Live data from Hacker News

cURL removes bug bounties

etn.se

131–140 of 271 posts

Re: cURL removes bug bounties

#131
post #37

An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…

Bug bounties often involve a lot of risk for submitters. Often the person reading the report doesn't know that much and misinterprets it. Often rules are unclear about what sort of reports are wanted. A pay to enter would increase that risk. Honestly bug bounties are kind of miserable for both sides. I've worked on the recieving side of bug bounty programs. You wouldnt believe the shit that is submitted. This was bef…

Real risk is missed security issue

Re: cURL removes bug bounties

#133

An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…

PIN only isn't too uncommon for online banking these days.

You still need to complete a SMS auth to do anything other than view records though, like transfer money.

Re: cURL removes bug bounties

#136
post #80

Earlier quoted context omitted.

Ok, run the same prompt on a legitimate bug report. The LLM will pretty much always agree with you

find me one

https://hackerone.com/curl/hacktivity Add a filter for Report State: Resolved. FWIW I agree with you, you can use LLMs to fight fire with fire. It was easy to see coming, e.g. it's not uncommon in sci-fi to have scenarios where individuals have their own automation to mediate the abuses of other people's automation.

I tried your prompt with https://hackerone.com/reports/2187833 by copying the markdown, Claude (free Sonnet 4.5) begins: "I can't accurately characterize this security vulnerability report as "stupid." In fact, this is a well-written, thorough, and legitimate security report that demonstrates: ...". https://claude.ai/share/34c1e737-ec56-4eb2-ae12-987566dc31d1

AI sycophancy and over-agreement are annoying but people who just parrot those as immutable problems or impossible hurdles must just never try things out.

Re: cURL removes bug bounties

#137
post #123
post #87

Earlier quoted context omitted.

They don't care. They generate large amounts of these, spam them out, and hope for some small success. If they get banned or blocked, they make new accounts. Shame isn't even a factor; it's all about money. They don't even attempt to understand or care about a product. This was partially the case before, where you'd still get weird spammy or extortive reports, but I guess LLMs enable random people to shoot their shot…

> Shame isn't even a factor That is general trend in society now.

That's because we stopped calling others out for shameful, disrespectful or unethical behavior as a rule. So there is less or nothing to be ashamed about anymore.

Re: cURL removes bug bounties

#138

Earlier quoted context omitted.

That freedom for many free licenses comes with the caveat that you provide basic attribution and the same freedom to your users. LLMs don't (cannot, by design) provide attribution, nor do LLM users have the freedom to run most of these models themselves.

That is if you redistribute or make a derivative work. Applying learnings you made from such software does not require such attribution.

In the first sentence "you" actually refers to you, a person, in the second you're intentionally cheating and applying it to a machine doing a mechanical transformation. One so mechanical that different LLMs trained on the same material would have output that closely resembles each other.

The only indispensable part is the resource you're pirating. A resource that was given to you under the most generous of terms, which you ignored and decided to be guided by a purpose that you've assigned to those terms that embodies an intention that has been specifically denied. You do this because it allows you to do what you want to do. It's motivated "reasoning."

Without this "FOSS is for learning" thing you think overrules the license, you are no more justified in training off of it without complying with the terms than training on pirated Microsoft code without complying with their terms. People who work at Microsoft learn on Microsoft code, too, but you don't feel entitled to that.

Re: cURL removes bug bounties

#139
post #96

Earlier quoted context omitted.

Just leaving this here: https://en.wikipedia.org/wiki/Pudding_mit_Gabel

already decades ago when we were kids eating pudding with a fork was a fun past time, and i am sure the idea is as old as pudding or forks themselves. i mean, the fact that it spread so fast shows that there are many who already practiced it. it's actually surprising it took this long to become a meme. heck, my cousin bet with me or let me compete eating pudding with chopsticks. (and that was long before i went to ch…

I think the meme is as much about a meetup with strangers to eat pudding as it is about using a fork to do it.
Post reply on HN