, you could epoxy-pot a firmware ROM, I suppose, but that can be defeated with a heat gun and a dental pick. Device manufacturers will learn not to pay for an assembly step that has become useless.
Forced migration from shipped binaries to tied cloud services will be tried - Adobe pioneered this, and Microsoft is pushing it as hard as they can given that their OS is a binary that has to run locally. Both companies are seeing massive user revolts over this. There is good reason to doubt that it's a strategy that can hold customers in the long term.
Also, a lot of things can't safely be tied to the cloud at all, because they can't tolerate a random network outage. Machine tools, medical devices...
A whole lot of proprietary software business models are going to collapse. Hard. One that I think might survive is tax software; being able to decompile it doesn't necessarily do you a lot of good because its actual value is tracking a ruleset that changes over time and has to be maintained by vendor specialists. But cases like this are unusual.
I think some dirty laundry is going to get aired, too. It has long been rumored that the reason graphics card manufacturers are so stubborn in their secrecy is that they've all been committing massive intellectual-property theft on each other for decades. If this is true, it will be exposed, and the lawsuits will be entertaining.
We're entering a new world, with a lot of ancient comfortable assumptions being blown up. It's going to be fun to watch.
2/2
I say "almost" because there is going to be one way to maintain secrecy. Software as a service with the executable hiding behind a network connection to the cloud. But as of now, we must assume that anything shipped as an executable, or even a firmware image, is as transparent as glass. It won't keep its secrets for any longer than it takes for somebody to be motivated to throw an LLM at it.
I did not see this coming. When I wrote down the theory of open source, 30 years ago now, I thought closed source would be gradually driven towards extinction by cost gradients, but survive indefinitely in certain niches. I did not foresee it being wiped out in a technoapocalypse.
Ironically, I thought one of the application areas in which closed source would persist longest was games.
There are still some obstacles. In US law, decompilation of a binary is a derivative work of the binary that falls under whatever copyright it had. However, it is also settled law that if you decompile binary code to a precise specification of what it does, then generate fresh code from that without looking at the decompiled stuff, you're in the clear. This was the case law that allowed PC clones to exist, after Phoenix Technologies reverse engineered the original IBM PC BIOS.
The two-step process - binary to specification to unencumbered code - will no longer takes a large number of programmers and years of development time. With an LLM, it's now a thing you can do in a day. Ubiquity will make it impractical to prosecute all the people who might skip the specification step.
Source code can also be covered by patents. You can be able to see their source code for a patented technique and not be able to use it without violating the law. Linux has evolved practices for dealing with this problem - one is not shipping patented video codecs, but requiring you to download them as plugins from jurisdictions where U.S. patents can't be enforced. This presents patent holders with the impractical challenge of individually suing millions of end users, assuming it can even figure out who they are. To date, AFAIK, this has not been attempted.
And that's about it. If there are any other ways left to retain software secrecy and lock-in than SaaS or patents, I can't think of any. Well, you could epoxy-pot a firmware ROM, I suppose, but that can be defeated with a heat gun and a dental pick. Device manufacturers will learn not to pay for an assembly step that has become useless.
Forced migration from shipped binaries to tied cloud services will be tried - Adobe pioneered this, and Microsoft is pushing it as hard as they can given that their OS is a binary that has to run locally. Both companies are seeing massive user revolts over this. There is good reason to doubt that it's a strategy that can hold customers in the long term.
Also, a lot of things can't safely be tied to the cloud at all, because they can't tolerate a random network outage. Machine tools, medical devices...
A whole lot of proprietary software business models are going to collapse. Hard. One that I think might survive is tax software; being able to decompile it doesn't necessarily do you a lot of good because its actual value is tracking a ruleset that changes over time and has to be maintained by vendor specialists. But cases like this are unusual.
I think some dirty laundry is going to get aired, too. It has long been rumored that the reason graphics card manufacturers are so stubborn in their secrecy is that they've all been committing massive intellectual-property theft on each other for decades. If this is true, it will be exposed, and the lawsuits will be entertaining.
We're entering a new world, with a lot of ancient comfortable assumptions being blown up. It's going to be fun to watch.
2/2
5:43 AM UTC · Oct 5, 2026 · 41K Views
1001792.6K495