The context: heise covered an ESR essay published this week arguing closed source is over. Not eroding — over. The demonstration is a DOS shareware game ("Firefighter") that Raymond ran through an LLM-assisted decompilation and rewrote in Rust; the claim is that the model recovered the original Borland Pascal structure, including meaningful function names, from the binary layout. He followed it the next day with what heise calls out, in exactly the right tone, as "not yet proven": the claim that a Photoshop-class application has been fully decompiled this way.

Read the counterarguments too. Security researchers heise quotes aren't dismissing the trend — they're pointing out that obfuscation gets cheaper to defeat but doesn't lose all its value, and that code signing and secure boot still prevent modified binaries from running on locked hardware even when the binary itself is readable.

What's actually new underneath

The novel thing in Raymond's essay isn't the headline hype or the one-DOS-game demonstration. It's the legal divergence he names in passing, and it matters more than the cultural claim:

  • In the US, Raymond argues the path is viable: decompile to a specification, generate fresh code from that spec without referencing the decompiled code, and you're in the same territory Phoenix Technologies used to clean-room the IBM PC BIOS. With an LLM doing the front half, he puts that work at about a day.
  • In the EU, the Software Directive plus an ECJ ruling he links (C-13/20) limit lawful decompilation to what's necessary for interoperability and error correction — a substantially narrower path than the US rule.

One legal regime makes "we reverse-engineered it and rebuilt it" a defensible engineering practice. The other makes it a narrower, interop-scoped exception. If you are choosing where to host infrastructure your community depends on, that divergence is not a curiosity — it is part of the jurisdictional surface.

The practical effect on community infrastructure

Here's the part that lands for people running fire halls, city halls, co-ops, and small networks:

The auditability argument for open source just got stronger, and the "we're sorry you can't see the code, trust us" argument got weaker — not because ESR says so, but because the excuse no longer holds mechanically. A vendor's remaining argument for shipping an opaque binary is no longer "you couldn't read it anyway." It's "reading it just became cheap enough that we're worried you will." That is a different, and much worse, look for a vendor selling to a community.

At the same time, this site has argued before that compliance theater and vendor trust promises aren't a control plane. LLM-assisted decompilation doesn't change that — it changes the cost of discovery: if a community gets a binary-only device (a router, a camera, a tool that "phones home") and wants to know what's actually in it, the practical cost of that question just dropped by orders of magnitude. That's the actionable shift, and it's a real one.

The honest limits

  • One 1990s DOS game is a demonstration, not a proof of scale. The triple-A decompilation claim is secondhand and unverified.
  • Code signing, secure boot, and hardware attestation still gate execution, not reading. Locking down the run-time path is unaffected; the audit path is what got cheaper.
  • SaaS sidesteps all of it — if the code never ships, there is nothing on your disk to decompile. Binary opacity is fading as a moat; hosted opacity is not. That's the same sovereignty-washing pattern this site has mapped before, and nothing about the current LLM wave fixes it.
  • Cloud-only software and patent thickets are, per Raymond himself, the two places where the closed model still holds — tax software among them, because its value is rule-maintenance, not code.

What to do with this

Not much, operationally, tonight. The claim that matters — that decompilation is now cheap enough for a skilled individual to do routinely — is one-person-anecdote-strong. Treat the essay as a signal, not a result.

But if the direction holds, it lands in an uncomfortable place for vendors, not for communities. If binary secrecy keeps eroding, the moat moves from the code to the operational discipline around it — patches, updates, support contracts, the things actually hard to fake. Vendors who make money on secrecy alone are the ones exposed by this trend, and communities who chose FOSS for auditability were never the ones buying secrecy in the first place. For anyone who has read this site for longer than one post, none of that is new advice — the underlying architecture decision hasn't moved: run code you can inspect.