Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

101–110 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#101
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

My company have accidentally forced this on me, and it is great.

I used to have a desktop that I could VPN+RDC into from my personal laptop or desktop to work away from the office¹. I've now got a laptop, that refuses to let me authenticate remotely and they have no interest in fixing that as there are other priorities, so I simply can't work if I don't have that laptop with me and I'm not carting it around when I'm already carting my own around (and if I'm not carrying my own, it is because it isn't a suitable situation to be bringing any laptop).

Not a workaholic, I don't think, but a 24/7 stress monkey when I think that I could be helping. Simply not being able to work away from the office actually helps with that: if there is literally nothing I can do, especially given it is work that has made that impossible, I don't stress the same way.

--------

[1] other than the VPN connector and the MFA doo-hicky on an old² phone, nothing work related, even Teams, even email, ever touches my personal devices

[2] a small old thing, factory reset with a dummy google account and just the MFA apps installed

Re: Curl will not accept vulnerability reports during July 2026

#102
post #16
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

You're a good person.

My manager doesn't stop overworking. When told on peer performance review that we have people who are consistently overwork because they are swamped, he played it down.

But hey, at least he doesn't encourage overworking either.

Re: Curl will not accept vulnerability reports during July 2026

#103

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

Consumers, not customers

Re: Curl will not accept vulnerability reports during July 2026

#104
post #50

Earlier quoted context omitted.

Quote from my partner's manager before a vacation: "If I see you log on, I'll disable your account."

Humm he means figure out everything you’re signed in to before going on vacation and log off? Personally I’m sure I’d forget to sign out of something.

Probably more Teams autostart and suddenly you appear in the online list when you are officially on vacation.

Re: Curl will not accept vulnerability reports during July 2026

#105
post #50

Earlier quoted context omitted.

Quote from my partner's manager before a vacation: "If I see you log on, I'll disable your account."

Humm he means figure out everything you’re signed in to before going on vacation and log off? Personally I’m sure I’d forget to sign out of something.

No, they don't mean "you should log off everywhere" literally; rather, "don't open Teams/Slack/${our_corporate_chat_software}".

Re: Curl will not accept vulnerability reports during July 2026

#106
post #26

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.

Why are you interpreting clear communication of a window of downtime with 2 weeks notice as a "lack of cooperation"? That's what cooperation looks like. It's not explicit but my read was that they're not even taking a vacation - they're just doing the rest of their job, a lot of which is probably going to be shipping fixes for vulnerabilities that are already triaged.

Re: Curl will not accept vulnerability reports during July 2026

#108
post #72
post #39

For anyone who thinks this might matter for security: * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.

> if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co No, that is the point, they are not going to accept your vuln report. They are taking a holiday.

There's a pretty big difference between a random report submitted via email, and, say, a close friend of the maintainers letting them know a serious vuln was found and they should login.

Re: Curl will not accept vulnerability reports during July 2026

#109
post #58

Earlier quoted context omitted.

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

It can honestly be annoying, if you're not privvy to it. I remember years ago needing urgent support for some bespoke European hardware we were developing software for. When we called support, we were greeted with a phone message stating the company was closed for the entire month due to vacation. This was not a one-man operation; the whole office closed for a summer holiday. We thought it was a joke. Needless to say…

I'm surprised, typically we don't all take vacation at the same time, but stagger it.

Re: Curl will not accept vulnerability reports during July 2026

#110
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

Easy, that has always been my whole European life, want to reach me on vacations, pay for it.
Post reply on HN