The original promise of personal computing was a new kind of clay. Instead, we got appliances: built far away, sealed, unchangeable. In this essay, we envision malleable software: tools that users can reshape with…
75 comments
There was a cascade of subtle issues which blocked every possibility.
My mother was using an an Apple iPad and I was using Linux. I sent her the link to the Google Meet to her email. When she tapped it, it opened in Safari browser. Safari did not allow screen sharing via Google Meet so I told her to download Chrome and told her to copy the URL into Chrome. Safari would not let her copy the URL from the address bar... She ended up literally typing out the URL and the resource ID by hand while I read it out to her. Then when she opened Google Meet in Chrome, it required her to download a browser extension (I don't recall having to do this on Linux)... Anyway it was unbelievably tedious.
It's obvious that operating system companies have been intentionally making it difficult to 1. Know where you are when browsing your file system or the web and 2. Copy the URL or path between different apps.
This has been a major point of frustration for software developers. First, it started with OSes hiding file extensions, then converting the address bar into breadcrumbs/buttons which can't be highlighted or selected... Then hiding the protocol (e.g. http:// or https://) then hiding most of the start of the breadcrumbs which make up the address so that you can't even see the full path in a single screen and you can't even select individual words to copy even a single folder name.
And this trend spread to a lot of other apps. Sometimes in downright dangerous ways. For example, recently, I noticed that my email client was hiding most of the email address of the sender of an email I had just received. If I clicked on the email address it opened up their contact card in a modal but only showed their name! Their email address still cut off on the contact card view and also not selectable... I just wanted to see if the domain name was legit but I physically couldn't see what the domain name was. OMG. Nowadays, whenever I'm forced to use one of these crappy web applications, I just open up the Chrome developer panel and inspect the HTML directly. I don't know what's wrong with people that they put up with this stuff voluntarily.
I think the essence of the GPL is trying to solve this issue, the freedoms of that license is focused on keeping software as editable as possible. The idea of malleable software is not new but most "business/industry" software is still very rigid.
One of the more interesting realized concepts of malleable software are the freewheeling apps from Kartik Agaram (https://akkartik.name/freewheeling/). Additionally in my opinion the idea of malleable software is at the core of unix everything is a file and the plan 9 system.
That's, uhm, normal and why groups form by interests, from cooking to hiking to reading to hackerspaces to rocketry. I see it as neither bad nor sad. My 2c.
DUH.
Guess what? That same knowledge gives you agency. With LLMs now, even more so. Want something? Build it (or have claude build it)
Why are you being a defeatist over something you can't control that was always the case? Nothing has changed.
But I don’t like to just bitch. I like to build. So then I show the free and battle tested software I built lovingly over a decade, that solves exactly this, and that I use in my own companies, but also give away for free
https://github.com/Qbix/Platform
What more can I do? I’m just some guy in Brooklyn, who never got funded by VCs (except Balaji’s fund) but persisted for over a decade and published nearly everything as open source for the benefit of others who might know how to deploy it. I keep sharing better and better versions over the years.
What initially surprised me over the years is that the result when I share all this for free on HN is… I get downvoted by other HNers who vehemently hate someone “self promoting” a solution to this very problem. They donmt just “not care”, they care very much that others on HN should not be exposed to such free and open source solutions
Having faced the same problem (of people not running their own servers), I went ahead and built an all-in-one server that you can use to create binaries, copy them, manage public web files like in redbean, as well as php files to run inside the server, then distribute those too. Took me months of iteration with Claude. When I posted it on HN got… 3 upvotes.
Then it was resurrected and reposted by the mods, got 40 upvotes, lots of snark about me having dared to use AI to build it, and “TL;DR” comments, and then… the post resurrected and reposted by the HN moderators themselves was… flagged:
https://news.ycombinator.com/item?id=49749789
In the days since, I have improved the server a lot and v2 even lets regular PHP script kiddies build a Jack-Dorsey-style app on iOS and Android. Many people on HN will immediately have a reaction: “why PHP, it’s so old”. So I updated the github to answer that:
https://github.com/Qbix/webserver
Again, this is MIT licensed, and open source. On Reddit, the situation was even worse. Lots of upvotes at first, then anyone saying nice things about it got heavily downvoted and various trolls started posting snarky comments. Oh well, at least it attracted 150 stars and some people are actually forking it and using it.
But let’s be real, not everyone wants to run a webserver. That’s why we had “commodity hosting” in the past. But how to make it so that people can “just use” software they can trust, without anyone being able to tamper with it? In 2017, I got enamored with Blockchain for that reason. I saw tens ofnthousands of people running nodes, and letting normies “just post” transactions. I saw a way that high-calue transactions and balances could be protected. I launched Intercoin Inc, raised half a million dollars (and more since), built the software, deployed it on 7+ EVM blockchains, and made it freely accessibls:
https://intercoin.org/applications:
https://www.sec.gov/Archives/edgar/data/1733567/000173356718...
Unlike most projects in 2018, we treated the fundraise like a security, and tried to do everything by the book. But, just sharing anything with the word “blockchain” in it should earn me the wrath and downvotes of a certain very active subset of HN. I feel like they almost see the word “blockchain” and insta downvote. Maybe these mechanisms are not even human? Who knows. It cost a lot of money to get right at the time, and released as free and open source. This is Hacker News. One would think they’d celebrate this, let others discover it and use it, even if they themselves don’t like web3. <— (there, I put that “keyword” in there, watch what happen to this comment now). But no.
But blockchain was expensive, slow, and couldn’t hold secrets. And that brings me to… my solution in 2026, which I spent over a year designing and building with AI:
https://safebots.ai/safebox.html
For now HN is split between AI fans and AI lamenters (I saw this arc in web3 too). So this should get a mixed reaction. Even though Safebox isn’t even only for AI. It’s a new security primitive, like blockchain itself was.
The key is this: normies don’t have to run it. You can run it, by cloning an EC2 instance, getting clients, and autonomously earning in safebux, which you can cash out on the… blockchains. Oh am I going to be downvoted now. There is nothing to configure, manage, etc. It is like running your own “commodity hosting”, except you never get to access client data, and you get paid through the decentralized system automatically, and clients get security, failover, etc.
There is much more to this, and soon you’ll hear more about it. But I expect to find - not just people “not caring” - but violent opposition from a very vocal and activist subset for some reason. I mean, I build it, refine it for a decade and give it away for free, for others to serve each other and make money. If you don’t want to, that’s fine, my company will run most of the servers (like Matt Mullenweg’s Wordpress.com did). Or you will be able to run some too, by just cloning an EC2 in your account on AWS, GCP, Azure, OCI, etc.
Once again, it’s not “most of the people out there”. Watch what happens right here on HN.
PS: Safebots + Safebox + Safebux is coming out in a couple months. Until then, I have released Safecloud for encrypted and decentralized storage, absolutely for free, and a alightly technical person can run a backend (Jet). And literally anyone can contribute storage and earn safebux by simply opening a tab and keeping it open. Or don’t earn safebux - the default is absolutely free, for everyone. Use it for some stakeholders or users of your own websites to contribute redundant storage. Or don’t. But at least maybe upvote to let others discover it? Anyway. Here are the links:
https://safebots.github.io/Safecloud/
Academic writeup: https://arxiv.org/abs/2606.09870
And initial coverage by security magazines:
https://www.helpnetsecurity.com/2026/06/19/safecloud-browser...
We're doing what we can. The point is it's not enough. One day they will lock us out either way.
The whole point is we can't create an open source computer fab. They cost billions of dollars. It's just not happening. We can make free software at home, but we can't make free computers in our garages. Unless we figure out a way to do this, it's pointless. The chip manufacturers will be the ones responsible for the end of our freedom.
Malleable software: Restoring user agency in a world of locked-down apps - https://news.ycombinator.com/item?id=44237881 - June 2025 (114 comments)
Read the full thread on Hacker News →
Related stories
- Lobsters · 86 points · about 1 year ago
- Hacker News · 1 points · 7 days ago
- Hacker News · 1 points · 7 days ago
- Ars Technica · 0 points · 6 days ago
- DEV Community · 27 points · 9 days ago
- DEV Community · 3 points · 8 days ago