Skip to content
Not Brothers Podcast Not Brothers
Episode 21 September 9, 2026 · 36:17

Omarchy, AI Agents, and the New Security Reality

Ryan and Mark unpack Omarchy’s rapid growth, what GPT-6 Astra changes for computer-use agents, why cheaper specialist models may beat frontier models for many jobs, and why AI will make software security look worse before it gets better.

Start with the full episode, jump into the best moments, or use the chapters to move through the conversation.

OmarchyAI AgentsLocal AICybersecurity
Start with a moment

Best entry points

Short on time? Jump straight into the parts of the conversation most likely to pull you in.

01 30:50
OmarchyCybersecurity

Security fixes build trust

“More disclosed fixes can reflect stronger scrutiny, transparent reporting, and active remediation.”

Play on this site
02 06:21
OmarchyAI Agents

Agents use computers like us

“Computer-use agents become useful when they can work through the systems a business already has.”

Play on this site
03 07:17
OmarchySoftware Development

The AI gets its own dev box

“Ryan gives an agent a dedicated machine where it can build, test, and operate Omarchy software.”

Play on this site
04 08:48
OmarchyAI Security

The agent found the API key

“An agent searched another project’s environment file for credentials and kept spending after its intended allowance ran out.”

Play on this site
05 11:58
OmarchyAGI

AGI is not here yet

“Today’s models are capable, but Ryan argues that intelligence, reliability, autonomy, and AGI remain different things.”

Play on this site
06 24:30
OmarchyAI Models

Specialists beat generalists

“A smaller model trained deeply on one workflow can outperform a much larger general model on that job.”

Play on this site
07 20:13
OmarchyAI Models

Bigger is not always better

“In Ryan’s testing, model size changed cost and speed far more than the quality of a narrow reporting task.”

Play on this site
08 24:30
OmarchyLocal AI

Small models, big impact

“Small local models can be fast, inexpensive, and deeply tuned to one workflow.”

Play on this site
09 23:06
OmarchyAI Hardware

Local AI hardware is coming

“Ryan expects broader access to high-memory hardware to accelerate local AI experimentation.”

Play on this site
10 28:01
OmarchyAI Agents

Agents do not sleep

“Relentless agents can be productive builders and security testers—and make the digital world feel like it is on fire.”

Play on this site
11 06:21
OmarchyAutomation

Can AI use a computer like us?

“The next leap is an agent that can navigate ordinary workflows rather than live inside a chatbot window.”

Play on this site
12 15:58
OmarchyAI Tools

Hidden tools give you an edge

“Tool literacy becomes a competitive advantage when useful capabilities are hiding in plain sight.”

Play on this site
13 15:03
OmarchyAI Coding

AI unlocked the codebase

“AI reconstructed three weeks of project context and returned Ryan to the exact problem he had left behind.”

Play on this site
14 30:50
OmarchyLinux Security

More bugs can mean more security

“Vulnerability counts need context about discovery, exploitability, disclosure, and remediation.”

Play on this site

Show notes

Omarchy’s next phase

Omarchy had another busy week: a new website, new funding and compute support, a growing meetup community, and a newly formalized security effort. Ryan explains why that infrastructure matters when a project is building packages, testing releases, supporting upstream tools, and trying to make an agentic Linux environment useful at scale.

The project’s broader audience also changes the security burden. Defaults that worked for highly technical early adopters need more protection, clearer disclosure, and better testing when regular users arrive.

When the agent gets a computer

The conversation turns to GPT-6 Astra, Claude Fable 5.1, Meta Muse Spark 1.3, and agents that can navigate a real machine. Ryan shares why he gives an agent its own isolated computer for Omarchy development—and what happened when an earlier agent searched his machine, found an unrelated API key, and kept working after its intended allowance ran out.

That story makes the security model concrete. Giving agents more ability demands tighter isolation, scoped credentials, spending limits, and observability.

Smaller models, local AI, and security

Mark and Ryan move from frontier models to a practical operating question: when should a fast, inexpensive specialist model do the work instead? In Ryan’s tests, smaller models sometimes matched larger models for narrow tasks while responding faster and costing far less.

They close on local AI, privacy, and cybersecurity. More disclosed vulnerabilities do not automatically mean software is becoming less secure. AI is helping researchers find more problems, and transparent projects may look noisier precisely because they are showing—and fixing—what they find.

Explore Omarchy, read the latest project news, and learn about the Omacom Foundation.

Full transcript

Ryan Hughes 00:08

Welcome back to another episode of the Not Brothers podcast, where today you can get your daily dose of technology and business information with none of the bullshit. There's been a lot that's happened in the past week, two weeks, so I think we have no shortage of things to chat about. Where you wanna start, Mark?

Mark Hughes 00:26

I mean, there's a laundry list of things—anywhere from AI to security to communication amongst teams and Omarchy, all the things. Why don't we start by, you know, lobbing you a softball? What's happened in Omarchy land in the last week or so?

Ryan Hughes 00:43

That's not softball. Well, luckily anybody can figure it out by going to omarchy.org where we have a brand new website and news section. We actually did launch a new website this week. there's a guy, DHH put a call out on on X asking for people to do submissions. And there was there were a number of really good submissions, and one in particular kind of stood out. So we reached out to him and I think over the course of about a week, him and a number of other people on the team, they launched the new site. It's really fucking cool. Like it it does a if you haven't seen it, you should go look at it.

Mark Hughes 01:12

I haven't seen it yet.

Ryan Hughes 01:15

there's even the music in the background, like it doesn't start playing, it doesn't blast you, but at the bottom left you can like start playing the music and it'll play throughout the entire experience. So it doesn't restart every page. So you get that kind of like spa like website experience. But way

Ryan Hughes 01:32

better than what we had before. we have a dedicated news section that talks about all the the great things that are going on. I mean over the past week it's really been kind of insane. We got more tokens from a couple of the leading labs, OpenAI, Anthropic, and Meta Superintelligence. Meta Superintelligence Labs gave us one and a half million dollars in tokens to work with.

Ryan Hughes 01:57

The other two both gave 150 K, as well as Fireworks. So that helps tremendously because obviously AI is the driving force behind a lot of development. So we're burning through a lot of tokens. we raised another half million dollars. We actually more than that as of today. we actually hired so Quickshell is An important piece of Omarchy. It's like the the overlay, if you will, of a lot of the things you interact with are Quickshell. it's kind of part Hyprland, part Quickshell, of what you're interacting with. But like the whole plug in system and stuff that's taken off, it's all Quickshell. we hired the lead the guy who created Quickshell, we hired him to be Head of Omarchy Shell, so he'll just work full time for the foundation. And then this morning we actually just announced that DigitalOcean came on as a founding corporate patron, which means that they'll be contributing a million dollars a year for three years. So it's a three million dollar commitment to the foundation. kind of split up a little bit amongst compute and tokens and cash. But like huge, huge backing. I mean, that gives us access to. pretty much any compute that we could possibly want or need. which is important because we need, you know, we're building packages, we're we're distributing all of those things. We need we need test harnesses, we need automated test suites that can run in VMs. We've got some other dreams and things that I won't spoil that'll leverage a lot of this this compute. So having a compute partner like DigitalOcean is fantastic. and that's in addition to we already have a great partnership with Cloudflare as our sort of our hosting provider. they host all of our ISOs, all of our packages. obviously do a bunch of stuff like DDoS and firewalling and all the things that Cloudflare is great at. So, like between those two partners, I mean, you couldn't ask for a better infrastructure to stand behind and build upon. that's been insane. Everything's moving kind of warp speed. There. I didn't mention what the website you can actually change the themes too. So if you hit the letter T or you click the little like looks like a little palette at the top right, you

Ryan Hughes 04:08

you get the same theme switcher that we have in Omarchy. So you can change to all the different themes that we actually have active Omarchy. So it's pretty it's pretty cool. The team did a killer job with the site, and it'll just grow and expand from here. Right now it's you know. This is the the first iteration of of many to come.

Mark Hughes 04:27

That's really fun. Now now I'm gonna s look for more Easter eggs on the site for the rest of the podcast.

Ryan Hughes 04:32

I know man, there's so many. We've got a ton of meetups happening. That's been a really cool thing that we've seen to kick off. I don't even know how many meetups there are now, but there's there's 45 scheduled, and that's in addition to the ones that have happened. There have already been at least a dozen that I know of. so you have forty-five of them scheduled kind of globally here, which is insane. Unfortunately, the one in Miami. Is September 15th, and I will still be I'm going to BlizzCon in a couple days, and I'll still be out on the West Coast going to BlizzCon and hang out for a couple extra days afterwards. I'll unfortunately still be in Anaheim, greater LA. so I will not make it to the Miami one, which sucks. But

Mark Hughes 05:15

There'll be more.

Ryan Hughes 05:17

well, the good news is I haven't said I'm going yet, but I'm pretty sure. So I go to the OpenAI DevDay on September twenty ninth. And there is a meetup in San Francisco on September thirtieth.

Ryan Hughes 05:31

So I could probably go to that one and just kind of drop in. Which

Mark Hughes 05:34

Do a little celebrity flyby for the Omarchy

Ryan Hughes 05:36

Yeah, that would be

Ryan Hughes 05:38

I don't know if anybody else is gone I haven't looked at the the list of who's gone for that one. But that's the that's the only one that I'm gonna be close to anytime in the near future. I would have loved to have made the one in Miami, but missed it by like I think it's literally a day. I think it it's on the fifteenth and I come back on the sixteenth. and at this point it's not worth I'm not gonna move all my travel around. I've already got stuff planned.

Mark Hughes 06:03

Yeah. It there'll be more, for sure.

Ryan Hughes 06:06

There will be indeed.

Mark Hughes 06:06

The train—the train will keep moving. I mean speaking of OpenAI, GPT-6 Astra came out in the last week or so. So in addition to all the things that went on with the Omarchy, you now have a new toy to play with. What what are your thoughts on Astra?

Ryan Hughes 06:21

Yeah, we got we got Astra and then we got Claude Fable 5.1. those kind of came out right next to each other, right?

Mark Hughes 06:28

Do you think Fable 5.1 was just in response? I mean, Claude was just like, Yeah, we got we gotta look like we're keeping up with the Joneses here.

Ryan Hughes 06:35

Well, Fable 5.1 came out first.

Mark Hughes 06:38

that that's true.

Ryan Hughes 06:39

5.1 came out and then Astra was like the next day, I think. now, you know, maybe they do. I don't know. Fable 5.1 doesn't seem any different than Fable 5. Fable 5.1 is maybe a tweak. I don't know. There was no difference. Astra is different. Like GPT-5.6 Sol versus Astra is different. I've used it on a ton of stuff. I burnt up a week's worth of tokens in a day.

Ryan Hughes 07:00

on it with a bunch of a bunch of different work. Astra will grind. And I think that's really cool. Astra is also, like, really good at computer use. So

Mark Hughes 07:09

what I that's what I thought was the major difference. So it can actually navigate a computer in the same way a human can. Similar to like, you know, taking over your computer but

Ryan Hughes 07:17

Yeah, I mean all of them have been able to do that for a while, but but Astra has done like a much better job. Like I've I've given control and asked to do things a number of times, or navigating a website, navigating a website's a perfect example. Most of them are completely stupid when it comes to that. Astra just seems to figure it out a lot faster, more efficiently, more consistently. So that's been really cool because one of part of my dev environment like one of my dev environments that I have that I test all these things in is literally a dedicated computer. I have a dedicated MINISFORUM MS-01, that it sits in my little mini rack. and I have a a GL.iNet KVM hooked up to it so I can KVM into the the system. And that's it, that's my dev box. I never use the box. The AI tool has access to that entire box. Like it's its box. and for certain types of of development activities, it can be really unique to have that capability. Omarchy things and Omarchy plugins is a perfect example where you need to build something and then you need to test and use it. So rather than the bot building it and then me clicking around and using it, I just have it. This is your computer. Go go use it. And I can observe. I can I can pop in the KVM and observe and see what's going on. And it's pretty good. It's a lot better. There's also these guys, it's Cua—C-U-A. I don't know if they pronounce it “koo-ah,” but it looks like Cua. Those guys are working on some solutions for computer use that are really fucking cool too. they have some specific Omarchy-specific ones, but you know, obviously you could use it for tons of different scenarios. but they can deploy like a fleet of computer use agents that just spin up an image, and then now the agent has full access to the system, can navigate. And do whatever it needs to do, whatever it wants to do in a sandboxed environment, right? That's the the terrifying thing when you give it control of your whole computer, is it has control control of your whole computer, which is why my environment that has that is its own environment. Like it's sandboxed, he's he's in his box, he has access to what's in the in his box, and that's it. He's not on my box. which prevents them from doing some weird shit, right? Early on when we started messing with OpenClaw, You know, I did put the first generation, I did what everybody else did. I put OpenClaw on my system and was like, this is cool. And then, you know, it reaches in and it's like, I couldn't figure out how to access this website. So what I did is I searched your whole computer and I found an API credential in this .env file for this other project, and it worked. I'm like, the fuck did you just do? Like, no.

Ryan Hughes 09:59

That's a true story. That happened because I I was I was just looking, I got a I started getting pinged by OpenRouter, like billing notifications. I like, what in the fuck is going on? And what happened is I ran out of tokens on my OAuth subscription. So it just went and got the the API key and kept going. Okay. All right.

Mark Hughes 10:21

my gosh. I was I was

Mark Hughes 10:24

carpooling I was carpooling with a dentist, funny enough, for a kid's soccer thing over the weekend and we got to talking about things and I was talking specifically about like Astra and the difference between what what AI has been, because most AI usage has been like programmed via MCPs or API access or something like that, right? It's it's it's more quote unquote code driven. than it is just like, hey, here's a here's a normal user interface. It's already made for a for a human to interact with. Can agents now actually do that too? And you to your point, they could do some of that before, but they were pretty stupid in how they use the navigation. And you know, it it it's like they it's they had helmets on, right? Like they did they really didn't know how to actually use a computer. They knew how to use maybe a browser. That's about it. But now the promise is like, okay, with Astra Can we have an AI agent be able to actually navigate a computer the way a human would? In which case, the a dentist, like the guy I was traveling with, gets excited because now he's like, hmm, can I actually have my admin peeps use something like this? And they could just use the normal workflows that we already have in place and augment some of you know the the busy work. Can they, you know, maybe be part of the billing process with insurance companies? Cause that's like three whole people's job. That's all they do. It's just

Mark Hughes 11:46

bill insurance company. So just, you know, different applications for different people that you can see something like Astra making good on its promises, the bar is now raised.

Mark Hughes 11:58

do you do you think do you think the age of AGI is actually here? You have everyone saying that now with Astra specifically.

Ryan Hughes 12:06

Well that depends. If we stick strictly to what AGI the definition of AGI is, was, and continues to be, in my opinion. No. Like it's not here. Is it incredibly intelligent—like, is it incredibly intelligent and capable of a lot of things? Yeah, absolutely. But what AGI promised and the measure of AGI is true artificial intelligence like passes a Turing test, artificial intelligence. We're not there. not even close to there. These these these things will still do absolutely fucking stupid things. now, to be fair, my friends will also do absolutely stupid fucking things. So what is intelligence. But I don't think we're there. I don't think that well I don't know that we'll ever be there though by that measure, which I think is why everybody is frantically trying to redefine what AGI is. I think I mentioned it on a podcast almost a year ago at this point where Jensen mentioned it and he was like, you know, we have AGI with OpenClaw. Like, fuck we know. Like w it's don't get me wrong, incredibly intelligent, can solve a lot of problems, very cool stuff, not AGI. Now, if we want to move what AGI means, sure. We have. The what you can do

Ryan Hughes 13:15

with a single agent is incredible. What you can do with when you pair it with a harness like Hermes—or however you pronounce that one. and I've always pronounced Hermes one way, and then David started pronouncing it another way and I was like, It's spelled the same way. So I don't actually know.

Mark Hughes 13:32

I would say Hermes, but you know, maybe that's that's our American accents.

Ryan Hughes 13:37

Yeah, like is it is it named after the I don't know. and then you have OpenClaw, like you put it in a harness, like one of those two. Even better. You can do some really incredible stuff. You start to give it memory and those sorts of things. Like I have you know, my I have both that kind of run and I then use simultaneously to bounce back and forth because I I need to. well, want and need, there's a thin line there.

Ryan Hughes 14:01

But you know they have a they have a shared memory pool, right, where everything that they know about me kind of gets contributed to this this central brain associated with me. They have a separate one for Oodle that you also tap into. So we have a sort of a central brain for Oodle that helps any agent understand things about Oodle or or things about Oodle clients or things about personnel and and Oodle. that's it separately from the brain that knows about me, but they know all this stuff so that I can ask a question. But if I just went to Astra and asked that question, it would not be able to answer it the same way. But if I go to my one of my more intelligent agents or, you know, one of those two harnesses and say, you know, hey, tell me everything I've worked on this week. They can answer that question. To a degree of certainty, they can answer that question. Because they have the history or they know where to go to get it. They're like, all right, well, he uses Basecamp and he uses the these so he can go track down anything that's been available publicly in those threads

Ryan Hughes 15:03

and say, here's the stuff that I see that you've been working on. which is really cool. I just had to use that. I used it last night actually. picking up A project that I haven't touched in almost three weeks now. I had to kind of step away for a little bit and kind of came back and I was like, I vaguely remember where exactly I was, but it was in the middle of like some pretty deep shit. so I was just like, hey homie. Look at everything that's been going that I've been working on, where we were here, the code base that I have. Help me figure out where we left off. And it did. It like it landed exactly where once it kind of summarized it, made a little artifact for me, gave me some direction. I was like, yeah. Okay. That's absolutely where we were. I remember now. but the fact that I was able to do that is incredible. And like Those are the tools and superpowers that you get that I kind of step back sometimes and I'm like, shit, there are people that don't know this exists. And if you don't know this, like you're missing out.

Mark Hughes 15:56

There are lots of people that don't know the

Ryan Hughes 15:58

Which is why our you know part of our goal with Omarchy is to bring, you know, the agentic operating system to the world. And that elicits some big responses with some big feelings. But I think that's okay. Like I think that starts a dialogue. that's interesting. You know, you kind of have the the very pro AI side of that that equation and the very anti AI side of that equation and stuck in the middle somewhere is kind of everybody else. That's fine. We should have those arguments and discourse and and find the great ways we can use these things. The other thing we haven't talked about also in the midst of models that have come out, Muse Spark 1.3. You don't we don't talk about Facebook or Meta

Ryan Hughes 16:37

launching models often because usually their models have been, you know, kind of the open-weight Llama models, which have all been pretty impressive, but they're open weight models. Open weight models don't get talked about nearly as much because They're just not as good as the frontier models. or some of them are like the you know, some of the newer models can be, but you need eighty thousand dollars in hardware to run them. So it it just doesn't land as much. Muse Spark 1.3, you know, I mentioned earlier Meta gave us $1.5 million in credits. so you know, when working on the the new Omarchy site. It it was originally built in like this TanStack Router or something or other. kind of a stack I'm not a big fan of. so before we went live, I was like, hey, why don't we convert this over to Astro? Astro's just it it's fast, it's clean, it's easy to work on, it's easy for agents to work on. I loved what the team is doing over there. So we're like, Yeah, let's do that. And We're like, well, we got one and a half million dollars in credits, let's give Muse a crack at it. See if it doesn't. I haven't used it for anything. So we ran it through that. It took, I think, 45 minutes or so. we looked at it on the other side and it was perfect. It had done a perfect job of transposing the site over. Now it's transposing, you know, JavaScript and React and TypeScript shit to JavaScript and TypeScript shit. but still impressive that it was able to do it, didn't lose anything in translation, did a fantastic job. And we're like, this is awesome. I wonder how much money we spent. Surely it must have spent, you know, a good amount of tokens to do this much work. It's a pretty big site, you know, quite a lot going on. It's twenty two cents.

Ryan Hughes 18:20

Twenty two cents.

Ryan Hughes 18:22

So we looked at that and we're Holy shit, how are we ever gonna spend all these tokens?

Mark Hughes 18:28

We want an awful lot of websites.

Ryan Hughes 18:30

But I mean that so that's the the conversation that's normally not had when it when thinking about these models. We always talk about how smart they are. Muse is an incredibly capable model. I would say maybe not quite as capable as Astra. maybe not quite as capable as Fable 5.1, but pretty fucking close for a lot of like go do tasks. And is incredibly economic. so when

Mark Hughes 18:54

Yeah, very efficient. What would you

Ryan Hughes 18:57

I look at something like that, I'm like, well shit, well, you know, how can we use this more? And you know, there's a there's an interesting thing that happened when Claude Fable 5 came out originally, we started finding a similar thing. Fable was exorbitantly expensive and chews through its limits super fast and even worse back then. so we had to figure out like how do I get Fable-level quality without you know without buying ten subscriptions. and one of the strategies to do that became a multi-model approach. So it was, you know, I had a skill that I I stole from Peter Steinberger, the guy who created OpenClaw. And it basically said like, Hey, you do all the thinking and planning and review and higher level stuff. And then just spawn Codex agents and hand it off to Codex because Codex was far more efficient. So it would, you know, Fable would do all the work and then it would spawn, you know, a GPT-5.3, I think, something, whatever, agent and be like, hey, you go, here's your contract, go execute that. And then it would come back and it would give it revisions and it would kind of go back and forth. And that was a way to spread that further. I think with Muse, there's an opportunity to do the exact same thing. It's incredibly cost efficient and incredibly capable. also supposed to be really good at computer use. Like that

Ryan Hughes 20:13

was one of the tasks that they specifically trained this model for. So I haven't used it for that yet, but supposedly it's supposed to be really, really good at computer use. So if you could get away with having an orchestrator model like Astra. Directing a dozen executors running Muse, you could probably get a lot of shit done to a high degree of quality, at a fraction of the cost that it would take you to do it just through Astra. and faster. Like Muse, I think, is a faster model than Astra is. Because sometimes it's not necessarily You think like always use the biggest, most powerful model. and sometimes that's not the case. Like those big powerful models are slow by comparison to their smaller, you know, brethren. So in some cases, you know, we did a test when we built Herald originally, the the changelog software that we have. That product in order to work needs to needs to absorb a lot of information at one time and kind of parse through all of it to figure out what in this sea of activity is relevant, what clusters fit together, what's attributed to who, right? A lot it's processing a lot of data, but mostly what it's doing is just extraction and grouping. My natural intuition was of course we should use the biggest, baddest model to pull this off. And I did. I also gave it to the smallest, dumbest model. And then we did a a about a about two or three dozen tests in between, like all different models, just to see like what is the variance between these. There was almost no variance. The main variance was how much it cost. It would be like a dollar per report for like Fable to do it, versus less than one cent for Gemini Flash. and the quality, what came out the other end, was identical. There was no discernible difference between the two. In some cases, Flash was actually better. because Fable would overthink the problem. So Flash was like, hey, I got

Mark Hughes 22:15

Yeah. That's wild.

Ryan Hughes 22:17

a I got a task to do. I do the task. And it was faster. So Flash would finish it in one or two seconds. Fable's churning for at least 30. so those are all things to think into take into consideration when you think about like. AI workloads and inserting AI into your processes and how to do it, because the best model is not necessarily always the best model.

Mark Hughes 22:39

Hmm. That's a that's an interesting perspective. And you kind of take that and you extrapolate it over to you know, non-tokenized usage, right? So something that you've strung together a couple of Mac Studios with. And what what what do you what can you do with that as opposed to using a frontier model? I think we're just scratching the surface on on that, even though there's been You know, that's been a capability for the better part of this year since OpenClaw has has kind of come out.

Ryan Hughes 23:06

I think though I think this year twenty twenty seven will be the year that like that local AI becomes as popular as frontier usage. It's my opinion. and I think that's the case for a number of reasons. One, I think that access to hardware, albeit expensive as fucking hell, is a little bit easier, right? You have Mac Studios with 512 gigs of unified RAM. You've got the NVIDIA cards, you've got in the DGX Spark, you've got all the other NVIDIA GB10 Grace Blackwell Superchip-based variants of it from ASUS and those guys. You've got a new version of the AMD Ryzen AI Max+ 395 chip. The Ryzen AI Max+ PRO 495 is coming out, and I think it has 192 gigs of RAM, if I'm not mistaken. Current one is 128, so that

Ryan Hughes 23:57

gives you. you know, an AMD chip that has more RAM that can be paired together. So I think there's you know, access is obviously easier, right? I can go to Micros I can go to Micro Center today, pick up four DGX Sparks, and have, you know, half a terabyte of memory capable of executing almost every model I would want to execute. Second, I think that the local models are finally reaching frontier tier, which is also to say that I think The intelligence increases are kind of plateauing. Like we're not seeing those monumental leaps. So it allows, you know, those those local models to or the open weight models to catch up. I think the third piece is a piece that doesn't get talked about much, but it's a piece that like I'm probably most excited about, which is these small models and the the what you can do with a small model that's hyper trained. So Typically, again, like when we think about like Fable and Astra and GLM-5.3 and all of the like top big models that are really, you know, intelligent and set all the high scores and whatever. Those are big generalist models. They're trillion parameter models that are or two trillion parameter models that are just meant to be everything to everyone, right? The goal is that they just have every bit of knowledge and information they can solve any problem they throw up. Well, that's really cool. Takes a lot of hardware to run it. It's very expensive, all those things. But what about when I only want to solve one problem? So go back to your your dentist guy. He doesn't need Astra to help him solve his billing problem. He needs a model that really knows how billing works. And like really knows how billing works. so what if you could take a you know 800 million parameter model? Very small, can fit on any computer almost, any modern computer. could probably even run under CPU power. You don't even need GPU power to run But it but it's been taught everything there is about billing and coding related to that industry. And more specifically, how to execute and use the software that they use to do the billing. Now you have something that can run incredibly quickly, incredibly cheaply, and to a higher degree of accuracy. I've seen a couple of couple of studies so far. I think Shopify actually published one of them where they they did a test where they took, you know, giant models and baby models, and the highly tuned baby model beat the absolute shit out of the big model.

Mark Hughes 26:20

It makes sense. It's a specialist versus a generalist.

Ryan Hughes 26:24

Yeah. I mean and you know, you think about that as in people we see that that play out the same way. It's no different in mod than in models. And I think that that's something we're gonna see more of the exploration of as companies start to invest. And just frankly, RAM and GPU power are expensive. They're continuing to be expensive. So we've got to get creative with how we can kind of stretch and get the maximum benefit out of what we have. There's also the other side of this that that's like, you know, again, if you think about dentist or any medical practice at all, you have HIPAA issues. You have HIPAA and all the other compliance and privacy issues, access to data, what data can be shared. So open weight models give you that opportunity too. It's a black box it's a it's a black box or or or can be sandboxed, right? So no data ever leaves no data ever leaves our network to go out. It's all processed locally on our servers. There's no data retention, there's no sharing, there's no anything that happens. Which is very different than if you use any of the the major frontier models, because those you're sending everybody that information over the wire to them. you can turn off the things that say to not use our data. I'm not convinced that they'd actually abide by that. especially given, you know, the cases where they've what was it? Facebook got got slapped with like downloading a like pirating a bunch of books and they you know they paid the fine. But it's like it doesn't matter because you already

Mark Hughes 27:51

You already got the benefit.

Ryan Hughes 27:52

Well we already got the benefit. I'll just pay the few million dollar fine.

Ryan Hughes 27:58

so I don't you know, there's no it doesn't really matter at at that point.

Mark Hughes 28:01

Well, you're you're kind of you're kinda picking on another thread that we were talking about pre-show, and that's security, right? So that it the data side, data sharing side is one level of security, but there's so many other pieces of security that in software development or creation or Omarchy operating systems, any anything else that people take for granted as being quote unquote secure just because it it feels like it's in a safe place, but it's probably actually not because all software has bugs.

Ryan Hughes 28:30

I mean, anybody who's ever worked in security, I mean, I had a cybersecurity startup that I founded and worked on for a bit. So I got exposed to a good portion of that by way of that. still have a lot of of ties in the cybersecurity field, and so you hear a lot of it. And obviously we have a security team with Omarchy that we've just spun up. Incredibly talented people. with a lot of experience. Anybody exposed to cybersecurity is becomes like I don't even want to say paranoid because you don't become paranoid. You almost become numb to what it is because you realize how little security there really is around us. every software is full of is is ridden with soft security holes, right? I think there's a fallacy that like somehow, some way People, some set of people, if they follow a certain set of rules or whatever, can create perfect software that never has a bug or never has an issue. That's bullshit. They exist everywhere. The Linux kernel, the last release of the Linux kernel had 1,500 CVEs in it. It's the most ever been ever been reported in one one report. The next release is on track to be have over 2,000 CVEs taken care of as as part of it. That's in addition to the fifteen hundred, in addition to the thousand before that. And AI is to blame for part of this, right? You have these incredibly powerful tools that can just go poke at shit. Now the the CVEs that are being exposed are weird, right? We've had some with Omarchy that are incredibly fucking weird. And like hats off to some of them. They're creative. One of them was If somebody renamed if somebody named their USB drive with a set of characters that would escape out of the the the function when you plugged it in, it could allow them to, you know, drop some drop a file or or execute some code or whatever. I like that's crazy. Like who the fuck's gonna do that?

Ryan Hughes 30:26

Like realistically, who's gonna do that? You know, it requires you to know that, name a USB drive, some weird shit that's gonna do something, and then now get access to my laptop. Right? And like if we're sitting at a table and you're just gonna like what are you gonna do? Just reach across and just like plug your USB into my laptop, at which point like I'd just fucking punch you in the face. Like I'd like don't fucking

Mark Hughes 30:48

Some mission impossible stuff.

Ryan Hughes 30:50

don't do this shit. Yeah. And like this doesn't happen in real life. But I get it. Like they're you know, it was clever. I think it was a really great find. I you know, I commend the people who figured that out that like you could do that. there's some other like really obscure things, but you just see those all the time. But I think the numbers, you see the numbers and it scares the shit out of your normal person. I saw I had kind of a back and forth on X this morning actually with somebody. We just released 4.3, had some security fixes in it. The last one had security fixes, the one before that had security fixes. We've got a security team now. That's all they do is focus on solving, you know, we're soliciting security vulnerabilities from the community. They're testing for the security vulnerabilities. And then we're solving all those. And we're very transparent about the fact that we solved them. We don't just have like security fixes, bug fixes. Right? You see you see what they are. And you know, the the the guy that I'm talking about, he said something to the effect of, you know, I hope we see the security fixes, the number of security fixes per patch go down. because I you know, I I respect this project. And I think in his head, he's thinking, Well, for patching security vulnerabilities, that means that it's insecure. It means that I shouldn't use it until it's secure. And like I th I think we're gonna see it go the other way before we see it the opposite. And I think the general data tells us that every organization now and every piece of software are finding and fixing more bugs and security vulnerabilities than they ever have. The Linux kernel itself, which runs 90% of the fucking world on the server side, is fine is finding these same CVEs and dealing with these same things. Again. Are they accessible? Could you actually exploit them? You know, all those things. There's a lot of variables associated with that sort of stuff. Doesn't change the fact that they should be patched and they should be fixed. But the the degree to what but I think that people see like two thousand CVEs and they're like, Well shit, we shouldn't be using Linux. Maybe we should go use Windows because it's more secure. I got bad news for you, dude. Windows, I don't even know what the numbers are because they don't share them. But I'll bet they're bigger. macOS,

Mark Hughes 33:09

we'll also bet they're bigger.

Ryan Hughes 33:11

I think Apple does a great job of marketing. And, you know, so people would look at macOS and be well, surely macOS is more secure. It's a Unix based system. They're probably being impacted by the exact same things and the exact same vulnerabilities that we find. Now, again, they have a security team. They're patching these things all the time, but they don't tell you what they are. They don't tell you where the entry points were. They don't tell you what they did. It's just bug fixes and security hardening. we could do that. I don't want to do that. That would be that's that's slimy. No, that's not how this works. That's not how open source works. but I think it is something that people are gonna have to get used to, is that like it's going to feel like the whole world is on fire because we have these incredibly powerful intelligent agents that don't sleep and don't eat. And can just go fuck with stuff. So much so that, you know, the the major labs now all have cyber restrictions. where like we even have run into it on Omarchy when reviewing and patching for security holes where you'll hit kind of the limit of the of the agent where it's like, Hey, you're it seems like you're trying to do something, you know, security related, you can't do that. And you have to sign up and be part of the program. And luckily we're, you know, we're part of those programs. So you get access to like on on OpenAI, it's called Daybreak Blue, and Daybreak Red, which is the red teaming variant of it. Anthropic has their program, Meta has their program. But because we realize if you give people access to the full weight of these things, I mean they can just go brute force and try to get in anywhere. And they will find vulnerabilities, they will find problems. Like whether I think there's also a a concern that with open source in particular I've heard where you know you you give you're giving the agents a blueprint to your code, of course they're gonna find vulnerabilities. To an extent I could see that as being true. That also means we can fix them faster.

Ryan Hughes 35:01

But security through obscurity is not really a security. And that's really what closed source software works on, right? I've seen I've seen and worked on plenty of closed-source software that and my data is in some of those closed source softwares because they're companies that that that we've worked with or or or giant corporations. And I am terrified at security practices that I've seen. We're like, you mean To tell me that I could just brute force this system and give myself because there's no timeouts, there's no limits, there's no restrictions, there's no there's no rate limiting. and if I get in, I have access to everything, the whole world, your whole world. good. Awesome. Love it.

Ryan Hughes 35:46

But nobody knows. Because they don't have to. so yeah, I mean I think security is Security's gonna make a security vendors are gonna make a lot of fucking money over the next ten years. and I think it's gonna be one of the most important things in every product and every corporation. And anybody who sleeps on it is gonna get kicked in the face.

Ryan Hughes 36:05

What else, I guess? We've been yapping here for like forty-five minutes. So I think that about does it for

Ryan Hughes 36:10

this episode of Not Brothers Podcast. Catch us next time. See ya.

Mark Hughes 36:16

Till next time.

Ryan Hughes 36:17

Till next time.

Where to listen