ATRIUMsearch → argument graph
ExampleVideo · 7:04 — 19:15

The open-source ecosystem that underpins software is maintained by under-resourced volunteers, so the burden ultimately falls on users to vet the artifacts they deploy — and the industry must move toward faster patching.

Dylan and Fas argue the software world rests on underfunded, volunteer-run infrastructure where vulnerabilities are inevitable, so frontier models are compressing the time between discovery and exploitation — demanding both faster patch approaches and genuine user responsibility for vetting the code they adopt. ✦ AI generated

Dylan · a16z Podcast · 2026-08-07 · original ↗

starts at this moment · 7:04

The whole world is built on this teetering infrastructure... package manager registries... a lot of those are run by volunteers, they're underresourced, underfunded, there's lots of risk there... the frontier models are causing a massive reduction in the time between the vulnerability discovery and vulnerability exploitation... It's on actually the users I think to actually vet what they're using... We just found this code on the internet and we just deployed it straight into prod and it's someone else's fault. No, actually, there's some definitely some responsibility for the users of this software to really be vetting the artifacts that they're bringing into their environments.

verbatim transcript · starts at 7:04

Transcript · around this moment

6:46everyone should be thinking about like kind of how are you thinking about that like that's that's really difficult >> like the zero day creation piece. >> Yeah. Yeah. But like for for specific parts of that like the control the supply chain. >> Yeah. Well I mean the the whole world is built on this you know teetering infrastructure that everyone is using >> like the classic picture of the the

7:04matchick holding up the complicated machine. >> Yeah. >> That that image probably popped into all the lines right now. Right. [laughter] And so everything from you know package manager registries like we like to focus on on that um because what we do at socket um a lot of those are you know run by volunteers um they're they're underresourced you know underfunded um you know there's lots of risk there uh

7:24right and uh and that kind of kind of cascades throughout the whole rest of the ecosystem. So if you look at the you know just the packages that we all depend on a lot of those are single individuals that you know like there's almost certainly we know there's a lot of vulnerabilities in the software and there aren't resources to look for them and so you know I think that stuff's

7:41always been there. just that these these you know these tools are like helping find them a lot a lot easier and I think that um you know the the frontier models are going to cause you know a you know they are causing kind of a massive reduction in the time between the vulnerability discovery and vulnerability exploitation and so what we we need to start thinking about is

8:02how do we patch more quickly um and so we need to get away from like our our take is we can't be >> requiring our security teams and our developers to to do these kind ownerous patch processes where they have to go from some ancient version of a package that their team is using up to the latest version across many major version upgrades because that's just so much

8:22work to do. it might require like code refactors in your application and so if we want to be able to keep up with you know a vul is announced this morning and then an exploit is available you know that afternoon like we can't be requiring that much work from engineering teams and there's also tons of legacy applications that you know are basically in maintenance mode or unmaintained or don't have don't have

8:42engineers that are even assigned to work on them at a lot of the companies that we work with and so it's it's um you know it's just we're going to have to think of new things as as an industry for how we're going to patch these things quickly right That's that's kind of like where our head is at and um and where I'm I'm spending a lot of time

8:57thinking about that lately. >> Yeah. Yeah. And I think that goes back to sort of the you know the the the pyramid question. So and I think Dylan you were you were hinting at this which is like these are very specialized skills like zero day exploits writing a zero day exploit doing a supply chain attack like these are these are not things that came from nowhere. These are

Around this claim