Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

41–50 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#41
post #16
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

extremely relevant recent Kai Lentit skit:

https://www.youtube.com/watch?v=5E7kBOH9owI

Re: Curl will not accept vulnerability reports during July 2026

#42

Earlier quoted context omitted.

> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…

This is the ideal, but in practice you need to own the business to live this way..

Also candy is enjoyable but 24/7 sucking on it is not.

Re: Curl will not accept vulnerability reports during July 2026

#43

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype) I have seen there to be an more influx of open source software as people are starting to create more software with vibe-coding and other things and just open-sourcing it, which while good in OSS'ing it but its mostly less valuable…

>The thing which bugs me is that OpenAI (which is an unprofitable company) is spending around what 100k$ per month for an completely AI generated slop called Openclaw. (All because of Hype)

For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop.

OpenAI is certainly not wasting the money they're spending on Openclaw, even if I personally wouldn't want to touch that particular piece of software.

Re: Curl will not accept vulnerability reports during July 2026

#44
The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!

Re: Curl will not accept vulnerability reports during July 2026

#46

Earlier quoted context omitted.

This is the ideal, but in practice you need to own the business to live this way..

Also candy is enjoyable but 24/7 sucking on it is not.

Imagine some people sleep at work... I get paid for being available, not LARPing at desk!

Much better than 2 hour daily unpaid commute at old job.

Re: Curl will not accept vulnerability reports during July 2026

#47

I read one sentence into this and knew directly that the developer must’ve been Swedish!

Hahaha yeah same here! My $dayjob has offices in Sweden and their summer breaks are legendary. We also have offices in the US, and the culture shock with the Americans never gets old

Re: Curl will not accept vulnerability reports during July 2026

#48
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…

You're basically saying to get a different job.

That's going to work in some situations, but it's not broadly applicable for many reasons. In particular it's way more work than the act of backing up 2FA and logging out of everything. So yeah, it makes a lot of sense for people to think that's not good advice.

Re: Curl will not accept vulnerability reports during July 2026

#49
post #33

[flagged]

https://curl.se/libcurl/ Let me Google that for you. supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Nego…

I think the argument was that curl is fairly feature complete (as shown by your list), is there really that many bugs in curl that require immediate attention?

Re: Curl will not accept vulnerability reports during July 2026

#50
post #16

Earlier quoted context omitted.

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

Quote from my partner's manager before a vacation: "If I see you log on, I'll disable your account."

Humm he means figure out everything you’re signed in to before going on vacation and log off?

Personally I’m sure I’d forget to sign out of something.

Post reply on HN