Sam: Six million fake stars. Eighteen thousand repos. Three cents each.
Kai: [excited] Okay, that's the plot twist of the year and you just tossed it out like a grocery receipt—
Sam: [dry] It's Sunday. I'm conserving energy. This is Sam.
Kai: And this is Kai! July 26th, 2026, and we've got three open-source stories with your name on 'em.
Sam: Three stories. Let's go.
Kai: First up — a peer-reviewed CMU study says six million GitHub stars are straight-up fake, and AI repos are the worst offenders.
Sam: Then CCP — sorry, Fenris Creations — open-sources EVE Online's entire Carbon engine under MIT. A real AAA engine, just... free.
Kai: [excited] Trinity AND Destiny, Sam — physics for thousand-ship battles—
Sam: And Canonical patches three snapd bugs — one's a local root escalation that should make every Ubuntu admin sit up.
Kai: Let's start with the great GitHub star heist. CMU, ICSE 2026, built a tool called StarScout and found about six million fake stars across 18,617 repos.
Sam: [dry] Finally. Someone put a number on the thing I've been muttering about for three years.
Kai: Three hundred and one thousand fake accounts pumping them. That's an army.
Sam: And here's the part that stings — those stars sell for three cents to eighty-five cents each. Your credibility, retail, under a buck.
Kai: [laughs] Eighty-five cents for the premium star? What's that get you, a little sparkle?
Sam: It gets you a fooled VC. That's the real product, Kai. The study says investors literally use star counts to source deals.
Kai: Okay, but hold on — the biggest non-malicious category was AI and LLM repos. That's not scammers, that's hype-drunk founders.
Sam: Which is worse, honestly. A malware repo buying stars, sure, I expect that. A funded AI startup juicing its numbers? That's fraud in a hoodie.
Kai: Come on, everyone's just trying to break through the noise—
Sam: [interrupting] By lying! And there's a companion gist listing the suspected projects. Names attached. This isn't vibes anymore.
Kai: [beat] Fine. Fair. So what's this mean for the person listening?
Sam: Stop treating stars as trust. Check the commit history, real contributors, actual issue traffic. Forty thousand stars and eleven forks? That's a ghost town in a tuxedo.
Kai: [laughs] Ghost town in a tuxedo. Alright, I'm never trusting my own starred list again.
Sam: You starred fourteen repos while I was talking, didn't you.
Kai: [sheepish] ...Three of them. Next story — this one I can star with a clean conscience. Fenris Creations open-sourced EVE Online's Carbon engine. MIT license.
Sam: Formerly CCP Games. Twenty-plus modules on GitHub. And MIT is the permissive one — do basically whatever you want.
Kai: [excited] Trinity does the rendering, Destiny does the physics — collision, pathfinding, all the stuff that lets thousands of ships brawl in one system without melting.
Sam: And that's the genuinely rare part. A shipped, battle-tested AAA engine going open. Most studios would rather burn the source than release it.
Kai: Right?! EVE fights are legendary — the ones that actually make headlines for costing real money in lost ships.
Sam: [dry] So now indie devs get the code that made those disasters possible. Beautiful.
Kai: Don't ruin this for me. It's a gift, Sam. Real production physics you can actually read.
Sam: I'm not ruining it. I'm genuinely into this one. MIT means no license landmines — that's the healthy kind of open source.
Kai: [surprised] Wait, was that... approval? From YOU?
Sam: One caveat — an engine dump isn't a game. Twenty modules with thin docs can be more museum than toolkit. Manage your expectations.
Kai: But if you're a game dev or a graphics nerd, this is a weekend rabbit hole. Go see how a real MMO handles massive-scale netcode and physics.
Sam: And it won't buy you fake stars to pretend you wrote it. Learn from it, credit it, move on.
Kai: [laughs] The callback returns. Last story — Canonical dropped USN-8579-1, patching three snapd vulnerabilities.
Sam: And the headline one is nasty. CVE-2026-8933, CVSS 7.8 — a local privilege escalation in snap-confine. A straight path to root.
Kai: Local, though. Attacker's already gotta be on the box, right?
Sam: Sure — but shared servers, CI runners, any multi-user machine? 'Local' is a low bar. Regular user to root is the whole ballgame.
Kai: Okay, and the second one — that's the sandbox bypass?
Sam: CVE-2026-15226, a seccomp confinement bypass, and it hits every Ubuntu release. The sandbox that's supposed to box in a snap? Snaps can climb out.
Kai: That's the part that gets me — containment was snap's whole pitch.
Sam: Which is why I keep saying convenience layers add attack surface. More magic, more to go wrong. Here's the receipt.
Kai: Alright, action item — what do we do right now?
Sam: Update. Today. Run your apt upgrade, confirm snapd's patched. It's not glamorous, it's not a shiny repo, it's just the thing that keeps you from getting rooted.
Kai: [laughs] No stars to buy for that one either.
Sam: None. Patching is the one place nobody fakes the numbers.
Kai: So — six million fake stars, and the lesson is trust commits, not sparkle.
Sam: EVE Online's Carbon engine goes fully open under MIT — a genuinely rare AAA gift, docs permitting.
Kai: And Canonical patched three snapd holes, including a local-root escalation. Update your Ubuntu boxes.
Sam: Three cents a star, listeners. Sit with that.
Kai: Before we go — I did the math on that study. Six million stars at three cents each? That's a hundred and eighty grand of pure vanity.
Sam: [dry] And someone raised a Series A on it. Guaranteed.
Kai: [laughs] For a hundred eighty grand I'd have just... written good code. Wild concept.
Sam: Revolutionary. Put it in the gist.
Kai: [excited] That's the show! See you tomorrow — and I promise to star fewer ghost towns in tuxedos.
Sam: [dry] You won't. I'm Sam — patch your snapd, and don't buy your credibility for eighty-five cents. See you tomorrow.
This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.