
Poul-Henning Kamp's last Bikeshed column warns about the future of open source
In his final ACM Queue column, the FreeBSD and Varnish developer argues that age verification and demands for accountability could end free and open source software as we know it.
A column that ran for two decades
Poul-Henning Kamp, a long-time FreeBSD developer and the author of the Varnish HTTP cache, has published the final instalment of his “Bikeshed” column in ACM Queue. The column began almost 20 years ago, he writes, after a friend suggested an article on flash memory. The last piece carries the subtitle “Please make my predictions come out wrong”.
LLM code review: useful, but not the revolution
Kamp is sceptical about the current wave of LLM-assisted code review. He describes a pattern he has seen with every code-quality tool he has tried, from the lint utility he read about in 1984 to Clang's static analysis: two days of impressive findings, a few genuine bugs over the following days, and by the second week, nothing more. On that basis he suspects that more than half of the “worst bugs found with LLM tools” have already been reported.
He compares the models to chess engines that search wider and deeper than human brains, and calls that a real gain for security work. The open question is economic: training costs are paid up front, while the resulting weights must be sold millions of times to turn a profit. Where the film industry wraps itself in copyright protection, LLM developers have argued “fair use” in infringement lawsuits, so it is unclear who will train the next generation of models once the bubble deflates.
Age verification and the accountability problem
The second half of the column is more pessimistic. Kamp argues that mandatory age verification will require cryptographically attested software integrity: someone must sign that an operating system can be trusted, and nobody will do that if users can modify and recompile the code. The likely outcome, he writes, is a walled-garden app-store model where only attested kernels can provide the legal attestations needed to browse the web, and only unmodified, approved programs can run outside the browser sandbox.
Part of the problem, he argues, traces back to encryption: after the Snowden revelations the industry encrypted everything, and nation-states are now working their way out of the corner they were pushed into. Europe's push for digital sovereignty has a similar effect. With no European alternative to Google, Apple, Microsoft or Meta, and with open source licences carrying what he calls a “don't blame me” clause, governments need counterparties that can be held accountable — and the EU's carve-outs for open source, notably in the Cyber Resilience Act, end as soon as a project becomes profitable.
Maintainers and the end of an era
Kamp expects the “benevolent dictator for life” model he belongs to will disappear. Consequential open source projects, he predicts, will be maintained by committees appointed by a steward or a company, because few people will take on unpaid maintainer work while others profit from it. What remains of FOSS as he knows it, he writes, is the ability to read the source code — and perhaps to compile it, provided nothing is changed. He closes by describing how he helped a friend install Ubuntu on a new laptop, admitting he hates how much that looked like the future.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.