Curl will not accept vulnerability reports during July 2026
231–240 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#232For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
Re: Curl will not accept vulnerability reports during July 2026
#233Earlier quoted context omitted.
> Especially since it appears there is a solution if you truly need a fix. If you ever really need anything fixed in the open source world, there is always the option of doing it yourself
Doing the fix yourself is almost always the easy part. Disclosing it and getting a patch shipped across the entire Internet is the hard part.
Re: Curl will not accept vulnerability reports during July 2026
#234Earlier quoted context omitted.
curl is the sandbox. It exchanges packets with the internet and then outputs a safely sanitized byte stream.
curl is only the sandbox if you don't then do anything with the byte stream. Pipe it to bash? game over Pipe it to less/more? Better hope your distro keeps those patched Open the file in a browser or PDF reader? Hey, look at all this shiny new attack surface!
Re: Curl will not accept vulnerability reports during July 2026
#235Today is Jun 15. So, I wonder if somebody + AI can rewrite curl in Rust in 1.5 months. I think it's possible if that person knows all curl features. However, does that person even exist?
Re: Curl will not accept vulnerability reports during July 2026
#236For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
Re: Curl will not accept vulnerability reports during July 2026
#237Earlier quoted context omitted.
The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.
Even the concept that you need permission from your employer to take a sick day is crazy to me. After all, if you're sick, you're sick, not like a hard deadline of 15 days (or whatever) is going to make the sickness go away?
For example, the way it works in Australia is that after you have used up your sick days, you have to take any further absences from work out of your annual leave balance, and once that is exhausted, you switch to leave without pay.
I had a downline team member who once needed to extend their time away from work for over 5 months due to illness. They had been with the company for several years at that point, so they had a reasonable sick leave balance, probably 10 weeks. When it became clear that they needed longer, they used their remaining 4 weeks of annual leave, then took a month of leave without pay, then another. They were still employed, I approved their leave requests each time they needed to extend, and we just used the most appropriate tool that was available at the time.
The thing you're getting permission for is not to be sick, it is to be considered still employed while not doing work, rather than being fired/disciplined for being AWOL.
Re: Curl will not accept vulnerability reports during July 2026
#238For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…
This is one of the reasons I work in an office every single day. I leave my work laptop there. I don't have any work software on any of my personal devices, including my phone. If I had the ability to check in on work things while out of the office, I probably would, so I make it impossible.
Re: Curl will not accept vulnerability reports during July 2026
#239Earlier quoted context omitted.
Until someone races to the bottom to do 12 months of availability.
Races to the bottom to … do work exclusively for free and not make any money out of the hopes that they become the most popular OSS toolkit, with an end goal of … what?
Greed, sometimes. Gotta get those usercounts high to get acquihired / to sell out / to flip on the paid subs for formerly free features.
I can’t remember the word for “prosocial through lowering cost to zero” is but sometimes that too.
Re: Curl will not accept vulnerability reports during July 2026
#240Earlier quoted context omitted.
One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…
I'm a senior at a big tech company. You can do this in America too. Just communicate with your manager and set the boundary. "By the way, when I'm on vacation I'm away from devices, so let's coordinate beforehand if there's anything critical path."