Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

21–30 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#21

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

They do, he said at the end if you have a support contract then they will respond and deal with security issues.

I guess the whole point of the article is to show that people should buy a support contract if they need support.

Re: Curl will not accept vulnerability reports during July 2026

#22

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)!

There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.

Re: Curl will not accept vulnerability reports during July 2026

#23

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

I think very few people would consider that to be responsible disclosure. The common practice is to allow 90 days as a minimum.

Re: Curl will not accept vulnerability reports during July 2026

#24

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

It does. The article clearly says that if you have a paid support contract they will be on-call as per usual.

Re: Curl will not accept vulnerability reports during July 2026

#25

I read one sentence into this and knew directly that the developer must’ve been Swedish!

For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break.

(See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven...)

Re: Curl will not accept vulnerability reports during July 2026

#26

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait.

Naturally some people find that this offensive since this puts a price to that “bliss”.

Re: Curl will not accept vulnerability reports during July 2026

#27
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

> Log out of all accounts, remove 2FA keys after backing them up on paper

Seems like a lot of extra work, just to go on vacation :)

I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO...

Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I spend less time on my phone than most social app users! I still do heavy coding in office a few times a month. And I am self employed for nit pickers.

Work does not have to be sufering, you can enjoy it!

Re: Curl will not accept vulnerability reports during July 2026

#29
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.

Re: Curl will not accept vulnerability reports during July 2026

#30

I read one sentence into this and knew directly that the developer must’ve been Swedish!

For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )

Not only that but the vacation is real. If someone is off then you should not expect them to answer at all (because if you do you’ll get very disappointed).
Post reply on HN