Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

71–80 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#71
post #18
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

Especially since it appears there is a solution if you truly need a fix. > Or you get a support contract and we get to read about it earlier.

In 2026 there is a considerably cheaper/quicker solution, but that in no way invalidates OSS maintainers' right to enjoy a summer vacation without interruption.

Re: Curl will not accept vulnerability reports during July 2026

#72
post #39

For anyone who thinks this might matter for security: * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.

> if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co

No, that is the point, they are not going to accept your vuln report. They are taking a holiday.

Re: Curl will not accept vulnerability reports during July 2026

#73
post #58
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

Thanks for the reminder that this shouldn't be taken for granted. I am a German and sometimes this privilege feels so normal that it's unthinkable that it could be different elsewhere in the world.

Re: Curl will not accept vulnerability reports during July 2026

#75
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…

Regarding your edit, you might be ok with going on a multi-day hiking trip or family holiday while still doing some amount of work from your phone, but many of us think that's a bad idea.

Truly disconnecting from our work is necessary for our mental health. When I'm on vacation, I want to be on vacation, which means not working.

Again, maybe you don't want to actually fully be on vacation from work. I guess that's fine; you do you. But I don't think that's healthy for most people, and regardless of health, many people do just want to completely disconnect from work for some number of days.

Re: Curl will not accept vulnerability reports during July 2026

#76
post #16

Earlier quoted context omitted.

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

Being the only dev in a startup since 2 years without a single day off where I wasn't messaged by my employer I want this. At least I'll have a 3 week out of country trip where I do not bring my laptop later this year...

Honestly, that is just bad management. It can make sense if it's your company, but even then, the risk profile is just off the charts. What happens if your only developer leaves or gets sick?

Real engineers think about handling things when stuff goes wrong, not "everything will be on the happy path forever".

Yes, there are constraints, but to me this sounds like an unacceptable level of exposure.

Re: Curl will not accept vulnerability reports during July 2026

#77
post #22

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.

You don't really though. Sure you can fork it and fix your issue, but then what? Are you going to maintain your fork in perpetuity? Are you going to patch all the software that depends on the code you fixed to use your version instead of upstream? Are you going to get your users to do that too?

In most cases this is extremely impractical.

Re: Curl will not accept vulnerability reports during July 2026

#78
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

> Log out of all accounts, remove 2FA keys after backing them up on paper Seems like a lot of extra work, just to go on vacation :) I would suggest another approach. Automate your work, that you can work from your phone. I go on multi day hiking trips, or a week long family beach holidays, without taking PTO... Edit: I do not get negative reactions. Big part of my work is to monitor system, and answer questions. I sp…

>> Log out of all accounts, remove 2FA keys after backing them up on paper [...]

>> Signed: Former workaholic.

> Seems like a lot of extra work, just to go on vacation :)

That's the point, this person and plenty others, are NOT able to "just" go and disconnect. If you can do that, wonderful for you, but please don't assume others are like you precisely when they are humble enough to clarify that they do have a problem and try to help others to overcome it.

Re: Curl will not accept vulnerability reports during July 2026

#79
post #54

Earlier quoted context omitted.

For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Yeah, but there's little culture of actually taking that time.

Re: Curl will not accept vulnerability reports during July 2026

#80
post #26

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.

There are no "rules" for responsible disclosure. We have guidelines that we have broadly accepted, but at the end of the day whether or not you discussed responsibly is in the opinion of your peers.

There's no such thing as "responsible disclosure on a technicality". Don't be a dick, and work in good faith to keep users safe.

Post reply on HN