AI Coding Agents and the Future of Open Source with Qwiet AI’s Chetan Conikee
We’re witnessing the emergence of AI-powered coding agents that raise an existential question: Are we entering an era where software becomes completely fungible, and if so, what happens to the OSS ecosystem that got us here?
Transcript
This is Textron tv. Hi everyone. Welcome back here to techron tv.
You know, one of the nice things I like doing what I do is I get, I I, you know, I see the people and I see them cycle through, and sometimes you see someone, you don't see 'em for a year or two. I'm happy to welcome back to our show, Chean Chean. Icky Chean is the co-founder and CTO of Quiet ai, but he'll tell us all about that.
Chean, welcome back to Tech Shrunk tv. How have you been? Thank you, Alan.
It's a pleasure to see you again. I'm doing great, and I'm hoping you are doing, uh, good as well. Yes, pleasure to be back.
It's good to have you. Um, you know, for those who follow along at home, uh, the last time, well, you've been co-founder and CTO of Quiet ai. Well, let me not, let's go this way with it.
Chean, tell us a little bit about Quiet AI and your role in it. Excellent. Um, let me start with my background and then, you know, I'll give you a sense of what Quiet is and what it was formally.
Um, as Alan stated, my name is Chaan Knicky. I'm the CTO and co-founder, um, of Quiet or AI formerly Shift Left. My background has primarily been at the intersection of, um, mathematics, infrastructure and banking, investment in retail.
That's where I journeyed into, you know, systems and, and got to where I am. Uh, in my past, I worked with several startups that were building systems to essentially manage some of the function that you execute. You know, when you're banking, meaning when you're moving money, when you're opening an account online, when you have systems that conduct two, two factor verification of your identity.
Um, there are many systems at play beneath what I just described. So much of my career was spent in building these systems, and then I pivoted briefly in the middle to taking the same principle of these systems, but detecting fraud because, you know, when banking became prevalent, brick and mortar shifted to online fraud became prevalent. So I spent a lot of time essentially protecting the systems that I built.
Um, and finally I landed into cyber. Cyber, which was primarily focused full-time on building systems to detect mal-intent in different ways. So, um, shift Left was the company that was co-founded almost about six years ago.
Our focus with Shift Left was can we analyze source code, which eventually becomes applications when you're deploying, you know, your data centers to serve your customers and detect vulnerabilities in this source code before it becomes an application, which means it's almost like precog before something bad happens, can you detect the bad and prevent the bad from happening? So that was the hypothesis on of building Shift left, and hence the word shift left, which is, you know, it was very popular during, you know, the last, you know, maybe about six, seven years ago, where everyone was speaking of moving performance, bottleneck, detection, security to the far left, which is the development phase. So you don't land up reacting to events when they happen the far right.
So we built Shift left. ai. The word quiet is a play on quiet, which is Q-U-I-E-T, because often security solutions are all about planting fear.
You know, they use the color red. It's all about alerts, the world falling apart, and here's the system that's out there to save you from, from this Roth. We want to take an opposite stance, which is what if the system is humming along in the background, helping you detect what matters, helping you fix what matters based on that detection.
So everything is quiet. Mm-hmm. So That's, so it's in a nutshell, it's interesting because when I, when I think of quiet and, and then security systems, so to me the opposite of it is noise.
Yeah. Right. And I think that's been a problem all too often.
I've been, I've been in security 30 years, is they all tend to make noise, and they, and there's so much noise that you become desensitized to that noise. And then, you know, uh, if everyone's talking at once, no one's talking as they say, right? And, and that, that's kind of the, the piece of it.
But you're right with the shift left, right, as we sit here, now, the concept of shift left itself is not a bad thing. But the, I think where we ran into problems was number one, you know, how far left if you, eventually you wind up putting it on the shoulders of the developer and the dev. In the case of security, the developer's not a security person.
They wanna develop quality code, but they don't want to be the security person. They want to be the developer. They want to develop code.
Secondly, I think we ran into issues that security tools designed for security people don't translate well to DevOps people or, or, uh, you know, those, uh, developers and what have you. I think we've seen the rise of the platform engineering discipline, which, you know, depending who you talk to, it's old, it's new, it's recycled, whatever, but as, as a result of just sort of too much shift left. But you're right, in a, in a perfect world, and using things like AI and machine learning, this stuff should go, it shouldn't rise to the level of the developer per se, right?
It should hum along quietly, hopefully, and, and, and do these things. How, you know, I would imagine the last two years with the rise of ai, machine learning continuously getting better has really allowed you guys to make a lot of progress in that regard. Absolutely.
Absolutely. Um, you know, let me start with, uh, your first statement in the narrative, which is, um, you know, security is all about noise. Fear, you know, induction of fear sells better than, you know, induction of guarantees, right?
And hence what happens is, everywhere you go and you're listening on maybe a floor of RSA, you see a lot of banners just positing and selling fear, right? Mm-hmm. And, and you want to protect yourself, hence, you buy into that fear.
The consequence then is you are overloaded because you, you are just inundated with lots of alerts. You land up with alert fatigue, you have no idea what you need to do. Then you go buy another tool that says, I will remove and filter those alerts.
And then you buy another tool that says, Hey, you know, yeah, many alerts from many systems, I'll advocate it for you. And what you have now is a barrage of tools, right? And, and there's, you're still vulnerable at the end of the day.
Nothing changes, right? It's status quo. So, um, the question is, how do you effectively build a system that can convey the information to the persona without running interference?
Uh, you also stated in your statement that at the far left, the persona operating are developers. Developers are not incentivized based on the number of vulnerabilities they fixed. They're incentivized on the number of products they build.
So they don't care about security. It's just a direct consequence. So how do you plant a, a tool or a measuring instrument that can do its job without interfering in the productivity curve of a developer?
That is our, that's how we started. Because our true knot saying, can we integrate and speak the language accordingly based on the persona? Meaning, when security folks place tools that run interference and develop a path, the natural reaction is to abandon, or the natural reaction is to say, take it out.
Because first of all, I don't understand what this thing is saying to me. The other is, fixing vulnerabilities is not mapped to my bonus, so why should I care? I'll just react to something, something happens in the future.
We'll figure it out for now. We don't have to care. So, uh, the most important goal that we, we strived with is there are two personas on the far left.
One is the security team and the devs. We will effectively communicate to each of these as we analyze and provide solutions without running interference. So with that true knot, fortunately, generative AI came to the fore where, uh, LLMs became popular.
They became an augmented instrument of reasoning. I would use the word augmented, because often, again, marketing says, Hey, here's this AI thing. Go replace humans.
Ain't gonna happen anytime soon. Because we understand, we as humans understand context. We understand what matters to us, our teams, our organizations.
So where LLMs or generative AI benefits us is it takes away those things that we otherwise need to do, those many things that we need to do to accomplish our goal. But these machines do not have understanding of the context, metacognition and intelligence to say, Hey, I will replace the unit. So with advent of generative ai, we use our existing technology to discover vulnerabilities in a very, very precise fashion.
Then we guide the large language model saying, here is a pathway that is vulnerable. Here are the policies that we use to detect the pathway. Now furnish, with all this context, how would you suggest remediation?
Now, the generative AI system takes all that information, precise context information, and then creates a patch. And now we serve the patch back to the developers. And this is a clear non-interfering way of, of approaching, you know, communication with the developer.
Because without these, the developer needs to take the finding, figure out how to fix it by googling, bringing back a patch and saying, okay, is this patch good enough? So I have to write a test case and then doing code review to see if it's good enough. Now, all of what I just described is subsumed or taken or owned by the generative AI system.
So that's where we are. That's why quite, and it's our core technology is what we call as the code property graph. Think of it as a Google Maps for your source code.
We take the map, we take generative ai, connect them together, we produce a patch, and IPN the developers get what they want, which is secure code. Love it. ai Q-W-I-E-T, not Q-U-I-E-T-Q-W-I-E-T.
All right. Let us pivot. Talk about what we wanted to talk about today, which is the rise in and potentially the fall of, as it's called the open source Lego Tower.
Are we entering the era of fungible software? Um, So as I spoke to you about it, I have my own views on this, but let me, let me let you go first. I recently wrote an article, um, on Substack, uh, positing this controversial discussion, which is, is, are we in the era of fungibility or, you know, the ability to recreate something from the scratch instead of leveraging, I, uh, took a position, 50 50.
I say, open source will still be relevant because ai, most of AI has been trained on understanding code that used open source in an effective way. So when it makes a recommendation, which is, you know, on the basis of its pre-training, it is going to recommend the use or of a certain library, sometimes it can go out of whack and just fictionally create a library that doesn't exist in, in, in the lingo Aramco of, uh, generative ai, they call this hallucination. Um, hence as humans, you gotta be the critical thinker.
You have to really see, is this just created out of fiction or is this real? How effective is this? And so on and so forth.
So coming back to your question, half of my position is open source will still be relevant. It'll still be hugely impacting how generative AI will use or choose certain libraries. But as models get intelligent, you can ask a model to create a library from scratch using prior knowledge that it has gained and has been trained on other libraries.
Um, except you as the critical thinker, should be smart enough to understand whether it's done a good job or not. Is it better than that library or not, right? Yeah.
Or is good or, you know, look, there's a couple of ways of looking at this. One is, I, I think from a, a developer point of view, if you will, right? Is the code good?
Is is the code I'm generating in AI as good or better than what may be available to me via open source? But I think there are other ways of looking at it. One, once I make the decision to o use open source, you know, there's free is and freedom and free is and beer with open source, right?
And so I may not be paying for that code with money, but I am getting, uh, I, there are strings attached there, there's a license there, there's IP there, there's things I'm supposed to do if I make changes to the code. There, right? There are it, it's the free is in freedom part can get a little tricky.
And if I can do as good or better by just building it, you know, via, uh, gen AI in a chat chatbot or even an agent or something, why wouldn't I, and not entangle myself well, back and forth on the open source. But then there's the legal concept here, cheating, right? Are we going, so to speak, from the frying pan to the fire, right?
We, we don't want to use the open source because of all the potential IP or entanglements it may have, but is that code being generated by our AI also free of copyright claims or IP claims? And I, oh, um, it's like this right now. Absolutely.
Yeah. You know, um, if I may, um, there are two sides of the coin, right? One is the most of generative AI has subjectively been trained on preexisting open source, independent of the fact of whether the open source was Apache, G-P-L-G-N-U, you know, that, that, that aside, it has been trained on a broad swath of such libraries.
And the very generative nature is it'll generate something from scratch, and you as the owner of the system, can choose whatever license you wish for it to be. Which, which means that, you know, if you have good faith, you just put it, make it Apache, you put it out, make it someone else's, uh, um, stack element and, and provide value to them. So from the, from the get go, right?
The two aspects. Now, when you, you're generating and using open source, you got to be judicious in terms of how you ask generative AI through the process of prompting to say, Hey, recommend this to me, but make sure any library recommend is Apache license, which gives me distribution freedom and doesn't make me liable. Um, then the second aspect of generating is up for grabs, because, you know, most of the vendors are not transparent about how they train their system.
So you don't know. Hence, you know, you become a consumer of the system with ignorance. Well, what we call that blissful I ignorance, right?
Yeah. Because it, it's sort of, I don't, what I don't know won't hurt me, hopefully, right? And I could exactly, I could plausible deniability as they say.
Exactly. Um, exactly that, you know, I, it, it, so here's the thing, and I think you hit it by, by hedging your bets here on a 50 50, right? It's gonna be interesting to see how this plays out because they, here's something else about the open source though.
If I'm truly using the open source software, one of the reasons theoretically I'm using it is the benefit of community, real live people. We think they're live and real anyway, who are continuously updating the code, making it better, coming out with updates and packages, fixing bugs, all of the above. If I'm just getting that code generated for me, you know, in a point in time from an ai, I'm losing out on the benefits of that community, There's always a trade-off, right?
Um, I'll sort of give you examples of trade-offs. Now, we as being humans carry with us, our biases carry with us, our issues, our moods, and our social anxiety, and our ability to communicate socially. Right?
Now, if you examine any open source community, it is not singing and humming along with, uh, with bliss. You have engineers who don't get along with each other. You have someone who has a bad day and says, heck, I'm gonna take five days to put this patch out.
So question is, what are you trading when you move to the other, other, other side of the, the, the pond, right? With generative ai, you, what you're trading off is no biases, no mood swings, no, uh, nine hours a day, work week. Uh, they're just trying.
The AI system is at your dispense all the time, but what you're getting in return is, uh, inaccuracies, hallucinations, um, and your governance. You have to stay on top of things by being the critical thinker and observing what it's produced so that you can course correct it to get what you want off it. So both the issues lie on both the sides because, you know, examine every open source community, they start off with the hope to become a communal offering.
Progressively it becomes a burden because they wanna monetize and they wanna make money because everyone needs food on the table. 20 cents a pop. So why are they making money?
And why, why am I not? And they flip the license, and we've seen that play out with HashiCorp. We've seen that play out with literally every offering that existed or originated as open source and then became monetizable.
So, um, where I'm getting at, I take that 50 50 position because, you know, there are advantages when you work with humans. They are disadvantages too. When you work with humans, they, and the same goes with AI advantages, disadvantages.
So it's up to you at your mercy of what you're gonna be trading off when you journey on a certain path. Agreed. Agreed.
And I think the other thing is, is we've gotta remember that we're still at the beginning of this journey of, of AI generated code. You know, I was, was reading an article today, you know, the hot thing that was of course, vibe coding, right? Everybody's vibe, coding, and really, is it dependable?
Is it, is it commercially viable to build your product on Vibe code? I bet you there's more stuff built on Vibe code than we know about, or we're giving credit to, but it's still a, this is still a developing area, cheating. I I, I think we may not know the answer here for another six months to a year.
Great question, right? Um, this, this whole concept of this metaphor of vibe coding was created by Andridge Pathy, uh, very intelligent person, uh, was the head of research at OpenAI, uh, out of humor and sarcasm. He just put that out on Twitter, and now it's become a metaphor.
It's got a Wikipedia page and it's a thing, right? But if you deconstruct what white coding means is, can a non-engineer engineer a system? I can, I just use natural language and summon AI to create applications out of thin air.
I would say no. Uh, it's a thing right now, at best. What it's gonna get you is lots of LinkedIn, thumbs up, likes, comments, lots of tweet replays, but reality is far away from that, right?
Because ai, generative AI needs to be communicated with from a human perspective, you have to be a critical thinker in the loop. And I would use the word you, because when you ask the system, you have an intrinsic understanding of what you want off it. You understand the circumstance, it's used, the environment, and all of those aspects.
So if you do a great job in communicating all of that, you get better results. But still, there is a large likelihood that the model will just wean off the path, and you have to rein it back in. So, um, this white coating thing is just all fun, in my opinion at this point.
You know, uh, you can just build an app, tweet it, get some likes, but heck no. You know, you can't push something into production because that's epic disaster, uh, waiting to happen. I'm, we're recording this.
I'm gonna replay it for you in that's six months. We'll check in and see what's the, if, if, if your opinion has changed, It'll not. I'm, I'm kind of, uh, asphyxiated because, you know, I went through the journey myself, right?
I said, okay, can I wipe code an application? I wrote another post in LinkedIn about it with evidence. Um, and, and I'll tell you why it won't work.
You know, of course I might be wrong because, you know, as models get better, things get better. But, uh, most of the critical thinking or reasoning in large language models, which is in vivo happening inside the model, uh, is powered by reinforcement learning, where, you know, you, you assign rewards and punishments, right? Um, sometimes the model, when it begins to think itself, it assigns a reward.
Saying, a successful build is what I want the outcome. And when it assigns a reward, it takes shortcuts. When a, when it compiles and you have some function failing, it'll just remove the whole function just to make your code compile.
And now suddenly you've remote something so critical as workflow that you have no way back if you haven't backed up. So, uh, my position is that you can wipe code, but you need to be the captain of the ship. You have to understand step by step what is generated, reflect, and then readjust, reorient, and push the system in the right direction.
I am not subscribed to, you know, the Twitters and LinkedIns because at the end of the day, a like is not gonna get you anything. It's just gonna make you feel good. So many folks are creating these apps and these little tiny toy apps, putting it out there without understanding consequences.
And, and there was one gentleman, you know, who tweeted, and I'll hopefully, I, I, it's not on top of my head. He attempted to wipe code and pushed it to production. And he got hacked badly.
He got badly hacked, and he was brave enough to drop his narratives of how he started working backward from that bad position he got into. So, where of getting at this trends happen, there are many who subscribe to the trend. The trend rises.
It becomes a metaphor, it becomes accepted as a norm. Um, but you know, as, as general critical thinkers, you have to evaluate, is this right for you? Is this wrong for you?
And then make the judicious decision. Yeah, it, you know what, it's interesting times, my friend that I'll tell you, it is, it's interesting times. Hey, we're over time and I'm already late.
But again, it's Q-W-I-E-T, ai. You got it. So Keon, I've been talking to you.
Always a pleasure. Co-founder, CTO at Quiet ai, will you be at RSA? Yes.
I'm gonna be Stop by. We're our broadcast alley all week. Come by.
We'll, we'll see you in person. Fantastic. Um, check him out.
Quiet ai, this Tech Drunk tv. We'll be back in a moment with our next guest. Thank you.